New: look around a live Uplivra server with a sample company's network already set up. Request demo access(free account, no card)
UplivraUplivra
Uplivra is in beta and online purchasing is paused. Apply to test it: testers get a license on request and 10% off when purchasing opens.

Home › Install guides › Uplivra's NTP server

Install guide · IT teams and MSPs

Uplivra's NTP server

A collector hands its clock to the switches, cameras, phones, printers and PCs on its networks, so they keep the same time as Uplivra's logs. It answers only your networks, limits each device, and tells devices "not synchronized" rather than hand out a wrong time.

Uplivra Technologies LLC · Guide for Uplivra 26.10 · Updated 11 October 2026 · Latest version: https://uplivra.com/guides/ntp-server.html

Download this guide as a PDF

What you need

  • A Linux collector or appliance. On Windows, the Windows Time service already uses port 123, so use it there.
  • Time servers it can reach: the ones under Settings › Time and NTP (pool.ntp.org and Cloudflare by default, or your own). The collector's clock is kept right with them by the operating system, and Uplivra compares it with them every minute.
  • Permission: Turn on and change Uplivra's NTP server.
  • Price: free, in Core.

Turn it on

  1. Open Network › NTP server.
  2. Next to the collector, choose Set up.
  3. Tick Serve time (NTP) on this collector.
  4. Pick the network ports it answers on. Add the networks allowed to ask; empty means private networks only (10/8, 172.16/12, 192.168/16, 100.64/10).
  5. Choose Save.

Within a minute the collector answers on UDP port 123 on those ports. On an Uplivra appliance, it opens UDP 123 in its own firewall on those ports.

Point devices at it

The Network › NTP server page lists the addresses to use.

  • Uplivra's DHCP server: put the address in the scope's Time servers (DHCP option 42).
  • Switches and routers: in the device's time settings, for example ntp server 192.168.10.2 on Cisco.
  • Windows domains: domain members take their time from the domain controllers. Point the domain controller with the PDC emulator role at the collector:
w32tm /config /manualpeerlist:"192.168.10.2" /syncfromflags:manual /reliable:yes /update
w32tm /resync
  • Two collectors give devices a backup: give them both addresses.

When it won't vouch for the time

A device that takes a wrong time is worse off than one that keeps its own. So the collector tells devices "not synchronized" (leap indicator 3, stratum 16), and they ignore it, when:

  • the operating system says the clock isn't synchronized;
  • its clock is further from your time servers than the limit (1,000 ms by default, set per collector);
  • your time servers haven't answered for an hour (until then it keeps serving, with the uncertainty growing);
  • the time server it compares with isn't synchronized itself.

The page shows not passing the time on with the reason, and an alert opens: NTP server on (collector) isn't passing the time on. It closes by itself when the clock is right again.

What it answers, and what it doesn't

  • Time requests only (NTP versions 1 to 4, client mode). Control (mode 6), private (mode 7, "monlist") and peer requests get no answer: those are what attackers use to make old NTP servers flood someone else.
  • Never a bigger answer than the question: every answer is 48 bytes.
  • Allowed networks only: other addresses get no answer.
  • A limit per device: 60 requests a minute by default. A device that asks faster is told to slow down (a "RATE" kiss-o'-death answer), then ignored until it does.
  • Stratum: one more than the time server the collector compares with. The reference is that server's address.

Check it

  • The page: each collector shows its state, the time server it's compared with and how far off it is, the devices that asked in the last hour, answers, and devices slowed down or refused.
  • An NTP check: add an NTP check on the collector's address, like any time server. It alerts on offset and stratum.
  • The command line: on the collector (or the Uplivra server, for every collector):
uplivra ntp status
uplivra ntp test 192.168.10.2

ntp test asks any NTP server, from any computer, and says how far its time is from that computer's. It exits with code 3 when the server doesn't answer, for scripts. See the command-line reference.

Ports

DirectionPortFromWhy
InUDP 123Devices on the networks it servesTime requests
OutUDP 123Your time serversKeeping the collector's own clock right (already needed)

See Ports and firewall rules.

Troubleshooting

  • "port 123 is already in use": another program serves time on the collector, usually chrony or ntpd set up to serve. Stop it serving (in chrony, remove the allow lines), or use another collector.
  • Devices don't take the time: check the device can reach UDP 123 on the collector (uplivra ntp test ADDRESS from a computer on that network), and that its network is in the allowed list. The page counts requests from networks not allowed.
  • Not passing the time on: read the reason on the page. On the collector, timedatectl status shows whether the system clock is synchronized, and Settings › Time and NTP lists the time servers it uses.