We help IT Professionals succeed at work.

Time Lag in Active directory sites

Medium Priority
422 Views
Last Modified: 2012-05-12
our client having 2 AD servers PDC and ADC on 2 sites they are facing time lag issues can you please what are the primary steps i have to check to resolve the issue and what could be the possible issues between them.
Comment
Watch Question

CERTIFIED EXPERT
Commented:
Check the event about w32time.
Please check if ADC is accepting time from PDC. Or else configure to sync time from internet.

http://mysysadmintips.com/index.php/servers/29-configure-time-server-on-windows-server-2003-dc
CERTIFIED EXPERT
Top Expert 2013

Commented:
How much time lag are you dealing with?
Bradley FoxLAN/WAN Systems Administrator
CERTIFIED EXPERT

Commented:
It looks like you don't have an authoritative time server in your domain or if you do it is syncing from it's hardware clock.  At the server you want to be your authoritative time server for the domain.  Note this should be one of your ADCs and you should only set one for the entire enterprise.  All DWORD values are Decimal unless otherwise specified

1. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W32Time\Parameters\Type
Value = NTP

2. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W32Time\Config\AnnounceFlags
Value = 5

3. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W32Time\TimeProviders\NtpServer\Enabled
Value = 1

4. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W32Time\Parameters\NtpServer
Value = tick.usno.navy.mil,0x1 tock.usno.navy.mil,0x1
Values above are US Navy time servers with a comma 0x1 separated by a space

5. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W32Time\TimeProviders\NtpClient\SpecialPollInterval
Value = 900
(This is time in seconds, 900=15 min)

6.  HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W32Time\Config\MaxPosPhaseCorrection
Value = 3600

7. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W32Time\Config\MaxNegPhaseCorrection
Value = 3600

8. open command prompt and type
net stop w32time & net start w32time

Bradley FoxLAN/WAN Systems Administrator
CERTIFIED EXPERT

Commented:
boy, I was slow on that one...
great@mcsween but tell me before making any change how could i check is there any server authorative or not?
Bradley FoxLAN/WAN Systems Administrator
CERTIFIED EXPERT

Commented:
Look at the registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W32Time\Config\AnnounceFlags

It should be set to 10 by default; 5 for your authoritative time server a reliable time server.

You could set this up on more than one server as long as you make sure
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W32Time\Parameters\NtpServer
is the same on any system acting as an authoritative time server.  You might want to setup one in each office if you had a slow link between offices.
What is the time difference between DC?

PDC role owner in forest root domain should be a authorative time server.  run "netdom qury fsmo" command to find out FSMO role owner.

You may refer below article for Time server configuration to sync PDC emulator to an External Time Source
http://abhijitw.wordpress.com/2011/10/08/time-server-configuration-to-sync-pdc-emulator-to-an-external-time-source/

Correction in command- netdom query fsmo

Explore More ContentExplore courses, solutions, and other research materials related to this topic.