华为交换机 NTP 时间同步配置实战(含认证与排障) - 夜莺博客

华为交换机 NTP 时间同步配置实战(含认证与排障)

日志时间对不上,是网络排障中最容易被忽视又最致命的坑:交换机日志显示 03:14,服务器日志显示 11:14,同一场故障在两份日志里跨越了八个小时,时间线彻底拼不起来。华为 S 系列 / CE 系列交换机内置 NTP 客户端与服务端能力,配置本身只要几条命令,但时区、主时钟层级和认证三个点最容易配错。本文按华为官方配置举例的步骤给出完整实操。

第一步:设置时区与系统时间

时间 = UTC + 时区偏移 + 夏令时偏移。华为 VRP 默认时区名为空,如果不显式设置,display clock 输出会是 UTC 时间。

<HUAWEI> clock timezone BJ add 08:00:00
<HUAWEI> clock datetime 14:30:00 2026-10-04
<HUAWEI> display clock

若手工设置时带上 utc 关键字,则输入的时间被当作 UTC 时间存放;不带 utc 且已设置时区,则输入的时间即为当前系统时间。机房跨时区时统一按 UTC 配置更省事。

第二步:把交换机配成 NTP 服务端(主时钟)

上层已有时钟源(例如 GPS 或上级 NTP 服务器)的交换机可以作为次末级服务端,向下发布时间。

<SwitchA> system-view
[~SwitchA] ntp refclock-master 1
[*SwitchA] ntp authentication enable
[*SwitchA] ntp authentication-keyid 45 authentication-mode hmac-sha256 hello123456
[*SwitchA] ntp trusted authentication-keyid 45
[*SwitchA] ntp server source-interface vlanif 100
[*SwitchA] undo ntp server disable
[*SwitchA] commit

refclock-master 1 把本地时钟声明为 stratum 1。认证模式支持 MD5 和 HMAC-SHA256,后者安全性更高,MD5 速度更快;生产环境建议统一用 HMAC-SHA256。

第三步:客户端同步并启用认证

<SwitchB> system-view
[~SwitchB] ntp authentication enable
[*SwitchB] ntp authentication-keyid 45 authentication-mode hmac-sha256 hello123456
[*SwitchB] ntp trusted authentication-keyid 45
[*SwitchB] ntp unicast-server 10.10.1.1 authentication-keyid 45
[*SwitchB] commit

注意客户端必须配置 ntp trusted authentication-keyid,否则即使 keyid 匹配,来自未标记为 trusted 的报文仍会被丢弃。这是“配置看起来都对却不同步”的首要原因。

第四步:验证同步状态

<SwitchA> display ntp status
clock status: synchronized
clock stratum: 1
reference clock ID: LOCAL(0)
clock offset: 0.0000 ms
root dispersion: 11.65 ms

<SwitchB> display ntp status
clock status: synchronized
clock stratum: 2
reference clock ID: 10.10.1.1
clock offset: 0.6828 ms

关键字段解读:

  • clock status 必须为 synchronized;clock not set 表示时钟尚未更新。
  • clock stratum 客户端应比服务端大 1,若始终停留在 16 说明未选中任何时钟源。
  • clock offset 持续大于 100 ms 说明网络抖动大或存在不对称路径,需要查 ACL / 排队策略。
<SwitchB> display ntp sessions
<SwitchB> display ntp statistics

常见故障与排查

现象 可能原因 处理
状态长期 not set UDP 123 被 ACL 拦截 在设备与防火墙两侧放通 UDP 123,检查源接口
sessions 里对端可达但不选中 keyid 未标记 trusted 补 ntp trusted authentication-keyid
时间偏差忽大忽小 多个不同层级时钟源竞争 只保留一个上游服务器,或使用 ntp unicast-server 指定优先级
可 ping 通服务端却不能同步 源接口未指定,报文从错误的 VLANIF 发出 配置 ntp server source-interface vlanif X

运维建议

把网络设备的时间基准放在核心层,接入层只做客户端;所有设备的日志、SNMP trap、syslog 都指向同一台 NTP 服务器;启用认证避免伪造时间源;每季度核对一次 display ntp status 的 stratum 与 offset,把时间同步纳入例行巡检,而不是等排障时才发现日志不可信。

Related Reading

Deeper dives on the same topics from our archive:

原文链接:https://support.huawei.com/enterprise/zh/doc/EDOC1000037064/18b98c59