Solved

How to diagnose time issues in a large 2003 domain?

Posted on 2012-12-26
9
231 Views
Last Modified: 2013-01-09
Hello,

We have a large (5500+) mixed OS (mostly Win7, a few WinXP) environment, with 6 Server 2003 DCs, running at a 2003 Functional Level.  These DC's are housed in four separate locations, all 'direct' connected to our home office via fiber.

We've noticed a time discrepancy in the past month or two with workstation time.  Initial diagnosis showed us that there are varying times between the six domain controllers.

The DC setup seems consistent and correct (as far as I know it... I don't have much experience with Server 2003).  DC2 has the PDC Emulator role, and is configured to use 0.north-america.pool.ntp.org as it's time server.  All other DCs are configured to look to DC2 for their time.

The odd thing is that even though we currently have a discrepancy of more than 3 minutes between DC1 and DC2, there are no (that I can find, anyway) NTP errors being reported on either server.

Can someone assist me in troubleshooting this?

Thank you.


Scott
0
Comment
Question by:meelnah
  • 5
  • 4
9 Comments
 
LVL 25

Expert Comment

by:Tony Giangreco
ID: 38722955
I would check the interval time is checked on your Main DC and setup a manual task on the other DC's to sync their time with the Main DC every hour or two. Then monitor them all a few times a day to see if they stay synced.
0
 
LVL 1

Author Comment

by:meelnah
ID: 38724679
Hi TG-TIS,

Thanks for the response.

I'm not sure exactly how you meant I should 'check the interval time on my main DC', but we may have a handle the issue now.

I ran 'w32tm /monitor' and found all six DC's reporting in were showing that they were syncing with DC2 (our PDC Emulator), but 4 of the six were 195 seconds off.  Also, the RefID in the results from the /monitor command referenced a forest root server, not the PDC Emulator.

I wasn't even aware that we had a forest root server (we have only one domain... it is a legacy server that was never removed from the network), but it was also set to pull it's time from an external time source.

To resolve, I left the FR server alone and configured the PDC Emulator's NtpServer registry setting to point to the FR server, rather than an external source.

I then went to each DC and verified (and in some cases reset) their NtpServer entry to the PDC Emulator, and their 'type' to NT5DS.

Afterward, I restarted the W32Time service on each, and then resync'd using w32tm /resync /rediscover.

So far, so good... each server is within 2 one-hundredths of the PDC.  I'll check again tomorrow.


sm
0
 
LVL 1

Author Comment

by:meelnah
ID: 38759031
Sorry for the late response...

The DC's are all keeping time correctly (3 weeks and counting)... however, some workstations in the domain are reporting being a few minutes off, even after multiple logoffs/reboots.

Any ideas how to troubleshoot this?
0
Backup Solution for AWS

Read about how CloudBerry Backup fully integrates your backups with Amazon S3 and Amazon Glacier to provide military-grade encryption and dramatically cut storage costs on any platform.

 
LVL 25

Expert Comment

by:Tony Giangreco
ID: 38759084
I've seen this before on older servers. what I did was add a scheduled task to the PDC to resync time with it's internet time server twice a day at specific times line 6AM and 6PM.

Add a scheduled task to all the uther servers to resync with the DC and different times so they al don't request time updates together. if this does not resolve the problem, let me know.
0
 
LVL 1

Author Comment

by:meelnah
ID: 38759111
Our problem isn't with the DCs at this point, but with some workstations in our environment.

I could potentially add w32tm /resync to the logon script for the workstations, if that's what you mean...
0
 
LVL 25

Expert Comment

by:Tony Giangreco
ID: 38759151
Yes, that should wok fine. you might have some Pc's that are loosing time due to hardware or other issues. Adding a schedule task to resync should resolve the problem on those Pc's.
0
 
LVL 1

Author Comment

by:meelnah
ID: 38759220
Ok...

Would the line just be w32tm /resync?  There are a host of other switches...
0
 
LVL 25

Accepted Solution

by:
Tony Giangreco earned 500 total points
ID: 38759283
You can probably put this in a batch file and add it as a scheduled task on the workstions

w32tm /resync
0
 
LVL 1

Author Comment

by:meelnah
ID: 38759285
i will give it a shot... thanks!
0

Featured Post

What is SQL Server and how does it work?

The purpose of this paper is to provide you background on SQL Server. It’s your self-study guide for learning fundamentals. It includes both the history of SQL and its technical basics. Concepts and definitions will form the solid foundation of your future DBA expertise.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
VM server storage space expansion to improve the Server performance. 2 98
How to customise Office 2016 font settings with a GPO 3 102
DHCP server 6 63
DNS/WINS in a domain 10 37
Organizations create, modify, and maintain huge amounts of data to help their businesses earn money and generally function.  Typically every network user within an organization has a bit of disk space to store in process items and personal files.   …
While rebooting windows server 2003 server , it's showing "active directory rebuilding indices please wait" at startup. It took a little while for this process to complete and once we logged on not all the services were started so another reboot is …
In an interesting question (https://www.experts-exchange.com/questions/29008360/) here at Experts Exchange, a member asked how to split a single image into multiple images. The primary usage for this is to place many photographs on a flatbed scanner…

679 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question