Link to home
Start Free TrialLog in
Avatar of dougdog
dougdog

asked on

what is the best practice to configure ntp service on vmware 4.0 and windows 2003 domain

What is the best way to configure ntp and time service for vsphere and windows 2003 domain
does all member servers point to the pdc for correct time?
does esx hosts point to pdc for time or do they need to be an external source?
does all pcs point to pdc for correct time?
Avatar of Andrew Hancock (VMware vExpert PRO / EE Fellow/British Beekeeper)
Andrew Hancock (VMware vExpert PRO / EE Fellow/British Beekeeper)
Flag of United Kingdom of Great Britain and Northern Ireland image

We have a GPS Clock, we sync Domain Controllers and ESX servers to the GPS Clock on the LAN.

All VMs (excluding DC's ) are then synced to Host ESX servers.

Checkout the whitepaper
www.vmware.com/files/pdf/Timekeeping-In-VirtualMachines.pdf
All VMs (excluding DC's ) are then synced to Host ESX servers using VMware Tools - Sync to Host Option.
The PDC emulator in the forest root points to the external or good time source and then let the windows hierarchy take over from there.  Matt has a great blog entry on it here

http://tigermatt.wordpress.com/2009/08/01/windows-time-for-active-directory/

Don't have any DCs sync time with the host.

Thanks

Mike
Avatar of dougdog
dougdog

ASKER

i have got a dc which is virtual and running on an esx host
Is that the PDCe?  You really don't need to do anything different other than make sure to not sync the DC time with the host.  From there just treat it as if it running on its own hardware.

Thanks

Mike
Avatar of dougdog

ASKER

if i dont want to buy a gps clock can i configure the pdc to point to an external time source
which will keep the pdc correct and then all pcs servers etc point to the pdc
can i also configure the est hosts to point to the same external time source
Yes, you can point to a reliable Internet Based NTP Source.

see here

http://www.pool.ntp.org/en/
Avatar of dougdog

ASKER

what happens if the pdc goes down
so am i right in saying on the esx ntp server settings i just add in say the following
europe.pool.ntp.org
If the PC Emualtor does down, they'll not sync.

Just add the correct NTP server to ESX.
If the PDC goes down permanently then you configure the new PDCe to point to an external source.

They key here is that the clocks stay within 5 minutes (Kerberos requirement).  The PDC being down for maintenance or a temporary outage should not cause a huge impact for time.

Thanks

Mike
Avatar of dougdog

ASKER

okay whats the best ntp server to use for the uk?
ASKER CERTIFIED SOLUTION
Avatar of Andrew Hancock (VMware vExpert PRO / EE Fellow/British Beekeeper)
Andrew Hancock (VMware vExpert PRO / EE Fellow/British Beekeeper)
Flag of United Kingdom of Great Britain and Northern Ireland image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of dougdog

ASKER

perfect