Private NTP Server

Serve disciplined time safely to systems on a private LAN.

Serve time to a private LAN

This guide turns the Chrony instance on a ROKO observer or ordinary Linux host into a restricted NTP server for home/lab computers.

It does not expose ROKO PTP² to LAN clients. PTP² and NTP are separate protocols.

Prerequisites

  • the server has a stable LAN address;
  • Chrony already uses at least three or four permitted, diverse sources;
  • `chronyc tracking` reports synchronized;
  • the host firewall can distinguish the LAN interface/subnet from the Internet.

Use `time.roko.network` as one source, not the only source.

Chrony configuration

Create a dedicated fragment using your actual LAN values:

# Upstream sources
server time.roko.network iburst
pool pool.ntp.org iburst maxsources 3
minsources 2
makestep 0.1 3
rtcsync

# Serve only the private LAN
allow <LAN_CIDR>
binddevice <LAN_INTERFACE>

# Disable the remote chronyc UDP command port
cmdport 0

# Limit abusive/misconfigured clients
ratelimit interval 3 burst 8 leak 2

Do not copy `<LAN_CIDR>` or `<LAN_INTERFACE>` literally. Use a narrow subnet; do not use `allow all` or `0/0`.

`cmdport 0` disables the remote UDP command interface. Local administration continues through Chrony's Unix socket.

Firewall

Permit UDP/123 only from `<LAN_CIDR>` on `<LAN_INTERFACE>`. Drop it on public interfaces. The exact command depends on your firewall manager; verify the effective rules after every reboot.

Do not open UDP/319 or UDP/320. ROKO PTP² is not IEEE 1588 PTP.

Validate the server

On the server:

sudo chronyc reload sources
chronyc tracking
chronyc sources -v
chronyc clients

On a LAN Linux client, add:

server <LAN_TIME_SERVER> iburst

Then inspect `chronyc sources -v` and `chronyc tracking`. macOS and Windows clients can use `<LAN_TIME_SERVER>` through their normal network time settings.

Test both sides of the boundary:

1. a LAN client receives NTP replies and converges; 2. a host outside the allowed subnet receives no reply; 3. a reboot restores firewall rules, upstream sync, and LAN service; 4. if upstream sources are unhealthy, the server does not claim a false local reference clock.

Security and accuracy notes

  • NTP representation and actual accuracy are different. Wi-Fi, NAT, queueing,

and asymmetric paths add error.

  • Standard NTP is unauthenticated unless NTS or another authenticated design is

configured. Do not add `nts` to a source that has not been verified to support it.

  • Do not mix leap-smeared and non-smeared upstreams.
  • Monitor loss of synchronization, root distance, falsetickers, reach, and

unexpected client volume.

Chrony configuration reference.