24.2.1 Packet Tracer - Configure Syslog and NTP (Answers)
Topology

24.2.1 Packet Tracer - Configure Syslog and NTP
Objectives
- Part 1: Configure Syslog Service
- Part 2: Generate Logged Events
- Part 3: Manually Set Switch Clocks
- Part 4: Configure NTP Service
- Part 5: Verify Timestamped Logs
Scenario
In this activity, you will enable and use the Syslog service and the NTP service so that the network administrator is able to monitor the network more effectively.
Instructions
Part 1: Configure Syslog Service
Step 1: Enable the Syslog service.
a. Click the Syslog server, then select the Services tab.
b. Turn the Syslog service on and move the window so you can monitor activity.
Step 2: Configure the intermediary devices to use the Syslog service.
a. Configure R1 to send log events to the Syslog server.
R1(config)# logging 10.0.1.254
b. Configure S1 to send log events to the Syslog server.
S1(config)# logging 10.0.1.254
c. Configure S2 to send log events to the Syslog server.
S2(config)# logging 10.0.1.254
Part 2: Generate Logged Events
Step 1: Change the status of interfaces to create event logs.
a. Configure a Loopback 0 interface on R1 then disable it.
R1(config)# interface loopback 0 R1(config-if)# shutdown
b. Turn off PC1 and PC2. Turn them on again.
Step 2: Examine the Syslog events.
a. Look at the Syslog events. Note: All of the events have been recorded; however, the time stamps are incorrect.
b. Clear the log before proceeding to the next part.
Part 3: Manually Set Switch Clocks
Step 1: Manually set the clocks on the switches.
Manually set the clock on S1 and S2 to the current date and approximate time. An example is provided.
S1# clock set 11:47:00 July 10 2020
Step 2: Enable the logging timestamp service on the switches.
Configure S1 and S2 to send its timestamp with logs it sends to the Syslog server.
S1(config)# service timestamps log datetime msec S2(config)# service timestamps log datetime msec
Part 4: Configure NTP Service
Step 1: Enable the NTP service.
In this activity, we are assuming that the NTP service is being hosted on a public Internet server. If the NTP server was private, authentication could also be used.
a. On the NTP server, open the Services tab of the NTP server.
b. Turn the NTP service on and note the date and time that is displayed.
Step 2: Automatically set the clock on the router.
Set the clock on R1 to the date and time according to the NTP server.
R1(config)# ntp server 64.103.224.2
Issue the show clock command to view the system clock setting. It can take time for the system clock to be updated to the time that is configured on the NTP server. If the system clock has not updated, click the Fast Forward time button until the router system clock is synchronized with the NTP server.
Part 5: Verify Timestamped Logs
Step 1: Change the status of interfaces to create event logs.
a. Re-enable and then disable the Loopback 0 interface on R1.
R1(config)# interface loopback 0 R1(config-if)# no shutdown R1(config-if)# shutdown
b. Turn off laptops L1 and L2. Turn them on again.
Step 2: Examine the Syslog events.
Look at the Syslog events. Note: All of the events have been recorded and the time stamps are correct as configured. Note: R1 uses the clock settings from the NTP server, and S1 and S2 use the clock settings that you configured in Part 3.
Device Configs - Final
ROUTER R1
! ============================================================== !--- 24.2.1 Packet Tracer - Configure Syslog and NTP !--- ANSWER SCRIPT FOR ROUTER R1 !--- Usage: copy this whole file and paste it into the R1 terminal (start at the R1> prompt). Every line beginning with "!" is a comment; IOS ignores it, so pasting a comment by accident is harmless. !--- Note: this lab has no fixed "Device Configs" answer key - it's built !--- directly from the Instructions. Part 2's and Part 5's Loopback 0 !--- toggling is done in two separate passes (before and after NTP sync) !--- purely to generate log events for Part 2 Step 2 and Part 5 Step 2 - !--- paste this whole file in one go and both passes will run back to back. ! ============================================================== enable configure terminal ! -------------------------------------------------------------- !--- Part 1, Step 2a: Point R1 at the Syslog server so its log events are !--- sent there instead of only kept in R1's own local buffer. ! -------------------------------------------------------------- logging 10.0.1.254 ! -------------------------------------------------------------- !--- Part 2, Step 1a: Create Loopback 0, then immediately disable it - the !--- interface-down event is what Syslog will record (with the wrong, !--- unsynchronized time stamp, since NTP hasn't been configured yet). ! -------------------------------------------------------------- interface loopback 0 shutdown exit ! -------------------------------------------------------------- !--- Part 4, Step 2: Point R1 at the public NTP server so its clock !--- synchronizes automatically - this is what fixes the time stamps for !--- everything R1 logs from this point on. ! -------------------------------------------------------------- ntp server 64.103.224.2 end ! -------------------------------------------------------------- !--- Part 5, Step 1a: Re-enable then disable Loopback 0 again - this !--- second up/down event is the one Syslog should now show with a !--- correct, NTP-synchronized time stamp. ! -------------------------------------------------------------- configure terminal interface loopback 0 no shutdown shutdown exit end ! -------------------------------------------------------------- !--- Save the configuration to NVRAM. (Press Enter when prompted for the destination filename.) ! -------------------------------------------------------------- copy running-config startup-config ! ============================================================== !--- Verification: !--- show clock -> Part 4, wait/fast-forward until this matches the NTP server's displayed time !--- show ntp associations -> 64.103.224.2 marked as the synchronized reference (*) !--- show logging -> Part 2's Loopback0 down event has an incorrect/default time stamp !--- show logging (after Part 5) -> the second Loopback0 up/down pair has a correct, current time stamp !--- Note: this lab gives no separate answer-key/"Device Configs" section !--- to cross-check against - the numbered Instructions steps are the only !--- source, and this script follows them directly; no discrepancies found. ! ==============================================================
SWITCH S1
! ==============================================================
!--- 24.2.1 Packet Tracer - Configure Syslog and NTP
!--- ANSWER SCRIPT FOR SWITCH S1
!--- Usage: copy this whole file and paste it into the S1 terminal (start at the S1> prompt). Every line beginning with "!" is a comment; IOS ignores it, so pasting a comment by accident is harmless.
