Solved

Windows NTP Setup: Domain PCs not sync with PDC server

Posted on 2016-07-26
4
59 Views
Last Modified: 2016-09-05
Hi,

We have two DCs on windows server 2008R2, DC1 and DC2.
DC1 is a PDC emulator and DC2 only has infrastructure master role.

I recently configured externl NTP on DC1 without any issues. but when I run command on domain PCs and find the they are syncing with DC2 instead of DC1
DC2 is syncing from DC1

On a domain PC
c:\w32tm /query /status
Leap Indicator: 0(no warning)
Stratum: 5 (secondary reference - syncd by (S)NTP)
Precision: -6 (15.625ms per tick)
Root Delay: 0.2587585s
Root Dispersion: 0.2337305s
ReferenceId: 0x0A050128 (source IP:  10.5.1.40)
Last Successful Sync Time: 27/07/2016 1:40:40 PM
Source: DC2.domain.local
Poll Interval: 14 (16384s)

Open in new window


On DC1
C:\Users\administrator.domain>w32tm /query /source
time2.google.com

Open in new window


On DC2
C:\Users\administrator.domain>W32tm /query /source
DC1.domain.local

Open in new window


My questions are
1. Are all domain controllers can be a NTP server?
2. If DC2 is offline, will other PC automatically to sync with DC1?
3. How can I change domain PCs to sync with DC1?

Thank You
0
Comment
Question by:jzrobbie
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
4 Comments
 
LVL 14

Expert Comment

by:frankhelk
ID: 41730987
@1: Yes. Every NTP client is an NTP server (with a higher stratum), too.

@2: I presume that's true (in classic NTP, when configured to both servers, it would. With W32time, I'm unsure)

@3: With W32time: I think you can't config that behaviour.

Speaking of W32time, the timekeeping service in Windows: I 've experienced enough trouble with that piece of crap when in NTP mode to avoid using it whenever I can.

For a mature timekeeping service with well documented behaviour, I'd recommend this:

Use a Windows port of the classic *ix NTP service on your DCs, and sync 'em with NTP time sources from pool.ntp.org. For VMs, ensure to disable the time sync features of VMware (to timekeeping services on one clock will cause time chaos). The NTP service software is free. Easy to install and configure, works like a charm and is stable as a rock. And it is nicer when it comes to one of the rare cases of troubleshooting.

See my article on NTP basics for the "How To".

The classic NTP client automatically selects the time source it evaluates to be the most reliable by means of startum and network latency (and repeatedly reevaluates that) ... W32time does that, too, in NTP mode. The NTP client could be configured to prefer one or more servers among others, a feature I havn't seen with W32time.

The NTP service has a low ressource footprint, therefore the NTP functionality could be hooked onto existing machines or VM's like webservers, ftp servers, mailservers or database hosts - even in a DMZ - without visible performance impact.

If securtity is an issue, you might as well use local radio controlled clock appliances (see the article for that, too) in your LAN who serve times very reliable and precise.
0
 

Accepted Solution

by:
jzrobbie earned 0 total points
ID: 41732232
After some research, I found it needs to run this command on DC2
w32tm /config /syncfromflags:domhier /reliable:no /update
net stop w32time
net start w32time

That will remove DC2 from reliable source.

After a coulp of minutes, all domain PCs will update themselves or you cam run this command to update manually, it needs to run on elevated command prompt
w32tm /resync /rediscover
w32tm /query /source
0
 
LVL 35

Expert Comment

by:Seth Simmons
ID: 41784444
This question has been classified as abandoned and is closed as part of the Cleanup Program. See the recommendation for more details.
0

Featured Post

Edgartown IT Case Study

Learn about Edgartown's quest to ensure the safety and security of the entire town's employee and citizen data. Read the case study!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Windows 10 Policy for Flash 3 57
Application of a group policy 11 69
Setting up two DCs 4 44
Powershell - getting input from CSV File 8 15
In-place Upgrading Dirsync to Azure AD Connect
Always backup Domain, SYSVOL etc.using processes according to Microsoft Best Practices. This is meant as a disaster recovery process for small environments that did not implement backup processes and did not run a secondary domain controller that ne…
To efficiently enable the rotation of USB drives for backups, storage pools need to be created. This way no matter which USB drive is installed, the backups will successfully write without any administrative intervention. Multiple USB devices need t…
Are you ready to implement Active Directory best practices without reading 300+ pages? You're in luck. In this webinar hosted by Skyport Systems, you gain insight into Microsoft's latest comprehensive guide, with tips on the best and easiest way…

737 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question