Solved

Allowing "Internet Time" to sync thru Firewall

Posted on 2010-11-18
10
1,147 Views
Last Modified: 2012-05-10
I'm running Windows Server 2008 and have tightened up the firewall too much and now my "Date and Time" won't sync via the "Internet Time" time.windows.com.

I allowed the "RunDLL32.com" inbound and outbound via firewall on all ports but no luck.

What firewall settings are necessary to allow the "Internet Time" to automatically synch my clock again?
0
Comment
Question by:deming
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 3
  • 2
  • +1
10 Comments
 
LVL 5

Expert Comment

by:mittermueller
ID: 34169016
Just open 123 UDP... (outside)
0
 

Author Comment

by:deming
ID: 34169145
When I click "Update now" I get "An error occurred while Windows was synchronizing with time.windows.com."

Was I supposed to also allow rundll32.exe access or not?
0
 

Author Comment

by:deming
ID: 34169163
Same error when I added rundll32.exe with full access in and out.
0
Edgartown IT Case Study

Learn about Edgartown's quest to ensure the safety and security of the entire town's employee and citizen data. Read the case study!

 
LVL 6

Expert Comment

by:univision-computers
ID: 34169203
You can try setting a different time server and see if that helps.  That would rule out the firewall as the cause if it works.  I have had a few servers unable to update the time lately and this fixed it:
http://support.microsoft.com/kb/816042
I just set it to us.pool.ntp.org for the time server (or pool.ntp.org outside the US) and you can choose to leave time.windows.com as a secondary server if  or remove it altogether
0
 
LVL 6

Expert Comment

by:univision-computers
ID: 34169208
To clarify, you just use the second "FIXIT" link and then you can add those servers in there.
0
 
LVL 5

Expert Comment

by:mittermueller
ID: 34169267
Open Dos Box and set your time server (eg. de.pool.ntp.org) with command NET TIME /setsntp:de.pool.ntp.org. See your NTP server at http://www.pool.ntp.org/en/
0
 

Author Comment

by:deming
ID: 34169355
To clarify, if I turn OFF the firewall, the the time updates fine.  So I feel certain it is a firewall setting restricting the access to the time server.  I need to allow the program access to the ports.  I did the DOS box "NET TIME /setsntp:de.pool.ntp.org" and it said Successful, however, the time still does not sync.
0
 
LVL 5

Expert Comment

by:mittermueller
ID: 34192555
Do you have opened port 123 (udp) outside as stated above?
0
 

Author Comment

by:deming
ID: 34270076
Yes, if I open port 123 Out UDP to any program, then the time updates correctly. However, I do not want to have that port wide open to any program. Thus, please tell me which program need is using that port to update the time so I can restrict the firewall to only that program which updates the time.
0
 
LVL 3

Accepted Solution

by:
TeraByteMan earned 500 total points
ID: 34273867
Here's how to do it:

Add a rule to your Firewall to allow outbound UDP on port 123 only for the program "w32tm.exe" which is found in our System32, or SysWow64 folder.

This will only allow the time to update on that port and no other program can use it.  I tested and confirmed this works.
0

Featured Post

Best Practices: Disaster Recovery Testing

Besides backup, any IT division should have a disaster recovery plan. You will find a few tips below relating to the development of such a plan and to what issues one should pay special attention in the course of backup planning.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

You may have a outside contractor who comes in once a week or seasonal to do some work in your office but you only want to give him access to the programs and files he needs and keep privet all other documents and programs, can you do this on a loca…
A quick guide on how to use Group Policy to create a custom power plan and set it active on Windows 7.
The Task Scheduler is a powerful tool that is built into Windows. It allows you to schedule tasks (actions) on a recurring basis, such as hourly, daily, weekly, monthly, at log on, at startup, on idle, etc. This video Micro Tutorial is a brief intro…
There are cases when e.g. an IT administrator wants to have full access and view into selected mailboxes on Exchange server, directly from his own email account in Outlook or Outlook Web Access. This proves useful when for example administrator want…

695 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question