<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do I debug NTP not working? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-do-i-debug-ntp-not-working/m-p/14010#M10287</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;For the systems I'm working on right now. The active PA in the HA group is marked as synchronized, the passive PA still isn't, though the passive PA's time matches my local systems time. I can see that by issuing:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show clock&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 30 Oct 2013 19:07:10 GMT</pubDate>
    <dc:creator>ddaniels</dc:creator>
    <dc:date>2013-10-30T19:07:10Z</dc:date>
    <item>
      <title>How do I debug NTP not working?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-do-i-debug-ntp-not-working/m-p/14007#M10284</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;(active)&amp;gt; (active)&amp;gt; show ntp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NTP state:&lt;BR /&gt;NTP synched to LOCAL&lt;BR /&gt;NTP server secondaryNtpIp connected: False&lt;BR /&gt;NTP server primaryNtpIp connected: False&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried debug software restart ntp, waited a while and got the same results. The time's off my system clock by less than a minute.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Oct 2013 18:08:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-do-i-debug-ntp-not-working/m-p/14007#M10284</guid>
      <dc:creator>ddaniels</dc:creator>
      <dc:date>2013-10-30T18:08:44Z</dc:date>
    </item>
    <item>
      <title>Re: How do I debug NTP not working?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-do-i-debug-ntp-not-working/m-p/14008#M10285</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;seems it is not connecting to your NTP Local.&lt;/P&gt;&lt;P&gt;if it is not mandatory for you use pool.ntp.org and try again.&lt;/P&gt;&lt;P&gt;Do you have service route configured ? Do you use management interface or other for Ntp ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also check&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-3684" title="https://live.paloaltonetworks.com/docs/DOC-3684"&gt;https://live.paloaltonetworks.com/docs/DOC-3684&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Oct 2013 18:36:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-do-i-debug-ntp-not-working/m-p/14008#M10285</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-10-30T18:36:47Z</dc:date>
    </item>
    <item>
      <title>Re: How do I debug NTP not working?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-do-i-debug-ntp-not-working/m-p/14009#M10286</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm using the management interface, the routing is working and I'm specifying internal IP's that I've verified are working for other things.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Oct 2013 18:55:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-do-i-debug-ntp-not-working/m-p/14009#M10286</guid>
      <dc:creator>ddaniels</dc:creator>
      <dc:date>2013-10-30T18:55:46Z</dc:date>
    </item>
    <item>
      <title>Re: How do I debug NTP not working?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-do-i-debug-ntp-not-working/m-p/14010#M10287</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;For the systems I'm working on right now. The active PA in the HA group is marked as synchronized, the passive PA still isn't, though the passive PA's time matches my local systems time. I can see that by issuing:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show clock&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Oct 2013 19:07:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-do-i-debug-ntp-not-working/m-p/14010#M10287</guid>
      <dc:creator>ddaniels</dc:creator>
      <dc:date>2013-10-30T19:07:10Z</dc:date>
    </item>
    <item>
      <title>Re: How do I debug NTP not working?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-do-i-debug-ntp-not-working/m-p/14011#M10288</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I don't know why, but I fixed this issue by referencing a slightly more stable clock, and switching to only reference that clock.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When in HA mode and having auto-updates, it's important to have updates apply at the same time so both systems should be synchronized to a high stability, low latency, low jitter to access clock.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Nov 2013 05:29:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-do-i-debug-ntp-not-working/m-p/14011#M10288</guid>
      <dc:creator>ddaniels</dc:creator>
      <dc:date>2013-11-15T05:29:33Z</dc:date>
    </item>
    <item>
      <title>Re: How do I debug NTP not working?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-do-i-debug-ntp-not-working/m-p/14012#M10289</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;How much did the box who didnt like to sync to NTP differ from realtime? If im not incorrect the NTP process usually refuse to sync the time if it differes more than 2 hours or something like that. To fix this you must first manually set the clock somewhat close to realtime and then start the NTP process (or make sure that ntpdate is being used during boot to set the clock "hard" before the ntpd client starts).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 01 Dec 2013 17:10:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-do-i-debug-ntp-not-working/m-p/14012#M10289</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2013-12-01T17:10:44Z</dc:date>
    </item>
    <item>
      <title>Re: How do I debug NTP not working?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-do-i-debug-ntp-not-working/m-p/14013#M10290</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I don't recall exactly now. If there was a difference it was less than a few seconds with a low jitter and a low reach (time servers were local, their were local stratum 4, low jitter, low reach, the source clocks sources during testing were low jitter, low reach, stratum 3).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="loading" href="http://doc.ntp.org/4.1.2/miscopt.htm" title="http://doc.ntp.org/4.1.2/miscopt.htm"&gt;http://doc.ntp.org/4.1.2/miscopt.htm&lt;/A&gt; says the tinker panic is 1000 s.&lt;/P&gt;&lt;P&gt;For authentication related issues &lt;A class="loading" href="http://web.mit.edu/kerberos/krb5-1.5/krb5-1.5.4/doc/krb5-admin/Clock-Skew.html" title="http://web.mit.edu/kerberos/krb5-1.5/krb5-1.5.4/doc/krb5-admin/Clock-Skew.html"&gt;http://web.mit.edu/kerberos/krb5-1.5/krb5-1.5.4/doc/krb5-admin/Clock-Skew.html&lt;/A&gt; says "the default value for maximum clock skew is 300 seconds, or five minutes".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Additionally many machines won't synchronize if the stratum is higher than 9. There's also considerations like jitter and reach.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Manually adjusting time on an ntp server can cause all it's clients to see high jitter and should be avoided. There's mechanisms in place by ntp to skew time in the right direction if allowed (see things like ntp reference above).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Jan 2014 17:53:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-do-i-debug-ntp-not-working/m-p/14013#M10290</guid>
      <dc:creator>ddaniels</dc:creator>
      <dc:date>2014-01-15T17:53:11Z</dc:date>
    </item>
    <item>
      <title>Re: How do I debug NTP not working?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-do-i-debug-ntp-not-working/m-p/14014#M10291</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Setting the time manually was on the box running the ntp client (in case my previous post was confusing &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Jan 2014 08:37:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-do-i-debug-ntp-not-working/m-p/14014#M10291</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2014-01-21T08:37:20Z</dc:date>
    </item>
  </channel>
</rss>

