Solved

Windows NTP Setup: Domain PCs not sync with PDC server

Posted on 2016-07-26
4
33 Views
Last Modified: 2016-09-05
Hi,

We have two DCs on windows server 2008R2, DC1 and DC2.
DC1 is a PDC emulator and DC2 only has infrastructure master role.

I recently configured externl NTP on DC1 without any issues. but when I run command on domain PCs and find the they are syncing with DC2 instead of DC1
DC2 is syncing from DC1

On a domain PC
c:\w32tm /query /status
Leap Indicator: 0(no warning)
Stratum: 5 (secondary reference - syncd by (S)NTP)
Precision: -6 (15.625ms per tick)
Root Delay: 0.2587585s
Root Dispersion: 0.2337305s
ReferenceId: 0x0A050128 (source IP:  10.5.1.40)
Last Successful Sync Time: 27/07/2016 1:40:40 PM
Source: DC2.domain.local
Poll Interval: 14 (16384s)

Open in new window


On DC1
C:\Users\administrator.domain>w32tm /query /source
time2.google.com

Open in new window


On DC2
C:\Users\administrator.domain>W32tm /query /source
DC1.domain.local

Open in new window


My questions are
1. Are all domain controllers can be a NTP server?
2. If DC2 is offline, will other PC automatically to sync with DC1?
3. How can I change domain PCs to sync with DC1?

Thank You
0
Comment
Question by:jzrobbie
4 Comments
 
LVL 14

Expert Comment

by:frankhelk
ID: 41730987
@1: Yes. Every NTP client is an NTP server (with a higher stratum), too.

@2: I presume that's true (in classic NTP, when configured to both servers, it would. With W32time, I'm unsure)

@3: With W32time: I think you can't config that behaviour.

Speaking of W32time, the timekeeping service in Windows: I 've experienced enough trouble with that piece of crap when in NTP mode to avoid using it whenever I can.

For a mature timekeeping service with well documented behaviour, I'd recommend this:

Use a Windows port of the classic *ix NTP service on your DCs, and sync 'em with NTP time sources from pool.ntp.org. For VMs, ensure to disable the time sync features of VMware (to timekeeping services on one clock will cause time chaos). The NTP service software is free. Easy to install and configure, works like a charm and is stable as a rock. And it is nicer when it comes to one of the rare cases of troubleshooting.

See my article on NTP basics for the "How To".

The classic NTP client automatically selects the time source it evaluates to be the most reliable by means of startum and network latency (and repeatedly reevaluates that) ... W32time does that, too, in NTP mode. The NTP client could be configured to prefer one or more servers among others, a feature I havn't seen with W32time.

The NTP service has a low ressource footprint, therefore the NTP functionality could be hooked onto existing machines or VM's like webservers, ftp servers, mailservers or database hosts - even in a DMZ - without visible performance impact.

If securtity is an issue, you might as well use local radio controlled clock appliances (see the article for that, too) in your LAN who serve times very reliable and precise.
0
 

Accepted Solution

by:
jzrobbie earned 0 total points
ID: 41732232
After some research, I found it needs to run this command on DC2
w32tm /config /syncfromflags:domhier /reliable:no /update
net stop w32time
net start w32time

That will remove DC2 from reliable source.

After a coulp of minutes, all domain PCs will update themselves or you cam run this command to update manually, it needs to run on elevated command prompt
w32tm /resync /rediscover
w32tm /query /source
0
 
LVL 34

Expert Comment

by:Seth Simmons
ID: 41784444
This question has been classified as abandoned and is closed as part of the Cleanup Program. See the recommendation for more details.
0

Featured Post

Backup Your Microsoft Windows Server®

Backup all your Microsoft Windows Server – on-premises, in remote locations, in private and hybrid clouds. Your entire Windows Server will be backed up in one easy step with patented, block-level disk imaging. We achieve RTOs (recovery time objectives) as low as 15 seconds.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Find out how to use Active Directory data for email signature management in Microsoft Exchange and Office 365.
The recent Microsoft changes on update philosophy for Windows pre-10 and their impact on existing WSUS implementations.
This tutorial will walk an individual through the steps necessary to enable the VMware\Hyper-V licensed feature of Backup Exec 2012. In addition, how to add a VMware server and configure a backup job. The first step is to acquire the necessary licen…
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …

867 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

16 Experts available now in Live!

Get 1:1 Help Now