Solved

Windows 2008 R2 DC NTP sync issue

Posted on 2011-03-11
2
3,132 Views
Last Modified: 2012-05-11
Hey

I have an internal firewall hosting our NTP server.

I would like to set out DC to use this NTP sever

I have added the following:

C:\Windows\system32>w32tm /config /syncfromflags:manual /manualpeerlist:10.1.0.1
 /update

C:\Windows\system32>net stop w32time
C:\Windows\system32>net start w32time
C:\Windows\system32>w32tm /resync

But in the evetlog i see:

Time Provider NtpClient: No valid response has been received from manually configured peer 10.1.0.1 after 8 attempts to contact it. This peer will be discarded as a time source and NtpClient will attempt to discover a new peer with this DNS name. The error was: The peer is unreachable.

I have also added 0x8 ... same problem.

I have a small NTP tool - that show the NTP server is responding.

What to do?

Mike
0
Comment
Question by:mikeydk
2 Comments
 
LVL 19

Assisted Solution

by:Miguel Angel Perez Muñoz
Miguel Angel Perez Muñoz earned 250 total points
ID: 35107460
0
 
LVL 2

Accepted Solution

by:
temores earned 250 total points
ID: 35160044
You should ensure that UDP port 123 is open to that port,it is probably the main cause. also remember that the time configuration depends on the time service configuration.

NT5DS means that the ntp client (even doman controllers) will search for the PDC on the domain and get it's hour from it, if your DC is configured this way it will override any configured NTP server and search for the PDC, you can change this setting from the following reg key: HKLM\system\currentcontrolset\services\w32time\Parameters\

Type: NTP (REG_SZ) or NT5DS
NtpServer means that the client will search for the configured stratum server, you can try adding somethin like 10.1.0.1,0x9

I strongly recommend to create a dns alias (ntp.domain.com) and point that to the IP you like, you can unse that dns record instead to configure the NTP clients so if you need to change the IP don't have to crawl on all you customized servers.

cheers.
0

Featured Post

Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
AD LDAP LDS 3 48
Group policy backup error 8 25
Using an internal domain name that you do not own 6 44
Cloud to Hybrid 4 22
As network administrators; we know how hard it is to track user’s login/logout using security event log (BTW it is harder now in windows 2008 because user name is always “N/A” in the grid), and most of us either get 3rd party tools, or just make our…
In this article, we will see the basic design consideration while designing a Multi-tenant web application in a simple manner. Though, many frameworks are available in the market to develop a multi - tenant application, but do they provide data, cod…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …

920 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

16 Experts available now in Live!

Get 1:1 Help Now