Solved

Set Windows (non domain joined) member server to sync time with a domain controller.

Posted on 2013-11-20
4
3,094 Views
Last Modified: 2014-03-13
Hi

I have a few servers that live in our DMZ that I wish to sync with our domain controller that is on the inside network.  These servers in the DMZ are not joined to the domain and are also running inside a Hyper V virtual machine which I believe is what is causing the time drift

The servers all run Windows Server 2008 R2.

So I am wondering how to set these servers to sync with the domain controller that is inside the private internal network.

I also understand firewall rules would need to be adjusted order for the servers in the DMZ to communicate with the domain controller.

I've been researching this, but am getting a lot of conflicting information, and some article indicate there is no concrete fix to get a non domain server to time sync with a Windows domain controller.

Looking for help,

Thank you!
0
Comment
Question by:paradigm_IS
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
4 Comments
 
LVL 6

Expert Comment

by:vmdude
ID: 39664164
How do your domain controllers keep time? Are they syncing with an external NTP time source? If so one option you might consider is allowing the servers in the DMZ to sync to the same NTP host.

Maybe not the answer you are looking for but just thought I'd throw it our there :)
0
 

Author Comment

by:paradigm_IS
ID: 39664185
Hi vmdude

I thought of that, but part of my problem is I am not entirely certain how to determine how my domain controller is keeping it's time.

I run this command on my domain controller:

w32tm /query /source

I get this result:
Free-running System Clock

Which I *think* means it is not syncing to anything other than the onboard RTC chip.


Thanks
0
 
LVL 6

Accepted Solution

by:
vmdude earned 500 total points
ID: 39664259
Try running the following command instead, this will tell you if you have any NTP time providers configured on your domian.

w32tm /query /configuration

My advice would be to first get the domain controller holding the PDC FSMO role (not sure how big your environment is so could all be the same server) syncing with a reliable NTP server I normally use ones from the following site http://www.pool.ntp.org/en/ 

To configure NTP is actually fairly straightforward the following commands will do it

C:\> w32tm /config /manualpeerlist:"0.pool.ntp.org,1.pool.ntp.org,2.pool.ntp.org" /syncfromflags:manual
C:\> w32tm /config /update
C:\> w32tm /resync
0
 

Author Closing Comment

by:paradigm_IS
ID: 39927868
That did the trick.
0

Featured Post

Why Off-Site Backups Are The Only Way To Go

You are probably backing up your data—but how and where? Ransomware is on the rise and there are variants that specifically target backups. Read on to discover why off-site is the way to go.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article is a collection of issues that people face from time to time and possible solutions to those issues. I hope you enjoy reading it.
When asking a question in a forum or creating documentation, screenshots are vital tools that can convey a lot more information and save you and your reader a lot of time
In this video, viewers will be given step by step instructions on adjusting mouse, pointer and cursor visibility in Microsoft Windows 10. The video seeks to educate those who are struggling with the new Windows 10 Graphical User Interface. Change Cu…
In this video, viewers are given an introduction to using the Windows 10 Snipping Tool, how to quickly locate it when it's needed and also how make it always available with a single click of a mouse button, by pinning it to the Desktop Task Bar. Int…

726 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question