Linux, FreeBSD, Juniper, Cisco / Network security articles and troubleshooting guides

FAQ
It is currently Thu Mar 30, 2023 6:39 pm


Tutorials applicable on more than one Unix/Linux OS and shell scripts: ssh / openssl / protocols.

Author Message
debuser
Post  Post subject: Linux/FreeBSD how to check ntp time synchronization  |  Posted: Tue Nov 01, 2011 9:50 am

Joined: Thu Aug 06, 2009 2:48 am
Posts: 105

Offline
 

Linux/FreeBSD how to check ntp time synchronization

Giving that a system has ntpd up&running, ntpq utility can be used to check system time synchronization:
Code:
# ntpq -pn
     remote           refid      st t when poll reach   delay   offset  jitter
==============================================================================
+80.96.120.251   .PPS.            1 u  984 1024  377   10.723   -0.909   1.437
+80.96.120.252   .PPS.            1 u  851 1024  377   10.800   -0.503   0.476
*80.96.120.253   .PPS.            1 u 1019 1024  377   10.611   -0.698   0.669


Man ntpq quote:
Quote:
NTPQ(8) FreeBSD System Manager's Manual NTPQ(8)

NAME
ntpq -- standard NTP query program

SYNOPSIS
ntpq [-inp] [-c command] [host] [...]

DESCRIPTION
The ntpq utility is used to monitor NTP daemon ntpd(8) operations and
determine performance. It uses the standard NTP mode 6 control message
formats defined in Appendix B of the NTPv3 specification RFC1305. The
same formats are used in NTPv4, although some of the variables have
changed and new ones added. The description on this page is for the
NTPv4 variables.
...
-n Output all host addresses in dotted-quad numeric format rather
than converting to the canonical host names.

-p Print a list of the peers known to the server as well as a sum-
mary of their state. This is equivalent to the peers interactive
command.






Top
debuser
Post  Post subject: Re: Linux/FreeBSD how to check ntp time synchronization  |  Posted: Tue Nov 01, 2011 10:01 am

Joined: Thu Aug 06, 2009 2:48 am
Posts: 105

Offline
Indication of the character to the left of the host:
Quote:
<sp> discarded due to high stratum and/or failed sanity checks;
"x" designated falsticker by the intersection algorithm;
"." culled from the end of the candidate list;
"-" discarded by the clustering algorithm;
"+" included in the final selection set;
"#" selected for synchronization but distance exceeds maximum;
"*" selected for synchronization;
and
"o" selected for synchronization, PPS signal in use.


Top
wnbv85
Post  Post subject: Re: Linux/FreeBSD how to check ntp time synchronization  |  Posted: Thu Dec 01, 2011 8:10 am

Joined: Tue Nov 29, 2011 9:41 am
Posts: 3

Offline
hi
I have a question concerning AD Time sync. We block NTP on our firewalls so
our main DC cannot get out to a tick and tock server to grab time. At this
point we are getting some w32time warnings (Event ID: 31) in our system
logs. We are debating two options one is to open NTP on our firewalls. 2 to
use a 3rd party app to go grab time from a server over http then point our
main dc to that machine for ntp. My question is has anyone used anything
third party apps for that and if not does any one have any best practices
for time sync? I do understand how important time sync is in AD for
replication purposes so any help would be appreciated...


Top
admin
Post  Post subject: Re: Linux/FreeBSD how to check ntp time synchronization  |  Posted: Tue Dec 06, 2011 8:22 am
Site Admin

Joined: Mon Aug 03, 2009 8:43 am
Posts: 104

Offline
wnbv85 wrote:
hi
I have a question concerning AD Time sync. We block NTP on our firewalls so
our main DC cannot get out to a tick and tock server to grab time. At this
point we are getting some w32time warnings (Event ID: 31) in our system
logs. We are debating two options one is to open NTP on our firewalls. 2 to
use a 3rd party app to go grab time from a server over http then point our
main dc to that machine for ntp. My question is has anyone used anything
third party apps for that and if not does any one have any best practices
for time sync? I do understand how important time sync is in AD for
replication purposes so any help would be appreciated...


Hi wnbv85,

Some firewalls can be set up to act as ntp servers for your network. For example, Juniper SRX firewalls:
Code:
    user@host# set system ntp server 78.46.194.186 version 4 prefer
    user@host# set system ntp server 88.198.34.114 version 4

I'm sure Cisco supports it, too.

Or if you're using FreeBSD/PF or Linux, it's very simple to set it up on your firewall.

_________________
VPSie - SSD VPS servers in AMS-IX, LINX, DE-CIX
https://vpsie.com


Top
Harespok
Post  Post subject: Re: Linux/FreeBSD how to check ntp time synchronization  |  Posted: Wed Aug 01, 2012 6:59 am
FreeBSD use the packet-switched, variable-latency data networks, computer systems, clock synchronization, network time protocol (NTP). NTP uses UDP port 123. If you have a computer or a single server, then you can easily synchronize with other NTP server time. All you need is an NTP client called ntpdate This is good. It uses to set the date and time of the NTP server.


Top
Display posts from previous:  Sort by  
E-mail friendPrint view

Topics related to - "Linux/FreeBSD how to check ntp time synchronization"
 Topics   Author   Replies   Views   Last post 
There are no new unread posts for this topic. Linux/FreeBSD: How to find process start time or running time with PS

admin

0

7797

Wed Jan 21, 2015 12:25 pm

admin View the latest post

There are no new unread posts for this topic. How to check SSL ciphers used in a web server's configuration ciphersuites

mandrei99

1

19007

Fri May 04, 2012 6:28 am

mandrei99 View the latest post

There are no new unread posts for this topic. Linux - zip command to archive directory recursive

debuser

1

6306

Sat Aug 04, 2012 8:03 am

Harespok View the latest post

There are no new unread posts for this topic. How to change user login shell to bash in Linux

mandrei99

0

2809

Thu Jan 22, 2015 11:37 am

mandrei99 View the latest post

There are no new unread posts for this topic. Linux - Unable to login (and authentication succeeds) - File size limit exceeded

debuser

3

3194

Tue Dec 06, 2011 8:24 am

admin View the latest post

 

Who is online
Users browsing this forum: No registered users and 1 guest
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum
Jump to:  
cronNews News Site map Site map SitemapIndex SitemapIndex RSS Feed RSS Feed Channel list Channel list


Delete all board cookies | The team | All times are UTC - 5 hours [ DST ]



phpBB SEO