<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NTP not working once authentication is enabled in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ntp-not-working-once-authentication-is-enabled/m-p/515641#M107091</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/202203"&gt;@Pras&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;See my suggestions below:&lt;/P&gt;
&lt;P&gt;-&amp;nbsp;&lt;SPAN&gt;NTP authentication checks the authenticity of NTP server before&amp;nbsp;&lt;SPAN&gt;&lt;SPAN class="" data-enable-toggle-animation="true" data-extra-container-classes="ZLo7Eb" data-hover-hide-delay="1000" data-hover-open-delay="500" data-send-open-event="true" data-theme="0" data-width="250" data-ved="2ahUKEwi54O3u0Kb6AhUyPewKHX84AO4QmpgGegQIFBAD"&gt;&lt;SPAN class="" data-bubble-link="" data-segment-text="synchronizing"&gt;synchronizing&lt;SPAN&gt;&amp;nbsp;local time with the server, so I would double check the ntp auth type (md5/sha1), the symmetric auth-key (the shared password), and the NTP version.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;- pcap wise, I would start with the very basic which is confirming I see a request/reply (although you mentioned it was working before w/o the auth). Next, I would inspect to see what NTP version is used and review the NTP header flags.&lt;/P&gt;
&lt;P&gt;- &lt;SPAN&gt;Do you have service routes configured? Do you use the mgmt interface or other for NTP?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;- If possible try switching to a different public ntp?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;- Do you have two ntp server configured? if yes, either try removing one or make sure the key-id is different.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;- filter under "monitor &amp;gt; logs &amp;gt; system" using&amp;nbsp;(subtype eq ntpd) for any information regarding the ntp events.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;- try "debug software restart process ntp" on the firewall and then try the show command again, if it still fails check the dagger log again.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;regards,&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 21 Sep 2022 20:30:42 GMT</pubDate>
    <dc:creator>vzamy</dc:creator>
    <dc:date>2022-09-21T20:30:42Z</dc:date>
    <item>
      <title>NTP not working once authentication is enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ntp-not-working-once-authentication-is-enabled/m-p/515049#M106888</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;
&lt;P&gt;NTP was working well. But when authentication was enabled below msg&amp;nbsp; is seen on the Firewall (NTP Stopped working)&lt;/P&gt;
&lt;P&gt;NTP server is a local one using IP address (not FQDN)&lt;/P&gt;
&lt;P&gt;PAN-OS Version 10.1.5-h1&lt;/P&gt;
&lt;P&gt;All the other devices are syncing except for the Firewall.&lt;/P&gt;
&lt;DIV id="tinyMceEditorparagkarki143_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="paragkarki143_1-1663308368803.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/43898i0D5769E6B1A5FD68/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="paragkarki143_1-1663308368803.png" alt="paragkarki143_1-1663308368803.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Has anyone else seen this issue?&lt;/P&gt;
&lt;P&gt;Any help would be greatly appreciated.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/125239"&gt;@vzamy&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Sep 2022 06:19:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ntp-not-working-once-authentication-is-enabled/m-p/515049#M106888</guid>
      <dc:creator>Pras</dc:creator>
      <dc:date>2022-09-16T06:19:25Z</dc:date>
    </item>
    <item>
      <title>Re: NTP not working once authentication is enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ntp-not-working-once-authentication-is-enabled/m-p/515208#M106892</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/202203"&gt;@Pras&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;Based on the panos version you are running, I would first say upgrade to the latest recommended asap. (10.1.5 had it's issues)&lt;/P&gt;
&lt;P&gt;If after upgrading the panos you are still experiencing the issue, please provide more info.&lt;/P&gt;
&lt;P&gt;What type of troubleshooting have you done?&lt;/P&gt;
&lt;P&gt;-&amp;nbsp;Per your output, it shows that the NTP is not reachable, did you rule that out?&lt;/P&gt;
&lt;P&gt;- What type of authentication are you using? md5/sha1?&lt;/P&gt;
&lt;P&gt;- Did you try using "show counter global filter delta yes packet-filter yes" combined with a pcap filter. (mandatory)&lt;/P&gt;
&lt;P&gt;- Do you have a pcap? what do you see there?&lt;/P&gt;
&lt;P&gt;regards,&lt;/P&gt;</description>
      <pubDate>Sun, 18 Sep 2022 07:53:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ntp-not-working-once-authentication-is-enabled/m-p/515208#M106892</guid>
