Private NTP Server
Serve disciplined time safely to systems on a private LAN.
Serve time to a private LAN
This guide turns the Chrony instance on a ROKO observer or ordinary Linux host into a restricted NTP server for home/lab computers.
It does not expose ROKO PTP² to LAN clients. PTP² and NTP are separate protocols.
Prerequisites
- the server has a stable LAN address;
- Chrony already uses at least three or four permitted, diverse sources;
- `chronyc tracking` reports synchronized;
- the host firewall can distinguish the LAN interface/subnet from the Internet.
Use `time.roko.network` as one source, not the only source.
Chrony configuration
Create a dedicated fragment using your actual LAN values:
# Upstream sources
server time.roko.network iburst
pool pool.ntp.org iburst maxsources 3
minsources 2
makestep 0.1 3
rtcsync
# Serve only the private LAN
allow <LAN_CIDR>
binddevice <LAN_INTERFACE>
# Disable the remote chronyc UDP command port
cmdport 0
# Limit abusive/misconfigured clients
ratelimit interval 3 burst 8 leak 2
Do not copy `<LAN_CIDR>` or `<LAN_INTERFACE>` literally. Use a narrow subnet; do not use `allow all` or `0/0`.
`cmdport 0` disables the remote UDP command interface. Local administration continues through Chrony's Unix socket.
Firewall
Permit UDP/123 only from `<LAN_CIDR>` on `<LAN_INTERFACE>`. Drop it on public interfaces. The exact command depends on your firewall manager; verify the effective rules after every reboot.
Do not open UDP/319 or UDP/320. ROKO PTP² is not IEEE 1588 PTP.
Validate the server
On the server:
sudo chronyc reload sources
chronyc tracking
chronyc sources -v
chronyc clients
On a LAN Linux client, add:
server <LAN_TIME_SERVER> iburst
Then inspect `chronyc sources -v` and `chronyc tracking`. macOS and Windows clients can use `<LAN_TIME_SERVER>` through their normal network time settings.
Test both sides of the boundary:
1. a LAN client receives NTP replies and converges; 2. a host outside the allowed subnet receives no reply; 3. a reboot restores firewall rules, upstream sync, and LAN service; 4. if upstream sources are unhealthy, the server does not claim a false local reference clock.
Security and accuracy notes
- NTP representation and actual accuracy are different. Wi-Fi, NAT, queueing,
and asymmetric paths add error.
- Standard NTP is unauthenticated unless NTS or another authenticated design is
configured. Do not add `nts` to a source that has not been verified to support it.
- Do not mix leap-smeared and non-smeared upstreams.
- Monitor loss of synchronization, root distance, falsetickers, reach, and
unexpected client volume.
- Follow RFC 8633 and the