!--- Note: this lab has no fixed "Device Configs" answer key - it's built
!--- directly from the Instructions. The "clock set" line below must run
!--- at the privileged EXEC prompt, before "configure terminal" - it is
!--- not a config-mode command. Replace the date/time in it with the
!--- actual current date and approximate time, as the lab itself asks for
!--- ("the current date and approximate time"), not the July 10 2020
!--- example shown in the lab text.
! ==============================================================
enable
! --------------------------------------------------------------
!--- Part 3, Step 1: Manually set S1's clock, since S1 has no NTP source
!--- in this activity (only R1 gets NTP, in Part 4) - substitute today's
!--- actual date/time for the placeholder below.
! --------------------------------------------------------------
clock set 11:47:00 July 10 2020
configure terminal
! --------------------------------------------------------------
!--- Part 1, Step 2b: Point S1 at the Syslog server so its log events are
!--- sent there instead of only kept in S1's own local buffer.
! --------------------------------------------------------------
logging 10.0.1.254
! --------------------------------------------------------------
!--- Part 3, Step 2: Have S1 attach a timestamp (with millisecond
!--- precision) to every log message it sends to the Syslog server - using
!--- the clock that was just set manually above.
! --------------------------------------------------------------
service timestamps log datetime msec
end
! --------------------------------------------------------------
!--- Save the configuration to NVRAM. (Press Enter when prompted for the destination filename.)
! --------------------------------------------------------------
copy running-config startup-config
! ==============================================================
!--- Verification:
!--- show clock -> matches the date/time you set
!--- show logging -> messages now carry a "datetime msec" style time stamp
!--- Syslog server's log window -> events from S1 show that same manually-set time, throughout Parts 2 and 5
!--- Note: this lab gives no separate answer-key/"Device Configs" section
!--- to cross-check against - the numbered Instructions steps are the only
!--- source, and this script follows them directly; no discrepancies found.
!--- Note: unlike R1, S1's clock is never corrected by NTP in this
!--- activity - per the lab's own closing note, "S1 and S2 use the clock
!--- settings that you configured in Part 3" for the rest of the activity.
! ==============================================================SWITCH S2
! ==============================================================
!--- 24.2.1 Packet Tracer - Configure Syslog and NTP
!--- ANSWER SCRIPT FOR SWITCH S2
!--- Usage: copy this whole file and paste it into the S2 terminal (start at the S2> prompt). Every line beginning with "!" is a comment; IOS ignores it, so pasting a comment by accident is harmless.
!--- Note: this lab has no fixed "Device Configs" answer key - it's built
!--- directly from the Instructions. The "clock set" line below must run
!--- at the privileged EXEC prompt, before "configure terminal" - it is
!--- not a config-mode command. Replace the date/time in it with the
!--- actual current date and approximate time, as the lab itself asks for
!--- ("the current date and approximate time") - S2's clock only has to be
!--- close to S1's, it doesn't need to match exactly.
! ==============================================================
enable
! --------------------------------------------------------------
!--- Part 3, Step 1: Manually set S2's clock, since S2 has no NTP source
!--- in this activity (only R1 gets NTP, in Part 4) - substitute today's
!--- actual date/time for the placeholder below.
! --------------------------------------------------------------
clock set 11:47:00 July 10 2020
configure terminal
! --------------------------------------------------------------
!--- Part 1, Step 2c: Point S2 at the Syslog server so its log events are
!--- sent there instead of only kept in S2's own local buffer.
! --------------------------------------------------------------
logging 10.0.1.254
! --------------------------------------------------------------
!--- Part 3, Step 2: Have S2 attach a timestamp (with millisecond
!--- precision) to every log message it sends to the Syslog server - using
!--- the clock that was just set manually above.
! --------------------------------------------------------------
service timestamps log datetime msec
end
! --------------------------------------------------------------
!--- Save the configuration to NVRAM. (Press Enter when prompted for the destination filename.)
! --------------------------------------------------------------
copy running-config startup-config
! ==============================================================
!--- Verification:
!--- show clock -> matches the date/time you set
!--- show logging -> messages now carry a "datetime msec" style time stamp
!--- Syslog server's log window -> events from S2 show that same manually-set time, throughout Parts 2 and 5
!--- Note: this lab gives no separate answer-key/"Device Configs" section
!--- to cross-check against - the numbered Instructions steps are the only
!--- source, and this script follows them directly; no discrepancies found.
!--- Note: unlike R1, S2's clock is never corrected by NTP in this
!--- activity - per the lab's own closing note, "S1 and S2 use the clock
!--- settings that you configured in Part 3" for the rest of the activity.
! ==============================================================