      <dc:creator>vzamy</dc:creator>
      <dc:date>2022-09-18T07:53:27Z</dc:date>
    </item>
    <item>
      <title>Re: NTP not working once authentication is enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ntp-not-working-once-authentication-is-enabled/m-p/515405#M107037</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/125239"&gt;@vzamy&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Thanks for your reply. Please find my replies as below:&lt;/P&gt;
&lt;P&gt;This deployment was working well before. But when customer tried to implement&amp;nbsp; authentication, it stopped. Even now, this works well if the authentication is removed. (no upgrades were performed)&lt;/P&gt;
&lt;P&gt;-&amp;nbsp;Per your output, it shows that the NTP is not reachable, did you rule that out?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;it is reachable- it's only not reachable when authentication is enabled&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;- What type of authentication are you using? md5/sha1?&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Tried on both md5/sha- both not working&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;- Did you try using "show counter global filter delta yes packet-filter yes" combined with a pcap filter. (mandatory)&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Not yet- since it works well with no authentication&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;- Do you have a pcap? what do you see there?&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Not Yet (even if I take what should I be looking at in it?)&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Thanks again.&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Sep 2022 01:28:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ntp-not-working-once-authentication-is-enabled/m-p/515405#M107037</guid>
      <dc:creator>Pras</dc:creator>
      <dc:date>2022-09-20T01:28:01Z</dc:date>
    </item>
    <item>
      <title>Re: NTP not working once authentication is enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ntp-not-working-once-authentication-is-enabled/m-p/515641#M107091</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/202203"&gt;@Pras&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;See my suggestions below:&lt;/P&gt;
&lt;P&gt;-&amp;nbsp;&lt;SPAN&gt;NTP authentication checks the authenticity of NTP server before&amp;nbsp;&lt;SPAN&gt;&lt;SPAN class="" data-enable-toggle-animation="true" data-extra-container-classes="ZLo7Eb" data-hover-hide-delay="1000" data-hover-open-delay="500" data-send-open-event="true" data-theme="0" data-width="250" data-ved="2ahUKEwi54O3u0Kb6AhUyPewKHX84AO4QmpgGegQIFBAD"&gt;&lt;SPAN class="" data-bubble-link="" data-segment-text="synchronizing"&gt;synchronizing&lt;SPAN&gt;&amp;nbsp;local time with the server, so I would double check the ntp auth type (md5/sha1), the symmetric auth-key (the shared password), and the NTP version.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;- pcap wise, I would start with the very basic which is confirming I see a request/reply (although you mentioned it was working before w/o the auth). Next, I would inspect to see what NTP version is used and review the NTP header flags.&lt;/P&gt;
&lt;P&gt;- &lt;SPAN&gt;Do you have service routes configured? Do you use the mgmt interface or other for NTP?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;- If possible try switching to a different public ntp?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;- Do you have two ntp server configured? if yes, either try removing one or make sure the key-id is different.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;- filter under "monitor &amp;gt; logs &amp;gt; system" using&amp;nbsp;(subtype eq ntpd) for any information regarding the ntp events.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;- try "debug software restart process ntp" on the firewall and then try the show command again, if it still fails check the dagger log again.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;regards,&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Sep 2022 20:30:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ntp-not-working-once-authentication-is-enabled/m-p/515641#M107091</guid>
      <dc:creator>vzamy</dc:creator>
      <dc:date>2022-09-21T20:30:42Z</dc:date>
    </item>
    <item>
      <title>Re: NTP not working once authentication is enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ntp-not-working-once-authentication-is-enabled/m-p/516427#M107240</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/125239"&gt;@vzamy&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Had already done the restart of the ntp process with no luck.&lt;/P&gt;
