IntermediatePublished 2026-07-04
Securing NTP with MD5 Authentication
Bundle lab
Lab 4 of 10 in NTP & Network Time · ← Previous · Next →
CCNA exam domain: IP Services
Configure NTP MD5 authentication so a client (R2) synchronizes only to a trusted, authenticated master (R1). R1 is already an authoritative clock (ntp master 3). You will enable NTP authentication on both routers, define and trust key 1, and bind the key on R2's ntp server statement. Verification focuses on authenticated associations and status; actual time lock may take minutes and is not graded.
Learning objectives
- Secure NTP using MD5 authentication between Cisco IOS routers
- Differentiate required NTP authentication components: authenticate, authentication-key, trusted-key, and keyed server
- Verify authenticated NTP associations and status without relying on full convergence
- Explain why unauthenticated or mismatched keys prevent time sync to block rogue sources
Troubleshooting focus
- Client has ntp server configured but lacks 'ntp authenticate' globally
- Key number mismatch between server and client (e.g., key 1 vs key 2) or untrusted key
- Shared secret differs across devices even if key numbers match
- Wrong server IP or link down—ping the master from the client
- Expect delays before selection; use 'show ntp associations detail' to confirm 'is authenticated'
Topology
Subscribe to preview this lab's topology.
See plansGrade your work
How this lab is graded
- Build it your way. Where a lab lets you choose a value — a VLAN name, an interface description — grading checks that you configured it, not which name you picked. Names that another line has to reference, like an ACL applied with
access-class, are stated in the guide and do have to match. - Addresses, modes and protocol keywords are exact. An IP address, a subnet mask,
switchport mode trunk, an encapsulation — these carry the meaning of the lab, so they are graded as written in the guide. - Grading reads your saved configuration. Export the lab from CML after you have configured it, and make sure anything you set is in the
running-config— a change that only exists in a terminal session never reaches the grader. - You can submit as many times as you like. Your best score stands, and each attempt tells you which checks passed so you can work the gaps.
- Scored something you believe is correct? Use Report an issue on this page — that is exactly how the grading fixes in the changelog got found.
Create a free account to submit your lab for grading.
Create a free accountFound a problem with this lab?
Please sign in to report a problem — tying it to your attempts lets us reproduce and fix it faster.