?
Solved

Windows NTP Setup: Domain PCs not sync with PDC server

Posted on 2016-07-26
4
Medium Priority
?
69 Views
Last Modified: 2016-09-05
Hi,

We have two DCs on windows server 2008R2, DC1 and DC2.
DC1 is a PDC emulator and DC2 only has infrastructure master role.

I recently configured externl NTP on DC1 without any issues. but when I run command on domain PCs and find the they are syncing with DC2 instead of DC1
DC2 is syncing from DC1

On a domain PC
c:\w32tm /query /status
Leap Indicator: 0(no warning)
Stratum: 5 (secondary reference - syncd by (S)NTP)
Precision: -6 (15.625ms per tick)
Root Delay: 0.2587585s
Root Dispersion: 0.2337305s
ReferenceId: 0x0A050128 (source IP:  10.5.1.40)
Last Successful Sync Time: 27/07/2016 1:40:40 PM
Source: DC2.domain.local
Poll Interval: 14 (16384s)

Open in new window


On DC1
C:\Users\administrator.domain>w32tm /query /source
time2.google.com

Open in new window


On DC2
C:\Users\administrator.domain>W32tm /query /source
DC1.domain.local

Open in new window


My questions are
1. Are all domain controllers can be a NTP server?
2. If DC2 is offline, will other PC automatically to sync with DC1?
3. How can I change domain PCs to sync with DC1?

Thank You
0
Comment
Question by:jzrobbie
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
4 Comments
 
LVL 14

Expert Comment

by:frankhelk
ID: 41730987
@1: Yes. Every NTP client is an NTP server (with a higher stratum), too.

@2: I presume that's true (in classic NTP, when configured to both servers, it would. With W32time, I'm unsure)

@3: With W32time: I think you can't config that behaviour.

Speaking of W32time, the timekeeping service in Windows: I 've experienced enough trouble with that piece of crap when in NTP mode to avoid using it whenever I can.

For a mature timekeeping service with well documented behaviour, I'd recommend this:

Use a Windows port of the classic *ix NTP service on your DCs, and sync 'em with NTP time sources from pool.ntp.org. For VMs, ensure to disable the time sync features of VMware (to timekeeping services on one clock will cause time chaos). The NTP service software is free. Easy to install and configure, works like a charm and is stable as a rock. And it is nicer when it comes to one of the rare cases of troubleshooting.

See my article on NTP basics for the "How To".

The classic NTP client automatically selects the time source it evaluates to be the most reliable by means of startum and network latency (and repeatedly reevaluates that) ... W32time does that, too, in NTP mode. The NTP client could be configured to prefer one or more servers among others, a feature I havn't seen with W32time.

The NTP service has a low ressource footprint, therefore the NTP functionality could be hooked onto existing machines or VM's like webservers, ftp servers, mailservers or database hosts - even in a DMZ - without visible performance impact.

If securtity is an issue, you might as well use local radio controlled clock appliances (see the article for that, too) in your LAN who serve times very reliable and precise.
0
 

Accepted Solution

by:
jzrobbie earned 0 total points
ID: 41732232
After some research, I found it needs to run this command on DC2
w32tm /config /syncfromflags:domhier /reliable:no /update
net stop w32time
net start w32time

That will remove DC2 from reliable source.

After a coulp of minutes, all domain PCs will update themselves or you cam run this command to update manually, it needs to run on elevated command prompt
w32tm /resync /rediscover
w32tm /query /source
0
 
LVL 35

Expert Comment

by:Seth Simmons
ID: 41784444
This question has been classified as abandoned and is closed as part of the Cleanup Program. See the recommendation for more details.
0

Featured Post

Ransomware-A Revenue Bonanza for Service Providers

Ransomware – malware that gets on your customers’ computers, encrypts their data, and extorts a hefty ransom for the decryption keys – is a surging new threat.  The purpose of this eBook is to educate the reader about ransomware attacks.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Let's recap what we learned from yesterday's Skyport Systems webinar.
In the absence of a fully-fledged GPO Management product like AGPM, the script in this article will provide you with a simple way to watch the domain (or a select OU) for GPOs changes and automatically take backups when policies are added, removed o…
To efficiently enable the rotation of USB drives for backups, storage pools need to be created. This way no matter which USB drive is installed, the backups will successfully write without any administrative intervention. Multiple USB devices need t…
This tutorial will show how to configure a single USB drive with a separate folder for each day of the week. This will allow each of the backups to be kept separate preventing the previous day’s backup from being overwritten. The USB drive must be s…
Suggested Courses

765 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question