NTP Rule for DC doesn't work

Tech-Archive recommends: Fix windows errors by optimizing your registry



Hi

I'm trying to get my win2003 dc to sync with an external time source. All
the other servers are set to nt5ds (sync using domain hierarchy), as per
default behaviour.

The access rule in the firewall is as follows:

To: (computer object with ip of external ntp)
From: (computer object representing the dc)
Protocol: NTP(UDP)
All Users

The dc resolves the address of the ntp server but can't connect. I've tried
this all sorts of different ways including allowing 2-way comms between the
two hosts.

The isa 2004 logging screen reports outbound traffic on NTP(UDP) to the ntp
server's ip and then a "Denied Connection" action, but without any rule name.

The network is in a standard back-to-back DMZ with dual-homed ISA in front
of the servers, and a WatchGuard firebox further out sitting between the
Internet router and the ISA. The WG allows NTP.

I've tried to solve this for 2 days and got nowhere! Any help much
appreciated...
.



Relevant Pages

  • Re: handling falseticker
    ... This would lead to a "lost sync" or a "sync to ... recognized by the clients and this NTP path will be ignored. ... Both Stratum 1 will keep being sync with the respective Stratum 0 because ... This means that my Stratum 2 Servers have only 2 servers. ...
    (comp.protocols.time.ntp)
  • Re: Cant time sync with Windows 2003 Server Std.
    ... but would the router block outgoing connections? ... Any other oddities that 2K3R2 Server may need to have NTP sync work? ... I've tried several NTP servers in this box with no success. ...
    (microsoft.public.windows.server.general)
  • Re: Re-establishing VPN connection when ISP forces new IP address
    ... We setup both Syslog logging and NTP to sync with servers on ...
    (comp.dcom.sys.cisco)
  • Re: Re-establishing VPN connection when ISP forces new IP address
    ... We setup both Syslog logging and NTP to sync with servers on ...
    (comp.dcom.sys.cisco)
  • Re: Setting Up NTP Subnet
    ... > I have questions regarding best practices on architecture of NTP ... > it sufficient to use multiple GPS receivers with ACTS dial ... The lower the stratum the bigger the ... servers and that the servers at this level should peer. ...
    (comp.protocols.time.ntp)