Solved

VMWare host best practice to configure NTP server to PDCe or external source

Posted on 2013-11-20
12
839 Views
Last Modified: 2013-11-21
Hello EE,

We have a PDCe that all our internal environment gets it's time from.  It happens to be a VM and one time the NTP client on my host stopped running and the time on this PDCe was off and started handing out faulty time.

I am wondering how to avoid this situation?  I have my PDCe setup to NTP to time.gov but it still got the time it appears from the host.  What are the best practices and how do you have it setup?
0
Comment
Question by:bergquistcompany
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 6
  • 6
12 Comments
 
LVL 121

Accepted Solution

by:
Andrew Hancock (VMware vExpert / EE MVE^2) earned 500 total points
ID: 39663531
How we setup our clients is as follows:-

1. ESXi/ESX Hosts are set to an external time source.

2. DC, PDC emulator is set to the same external time source as in 1.

3. VMware Tools Sync time with host is disable on ALL Windows VMs. They will get time from Domain.

4. Linux/Unix VMs are synced with external time source as in 1.

I also refer you to:-

VMware KB: Timekeeping best practices for Windows, including NTP

VMware KB: Troubleshooting NTP on ESX and ESXi 4.x / 5.x

Timekeeping In VirtualMachines Whitepaper
0
 

Author Comment

by:bergquistcompany
ID: 39663724
Excellent!  Yes I found the first article and have the DC setup properly but was concerned as my hosts are getting time from the PDC that is getting time from outside and when the service stopped on one host it was really ugly and I want to make sure I'm setting it up properly to avoid.

I setup the Client, Parameter to NTP, but on the NTP server will it appear as follows or should there be no number 1.2.3:
 1.pool.ntp.org,0x1 2.pool.ntp.org,0x1 3.pool.ntp.org,0x1
0
 
LVL 121
ID: 39663960
We usually setup the Hosts to go directly to the NTP Source. (same source as PDCe)

so that would be:-

server 0.pool.ntp.org
server 1.pool.ntp.org
server 2.pool.ntp.org
server 3.pool.ntp.org

We have read, that's it's etiquitte that, only a single device from your LAN should contact an external NTP server.

I cannot remember where I read that...

but we some clients also use an NTP Virtual Server as a time server, which fetches the time from a random set of servers, to maintain accuracy, and then clients set ALL LAN devices to this NTP Virtual Server (or physical server on the LAN!).
0
When ransomware hits your clients, what do you do?

MSPs: Endpoint security isn’t enough to prevent ransomware.
As the impact and severity of crypto ransomware attacks has grown, Webroot fought back, not just by building a next-gen endpoint solution capable of preventing ransomware attacks but also by being a thought leader.

 

Author Comment

by:bergquistcompany
ID: 39664046
so in the registry I have this:
1.pool.ntp.org,0x1 2.pool.ntp.org,0x1 3.pool.ntp.org,0x1

should be:
server 0.pool.ntp.org,server 1.pool.ntp.org,server 2.pool.ntp.org, server 3.pool.ntp.org
0
 
LVL 121
ID: 39664063
fqdn is 0.pool.ntp.org etc

that's Linux config from our ntp.conf
0
 

Author Comment

by:bergquistcompany
ID: 39664105
oh I'm in the windows registry
Capture2.JPG
0
 
LVL 121
ID: 39664211
okay, a little confused here....

I'm discussing hosts getting time from external time source.

and I though your Windows is working correctly getting time from external time source?
0
 

Author Comment

by:bergquistcompany
ID: 39664310
Ok my bad put the setting in VMware, thought should change PDCe to point to same location
0
 
LVL 121
ID: 39664356
both PDCe and VMware Hosts should point to same NTP location.

some organizations have their own time server.
0
 

Author Comment

by:bergquistcompany
ID: 39664368
Ok ill change the PDCe then too once I figure how to add the list.  Thanks
0
 
LVL 121
ID: 39664432
so what are you Windows server set to currently?
0
 

Author Comment

by:bergquistcompany
ID: 39664566
Time.gov
0

Featured Post

Free Tool: Path Explorer

An intuitive utility to help find the CSS path to UI elements on a webpage. These paths are used frequently in a variety of front-end development and QA automation tasks.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

When converting a physical machine to a virtual machine using VMware vCenter Converter Standalone or vCenter Converter Enterprise, if an adapter type is not selected during the initial customization the resulting virtual machine may contain an IDE d…
This article outlines why you need to choose a backup solution that protects your entire environment – including your VMware ESXi and Microsoft Hyper-V virtualization hosts – not just your virtual machines.
Teach the user how to use vSphere Update Manager to update the VMware Tools and virtual machine hardware version Open vSphere Client: Review manual processes for updating VMware Tools and virtual hardware versions: Create a new baseline group in vSp…
Advanced tutorial on how to run the esxtop command to capture a batch file in csv format in order to export the file and use it for performance analysis. He demonstrates how to download the file using a vSphere web client (or vSphere client) and exp…
Suggested Courses

617 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question