&lt;P&gt;The troubleshooted some more and would like to show come snaps as below:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="paragkarki143_0-1664507086700.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/44303iD420F17E0623079B/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="paragkarki143_0-1664507086700.png" alt="paragkarki143_0-1664507086700.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;NTP server is a&lt;SPAN&gt;&amp;nbsp;Linux base and OS version is Redhat Enterprise Linux 7.9&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;It is pinging the server but apart from pinging nothing is being captured.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="paragkarki143_1-1664507361121.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/44304i8159A9497245740E/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="paragkarki143_1-1664507361121.png" alt="paragkarki143_1-1664507361121.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Also,&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="paragkarki143_2-1664507495752.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/44305i205926F19BE60CC0/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="paragkarki143_2-1664507495752.png" alt="paragkarki143_2-1664507495752.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="paragkarki143_3-1664507583997.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/44306iB182FF5FDA136D36/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="paragkarki143_3-1664507583997.png" alt="paragkarki143_3-1664507583997.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Server side has no issue apparently: it is getting the ntp packets from the FW&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="paragkarki143_4-1664507808182.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/44307i218F644593952246/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="paragkarki143_4-1664507808182.png" alt="paragkarki143_4-1664507808182.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What could be the issue here?&lt;/P&gt;
&lt;P&gt;Thanks in advance.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Sep 2022 03:17:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ntp-not-working-once-authentication-is-enabled/m-p/516427#M107240</guid>
      <dc:creator>Pras</dc:creator>
      <dc:date>2022-09-30T03:17:17Z</dc:date>
    </item>
    <item>
      <title>Re: NTP not working once authentication is enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ntp-not-working-once-authentication-is-enabled/m-p/516457#M107243</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/202203"&gt;@Pras&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;- your printscreen shows one NTP call (the 1st line) so it does capture the NTP traffic.&lt;BR /&gt;Remember that the ntp polling occurs every x interval (between 64 and 1024)&lt;BR /&gt;- your tcpdump filter only captures destination x.x.x.134 thus we can't see any reponse from the otherside&lt;BR /&gt;e.g we can only see the ICMP requests&lt;BR /&gt;- please run the tcpdump like this instead&lt;BR /&gt;&amp;gt; tcpdump filter "host x.x.x.134" snaplen 0&lt;BR /&gt;- in the traffic logs, please extend one of the sessions using the detailed log view and inspect the bytes sent/received&lt;BR /&gt;what are they? it should show as 1:1 or higher, the goal is to see if we have bi-directional traffic.&lt;BR /&gt;- Please confirm if the Linux server is responsive (NTP-wise). The server-side printscreen you attached only shows a &lt;BR /&gt;unidirectional packet capture. Re-run the tcpdump on the server side:&lt;BR /&gt;e.g&lt;BR /&gt;tcpdump -nni 0.0 port 123&lt;BR /&gt;or&lt;BR /&gt;tcpdump -nni 0.0 host x.x.x.5&lt;/P&gt;
&lt;P&gt;- Are the key-ids aligned between the FW and NTP server? To confirm, inspect the pcap and look for the Key ID sent from FW and&lt;BR /&gt;also, the Key ID returned from the server.&lt;BR /&gt;If they aren't try setting them both to the same key-id.&lt;BR /&gt;- The authentication procedures require that both the local and remote servers share the same key and key identifier for this purpose, &lt;BR /&gt;although different keys can be used with different servers. The key arguments are 32-bit unsigned integers with values from 1 to 65,534.&lt;BR /&gt;- since you have the MP attached to the DP you can run the PCAP there and download it for futher inspection. Make sure to configure&lt;BR /&gt;all the stages and observe if anything goes into the drop stage.&lt;BR /&gt;- If no NTP traffic is seen, to trigger it either restart the FW's ntp service or do a "commit force".&lt;BR /&gt;- Please also use "show counter global filter delta yes packet-filter yes" combined with a pcap filter. (mandatory)&lt;BR /&gt;and share the findings (make sure to generate the ntp traffic)&lt;BR /&gt;- If we still have no progress, at this stage I would try and rule out the NTP server. If you have a Cisco at hand&lt;BR /&gt;you can easily configure it to act as an NTP server.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Sep 2022 08:32:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ntp-not-working-once-authentication-is-enabled/m-p/516457#M107243</guid>
