Nerzen NTP Loading status TR

NTP and NTS setup

In every example below, all you need to do is enter time.nerzen.com as the server name. No registration, key or permission is required. Use the hostname rather than the IP address; your configuration won't be affected if the address changes.

Linux

chrony — Debian, Ubuntu, AlmaLinux, Rocky, RHEL, Fedora

The configuration file is /etc/chrony/chrony.conf on Debian/Ubuntu and /etc/chrony.conf on the RHEL family. Add this next to the existing pool / server lines:

chrony.conf
server time.nerzen.com iburst
Apply and check
sudo systemctl restart chrony    # on the RHEL family: chronyd
chronyc sources -v
chronyc tracking

With NTS — recommended

chrony 4.0 and later supports NTS (Ubuntu 22.04+, Debian 11+, RHEL 9+). The only difference is the word nts at the end of the line:

chrony.conf · NTS
server time.nerzen.com iburst nts
ntsdumpdir /var/lib/chrony

systemd-timesyncd

The default on lightweight installations and on Raspberry Pi OS. It does not support NTS.

/etc/systemd/timesyncd.conf
[Time]
NTP=time.nerzen.com
Apply and check
sudo systemctl restart systemd-timesyncd
timedatectl timesync-status

ntpd / NTPsec

/etc/ntp.conf or /etc/ntpsec/ntp.conf
server time.nerzen.com iburst
# NTS with NTPsec:
# server time.nerzen.com iburst nts

Windows

Single computer — Command Prompt as administrator

cmd · administrator
w32tm /config /syncfromflags:manual /manualpeerlist:"time.nerzen.com,0x8"
w32tm /config /update
w32tm /resync
w32tm /query /status

Domain controller — PDC emulator

Computers in a domain take their time from the PDC emulator; configure the external source on that server only.

On the PDC emulator
w32tm /config /manualpeerlist:"time.nerzen.com,0x8" /syncfromflags:manual /reliable:yes /update
net stop w32time && net start w32time
w32tm /resync /rediscover

macOS

Terminal
sudo systemsetup -setnetworktimeserver time.nerzen.com
sudo systemsetup -setusingnetworktime on

From the interface: System Settings → General → Date & Time → Source → time.nerzen.com.

Network devices

MikroTik RouterOS 7

RouterOS 7
/system ntp client set enabled=yes
/system ntp client servers add address=time.nerzen.com

MikroTik RouterOS 6

RouterOS 6
/system ntp client set enabled=yes server-dns-names=time.nerzen.com

Cisco IOS / IOS-XE

IOS
configure terminal
 ntp server time.nerzen.com
end
show ntp associations

Juniper Junos

Junos
set system ntp server 141.98.50.237
commit
show ntp associations

Junos resolves the hostname only at commit time, so entering an IP address is more predictable here. For IPv6, use 2a0f:bf01:0:1::3.

pfSense / OPNsense

Add time.nerzen.com under Services → NTP → Time Servers and save.

OpenWrt

OpenWrt
uci delete system.ntp.server
uci add_list system.ntp.server='time.nerzen.com'
uci commit system
/etc/init.d/sysntpd restart

Virtualisation and storage

VMware ESXi

Host → Manage → System → Time & date → Edit NTP settings → time.nerzen.com, with the service startup policy set to "Start and stop with host". From the command line (7.0 U1+):

ESXi shell
esxcli system ntp set -s time.nerzen.com -e true

Proxmox VE

Proxmox VE 7 and later uses chrony; add the chrony line above to /etc/chrony/chrony.conf and run systemctl restart chrony.

KVM / libvirt guests and VPSs

A guest does not follow the host's clock automatically; run chrony or timesyncd inside the guest. VPSs on the Nerzen network get the best results because they are in the same data centre as the server.

Synology DSM

Control Panel → Regional Options → Time → "Synchronize with NTP server" → time.nerzen.com.

QNAP QTS

Control Panel → System → General Settings → Time → "Synchronize with an Internet time server automatically" → time.nerzen.com.

Docker · Podman · LXC · Kubernetes

Containers share the host's kernel clock; do not run NTP inside a container. Configuring the host (or the nodes) is enough.

NTS — authenticated time

Plain NTP responses are unsigned; someone on the path can alter a response and shift your clock. NTS (Network Time Security, RFC 8915) first performs a key exchange over TLS (4460/tcp), then authenticates every NTP response with those keys. The content is not hidden, but it is proven that the response really came from us and was not changed in transit.

Requirements: an NTS-capable client (chrony ≥ 4.0, NTPsec ≥ 1.2), outbound access to 4460/tcp and 123/udp, and a roughly correct starting time so that the certificate can be validated.

Verifying that it works

chrony
chronyc -N authdata
# You should see NTS in the Mode column and values greater than zero in the KeyID and Cook columns

Configure more than one server

A client that depends on a single time server cannot tell when that server is wrong. On production systems, add at least two, preferably three, other independent sources you trust alongside time.nerzen.com; your client will automatically discard whichever one disagrees with the majority.