[2 days left] What’s wrong with your cloud strategy? Learn why multicloud solutions matter with Nimble Storage.Register Now

x
?
Solved

Windows NTP Setup: Domain PCs not sync with PDC server

Posted on 2016-07-26
4
Medium Priority
?
73 Views
Last Modified: 2016-09-05
Hi,

We have two DCs on windows server 2008R2, DC1 and DC2.
DC1 is a PDC emulator and DC2 only has infrastructure master role.

I recently configured externl NTP on DC1 without any issues. but when I run command on domain PCs and find the they are syncing with DC2 instead of DC1
DC2 is syncing from DC1

On a domain PC
c:\w32tm /query /status
Leap Indicator: 0(no warning)
Stratum: 5 (secondary reference - syncd by (S)NTP)
Precision: -6 (15.625ms per tick)
Root Delay: 0.2587585s
Root Dispersion: 0.2337305s
ReferenceId: 0x0A050128 (source IP:  10.5.1.40)
Last Successful Sync Time: 27/07/2016 1:40:40 PM
Source: DC2.domain.local
Poll Interval: 14 (16384s)

Open in new window


On DC1
C:\Users\administrator.domain>w32tm /query /source
time2.google.com

Open in new window


On DC2
C:\Users\administrator.domain>W32tm /query /source
DC1.domain.local

Open in new window


My questions are
1. Are all domain controllers can be a NTP server?
2. If DC2 is offline, will other PC automatically to sync with DC1?
3. How can I change domain PCs to sync with DC1?

Thank You
0
Comment
Question by:jzrobbie
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
4 Comments
 
LVL 14

Expert Comment

by:frankhelk
ID: 41730987
@1: Yes. Every NTP client is an NTP server (with a higher stratum), too.

@2: I presume that's true (in classic NTP, when configured to both servers, it would. With W32time, I'm unsure)

@3: With W32time: I think you can't config that behaviour.

Speaking of W32time, the timekeeping service in Windows: I 've experienced enough trouble with that piece of crap when in NTP mode to avoid using it whenever I can.

For a mature timekeeping service with well documented behaviour, I'd recommend this:

Use a Windows port of the classic *ix NTP service on your DCs, and sync 'em with NTP time sources from pool.ntp.org. For VMs, ensure to disable the time sync features of VMware (to timekeeping services on one clock will cause time chaos). The NTP service software is free. Easy to install and configure, works like a charm and is stable as a rock. And it is nicer when it comes to one of the rare cases of troubleshooting.

See my article on NTP basics for the "How To".

The classic NTP client automatically selects the time source it evaluates to be the most reliable by means of startum and network latency (and repeatedly reevaluates that) ... W32time does that, too, in NTP mode. The NTP client could be configured to prefer one or more servers among others, a feature I havn't seen with W32time.

The NTP service has a low ressource footprint, therefore the NTP functionality could be hooked onto existing machines or VM's like webservers, ftp servers, mailservers or database hosts - even in a DMZ - without visible performance impact.

If securtity is an issue, you might as well use local radio controlled clock appliances (see the article for that, too) in your LAN who serve times very reliable and precise.
0
 

Accepted Solution

by:
jzrobbie earned 0 total points
ID: 41732232
After some research, I found it needs to run this command on DC2
w32tm /config /syncfromflags:domhier /reliable:no /update
net stop w32time
net start w32time

That will remove DC2 from reliable source.

After a coulp of minutes, all domain PCs will update themselves or you cam run this command to update manually, it needs to run on elevated command prompt
w32tm /resync /rediscover
w32tm /query /source
0
 
LVL 35

Expert Comment

by:Seth Simmons
ID: 41784444
This question has been classified as abandoned and is closed as part of the Cleanup Program. See the recommendation for more details.
0

Featured Post

Free learning courses: Active Directory Deep Dive

Get a firm grasp on your IT environment when you learn Active Directory best practices with Veeam! Watch all, or choose any amount, of this three-part webinar series to improve your skills. From the basics to virtualization and backup, we got you covered.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Had a business requirement to store the mobile number in an environmental variable. This is just a quick article on how this was done.
This process allows computer passwords to be managed and secured without using LAPS. This is an improvement on an existing process, enhanced to store password encrypted, instead of clear-text files within SQL
This tutorial will walk an individual through locating and launching the BEUtility application to properly change the service account username and\or password in situation where it may be necessary or where the password has been inadvertently change…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …

649 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question