      <dc:creator>vzamy</dc:creator>
      <dc:date>2022-09-30T08:32:50Z</dc:date>
    </item>
    <item>
      <title>Re: NTP not working once authentication is enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ntp-not-working-once-authentication-is-enabled/m-p/517396#M107383</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/125239"&gt;@vzamy&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;Just received few requested outputs as below:&lt;/P&gt;
&lt;P&gt;1.&lt;STRONG&gt;Restart done&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;admin@W01(active)&amp;gt; debug software restart process ntp&lt;/P&gt;
&lt;P&gt;Process ntp was restarted by user admin&lt;/P&gt;
&lt;P&gt;2.&lt;STRONG&gt;TCP dump&lt;/STRONG&gt;&amp;nbsp;(FW side)--&amp;gt; server I will share shortly&lt;/P&gt;
&lt;P&gt;admin@W01(active)&amp;gt; tcpdump filter "host x.x.x.134" snaplen 0&lt;/P&gt;
&lt;P&gt;Press Ctrl-C to stop capturing&amp;nbsp;&lt;/P&gt;
&lt;P&gt;tcpdump: listening on eth0, link-type EN10MB (Ethernet), capture size 65535 bytes&lt;/P&gt;
&lt;P&gt;^C3 packets captured&lt;/P&gt;
&lt;P&gt;3 packets received by filter&lt;/P&gt;
&lt;P&gt;0 packets dropped by kernel&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;admin@W01(active)&amp;gt; view-pcap mgmt-pcap mgmt.pcap&lt;/P&gt;
&lt;P&gt;14:39:21.753391 IP ...local.ntp &amp;gt; M01.x.local.ntp: NTPv4, Client, length 68&lt;/P&gt;
&lt;P&gt;14:40:25.753435 IP ....local.ntp &amp;gt; M01x.local.ntp: NTPv4, Client, length 68&lt;/P&gt;
&lt;P&gt;14:41:30.753456 IP ....local.ntp &amp;gt; RSSITDC1LM01.x.local.ntp: NTPv4, Client, length 68&lt;/P&gt;
&lt;P&gt;admin@AW01(active)&amp;gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="paragkarki143_0-1665464904017.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/44558i7104042B0AA873A7/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="paragkarki143_0-1665464904017.png" alt="paragkarki143_0-1665464904017.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;admin@W01(active)&amp;gt; show ntp&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;NTP state:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; NTP not synched, using local clock&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; NTP server: x.x.x.134&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; status: rejected&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; reachable: no&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; authentication-type: symmetric key&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Clock is set manually (i.e aligned to real time).&lt;/P&gt;
&lt;P&gt;Server side captures show as below. I see that the NTP version configured from server side is 3. Could this be an issue?&lt;/P&gt;
&lt;P&gt;Also, the reference ID is different (do not know if this could be an issue)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="paragkarki143_1-1665528666051.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/44588iEA08F14EE41C680F/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="paragkarki143_1-1665528666051.png" alt="paragkarki143_1-1665528666051.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="paragkarki143_2-1665528840751.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/44589i0F785152E27F4524/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="paragkarki143_2-1665528840751.png" alt="paragkarki143_2-1665528840751.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you heaps in advance.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Oct 2022 22:01:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ntp-not-working-once-authentication-is-enabled/m-p/517396#M107383</guid>
      <dc:creator>Pras</dc:creator>
      <dc:date>2022-10-17T22:01:48Z</dc:date>
    </item>
    <item>
      <title>Re: NTP not working once authentication is enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ntp-not-working-once-authentication-is-enabled/m-p/518765#M107599</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/202203"&gt;@Pras&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- There seems to be NTP communication between the client (FW) and the server, your server-side captures confirm that.&lt;BR /&gt;- Reference ID (refid): 32-bit code identifying the particular server or reference clock. So this isn't the issue.&lt;BR /&gt;- keyid: Symmetric key ID for the 128-bit MD5 key used to generate and verify the MAC. &lt;BR /&gt;The client and server or peer can use different values, but they must map to the same key.&lt;BR /&gt;Please try resetting your PSK (use something simple for the testing purpose)&lt;BR /&gt;- Have a look at the current NTPv4 RFC 5905 “Network Time Protocol Version 4: Protocol and Algorithms Specification” in order to understand the packets and protocol details. &lt;BR /&gt;Looking at the wire you should understand the packet header (&lt;A href="https://www.rfc-editor.org/rfc/rfc5905#section-7.3" target="_self"&gt;section 7.3&lt;/A&gt; in the RFC).&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;- your "show ntp" output shows the server NTP is being 'rejected'.&lt;BR /&gt;admin@W01(active)&amp;gt; show NTP&lt;BR /&gt;NTP state:&lt;BR /&gt;NTP not synched, using local clock&lt;BR /&gt;NTP server: x.x.x.134&lt;BR /&gt;status: rejected &amp;lt;&amp;lt; here&lt;BR /&gt;reachable: no&lt;BR /&gt;authentication-type: symmetric key&lt;/P&gt;
