Solved

What should be AnnounceFlags for Time source on Domain controllers

Posted on 2012-03-29
7
2,082 Views
Last Modified: 2012-03-29
Controlling time on memeber servers via GPO setting to NT5DS and the DC's also to NT5DS with announce flag of 5 .

confusion whether announceflag should be set to 5 or 10 on the domain controllers...

should pdc be set to 5 and all other DC's to 10? or should all be set to 5 ...
with the setting of 5, some dcd's start getting time from other dc's and not the PDC. causing issues...
0
Comment
Question by:ARM2009
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
  • 2
7 Comments
 
LVL 9

Expert Comment

by:Geodash
ID: 37782244
If i remember right, they are set to 5 -

Look at this article

http://support.microsoft.com/kb/816042
0
 

Author Comment

by:ARM2009
ID: 37782270
when we set themt to 5 ... some DC's will advertise and other DC's start taking time from them instead fo the PDC.

if we set to 10... no issues... but i am not seeing nay concrete evidence that 10 should be the setting on all dc's except PDC.

if all are set to 5... are they all advertising at the time source?
0
 
LVL 9

Expert Comment

by:Geodash
ID: 37782285
Here is another good explanation that may help clear this up for you - take a look here -

http://serverfault.com/questions/218722/config-time-service-on-server-2008-dc-using-group-policy-only
0
Office 365 Training for IT Pros

Learn how to provision tenants, synchronize on-premise Active Directory, implement Single Sign-On, customize Office deployment, and protect your organization with eDiscovery and DLP policies.  Only from Platform Scholar.

 
LVL 57

Expert Comment

by:Mike Kline
ID: 37782314
Set it to 5 on the PDCe  

1 (The DC always advertises time service) + 4 (the DC will always advertise reliable time service)

Set the other ones to 10


http://technet.microsoft.com/en-us/library/cc773263(v=WS.10).aspx
http://technet.microsoft.com/en-us/library/cc784191(v=WS.10).aspx

Thanks

Mike
0
 

Author Comment

by:ARM2009
ID: 37782337
Mike ...

if you see my post... your settings work for me but looking for an explanation why other dc's should be 10 and not 5... any technet links on that?

or technical explanation for that....

thanks
0
 
LVL 57

Accepted Solution

by:
Mike Kline earned 250 total points
ID: 37782378
only the pdce should advertise and from there let the windows hierarchy take over.

see the diagram on Ace's blog   https://msmvps.com/blogs/acefekay/archive/2009/09/18/configuring-the-windows-time-service-for-windows-server.aspx

Thanks

Mike
0
 

Author Closing Comment

by:ARM2009
ID: 37782519
clarificaiton is what i needed and mike did that.
0

Featured Post

Complete VMware vSphere® ESX(i) & Hyper-V Backup

Capture your entire system, including the host, with patented disk imaging integrated with VMware VADP / Microsoft VSS and RCT. RTOs is as low as 15 seconds with Acronis Active Restore™. You can enjoy unlimited P2V/V2V migrations from any source (even from a different hypervisor)

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A company’s centralized system that manages user data, security, and distributed resources is often a focus of criminal attention. Active Directory (AD) is no exception. In truth, it’s even more likely to be targeted due to the number of companies …
A hard and fast method for reducing Active Directory Administrators members.
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …
Attackers love to prey on accounts that have privileges. Reducing privileged accounts and protecting privileged accounts therefore is paramount. Users, groups, and service accounts need to be protected to help protect the entire Active Directory …

717 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question