Using the member time service

The member time service is available only from the CNX member peering network. Your router must be directly connected to CNX, and requests must be sourced from the IPv6 peering address assigned to your membership. This is a hard access requirement: the service is not reachable from the public Internet or through another network.

IPv6 address: 2001:df6:1440::123
NTP: UDP/123
NTS key establishment: TCP/4460
NTS hostname: nts.cnx.net.kh

This page covers the service available over the IX fabric. Standalone paid NTP, NTS, and PTP services have a separate service contract and will be documented outside the Exchange section.

Use NTP

Configure 2001:df6:1440::123 as an NTP source and bind the request to the router's CNX-assigned IPv6 address. Source selection is required, not optional. If the router cannot source NTP from that address over the CNX member peering network, it cannot use this service. Permit UDP/123 in both directions.

Unauthenticated NTP provides time synchronization but does not authenticate the server or subsequent time packets.

Platform configuration patterns are:

Cisco IOS XE:
ntp server 2001:df6:1440::123 source <IX_INTERFACE> prefer

Junos OS:
set system ntp source-address <MEMBER_IPV6>
set system ntp server 2001:df6:1440::123 prefer

Huawei VRP:
ntp-service unicast-server 2001:df6:1440::123
ntp-service server source-interface <IX_INTERFACE>

Verify that the resulting packets use <MEMBER_IPV6> as their source. See the complete Cisco IOS XE, Junos OS, and Huawei VRP configurations.

Native router NTS support

NTS is relevant here only when the directly connected IX router implements an RFC 8915 client. An off-router relay is not part of this service guide because such a host is not normally attached to the peering LAN.

CNX currently documents native NTS only for Junos OS Evolved 24.2R1 or later on supported ACX, QFX, and PTX devices. Confirm the exact model and release in Juniper Feature Explorer before enabling it. Native NTS client support has not been established for Cisco IOS XE or Huawei VRP routers; use unauthenticated NTP on those platforms.

NTS uses TLS on TCP/4460 for key establishment and authenticated NTP on UDP/123. The Junos configuration has this shape:

set system ntp source-address <MEMBER_IPV6>
set system ntp nts trusted-ca trusted-ca-profile CNX-ROOT
set system ntp server 2001:df6:1440::123 nts remote-identity hostname nts.cnx.net.kh

Import the CNX root certificate from the CNX PKI repository into the CNX-ROOT CA profile and verify its published fingerprint first. The server must present its leaf certificate and CNX Service Intermediate CA during NTS key establishment. A combined intermediate-and-root bundle should be offered only if testing shows that a supported router requires it; the normal trust anchor is the root CA.

The commands above describe the Junos hierarchy but do not replace the model- and-release-specific PKI import procedure. Validate the candidate configuration and certificate chain before committing it.

Verify

Confirm that:

  • traffic is sourced from the assigned CNX IPv6 address;
  • TCP/4460 completes with the ntske ALPN;
  • the certificate validates against the CNX root and nts.cnx.net.kh;
  • when NTS is enabled, the router reports successful TLS certificate and NTS authentication; and
  • offset, reachability, and stratum remain within your local operating limits.

Juniper documents native NTS support and its configuration in the Junos NTS overview and NTP CLI reference.