&lt;P&gt;- NTP will refuse to synch if the time is too far off, due to its methodology, which is to slow or speed the clock and adjust gradually.&lt;BR /&gt;I see you mentioned you've manually adjusted your clock to a time closer to actual time for you time zone.&lt;/P&gt;
&lt;P&gt;- NTPv4 is an extension of NTPv3 that supports IPv4 and IPv6. It is backward compatible with NTPv3, offers some new features, and time synchronization &lt;BR /&gt;is faster and more precise. Security has improved, NTPv4 supports public key cryptography and standard X509 certificates.&lt;BR /&gt;So although server side and client side use different NTP version this should not be an issue. But to rule out any possibility&lt;BR /&gt;I would align these two.&lt;/P&gt;
&lt;P&gt;- Please comment on these two previously proposed steps:&lt;BR /&gt;1- Please also use "show counter global filter delta yes packet-filter yes" combined with a pcap filter. (mandatory)&lt;BR /&gt;and share the findings (make sure to generate the NTP traffic)&lt;BR /&gt;2- If we still have no progress, at this stage I would try and rule out the NTP server. If you have a Cisco at hand&lt;BR /&gt;you can easily configure it to act as an NTP server.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Oct 2022 19:24:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ntp-not-working-once-authentication-is-enabled/m-p/518765#M107599</guid>
      <dc:creator>vzamy</dc:creator>
      <dc:date>2022-10-21T19:24:35Z</dc:date>
    </item>
    <item>
      <title>Re: NTP not working once authentication is enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ntp-not-working-once-authentication-is-enabled/m-p/520454#M107851</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/125239"&gt;@vzamy&lt;/a&gt;&amp;nbsp;The issue has not been resolved.&lt;BR /&gt;Thanks for your suggestions they definitely helped us troubleshoot the issue. Initially, there was no 2-way communication but when the encryption was changed to&amp;nbsp;&lt;SPAN&gt;SHA1&amp;nbsp; with &amp;nbsp;exactly 40bit character length key the issue got resolved.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Nov 2022 00:23:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ntp-not-working-once-authentication-is-enabled/m-p/520454#M107851</guid>
      <dc:creator>Pras</dc:creator>
      <dc:date>2022-11-07T00:23:27Z</dc:date>
    </item>
    <item>
      <title>Re: NTP not working once authentication is enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ntp-not-working-once-authentication-is-enabled/m-p/589855#M117543</link>
      <description>&lt;P&gt;How did you generate the sha1 ntp hash? I tried generating a hash from the plain text password via a linux command, and subsequently tried in powershell. Neither of those hashes worked. I know the plaintext password works when I apply it to other devices, but I can't seem to get the right hash for the sha1 password field.&lt;/P&gt;
&lt;P&gt;Any help would be greatly appreciated!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Steve&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jun 2024 22:36:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ntp-not-working-once-authentication-is-enabled/m-p/589855#M117543</guid>
      <dc:creator>cullums</dc:creator>
      <dc:date>2024-06-18T22:36:50Z</dc:date>
    </item>
    <item>
      <title>Re: NTP not working once authentication is enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ntp-not-working-once-authentication-is-enabled/m-p/615020#M121629</link>
      <description>&lt;P&gt;Do not hash the key value. Some NTP providers (eg. NIST) supply the authentication key value in ASCII format. The 40-character SHA1 NTP authentication key that you enter into the PanOS WebUI must be a Hex representation of the plaintext ASCII password, not its SHA1 hash. That 20 character ASCII password needs to be converted to a 40 character hex format. This site can help:&amp;nbsp;&lt;A href="https://www.rapidtables.com/convert/number/ascii-to-hex.html" target="_blank"&gt;https://www.rapidtables.com/convert/number/ascii-to-hex.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Oct 2024 21:29:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ntp-not-working-once-authentication-is-enabled/m-p/615020#M121629</guid>
      <dc:creator>bartpmika</dc:creator>
      <dc:date>2024-10-25T21:29:24Z</dc:date>
    </item>
  </channel>
</rss>

