<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unable to connect to pool.ntp.org in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-connect-to-pool-ntp-org/m-p/380883#M89701</link>
    <description>&lt;P&gt;This is correct - i couldnt get NTP to sync on my PA220 when using "pool.ntp.org" - had to change the NTP server address to 0.pool.ntp.org&lt;/P&gt;</description>
    <pubDate>Tue, 19 Jan 2021 20:36:40 GMT</pubDate>
    <dc:creator>HarshadSowani</dc:creator>
    <dc:date>2021-01-19T20:36:40Z</dc:date>
    <item>
      <title>Unable to connect to pool.ntp.org</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-connect-to-pool-ntp-org/m-p/251153#M71419</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I have a problem with the NTP sync. When i make a "show ntp"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;NTP state:&lt;BR /&gt;NTP not synched, using local clock&lt;BR /&gt;NTP server: &lt;A href="https://www.ntppool.org/zone/asia" target="_blank"&gt;asia&lt;/A&gt;.pool.ntp.org&lt;BR /&gt;status: rejected&lt;BR /&gt;reachable: no&lt;BR /&gt;authentication-type: none&lt;BR /&gt;NTP server: pool.ntp.org&lt;BR /&gt;status: rejected&lt;BR /&gt;reachable: no&lt;BR /&gt;authentication-type: none&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But my mgmt interface is alow via policy rule to use ntp. I am able to ping the ntp host and a traceroute runs good.&lt;/P&gt;&lt;P&gt;So I search a bit you erros.. only found in sysdagent.log TIME: Unable to connect to asia.pool.ntp.org for ntpdate&lt;/P&gt;&lt;P&gt;I test it with "debug software restart process ntp"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any Ideas?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Feb 2019 13:05:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-connect-to-pool-ntp-org/m-p/251153#M71419</guid>
      <dc:creator>clonesheep</dc:creator>
      <dc:date>2019-02-25T13:05:56Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to connect to pool.ntp.org</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-connect-to-pool-ntp-org/m-p/251162#M71420</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43193"&gt;@clonesheep&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;you may need to change the service route for NTP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Device/Setup/Services/Service Route Configuration/NTP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;you will need to set this to the same interface that matches your policy.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Feb 2019 14:02:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-connect-to-pool-ntp-org/m-p/251162#M71420</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-02-25T14:02:52Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to connect to pool.ntp.org</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-connect-to-pool-ntp-org/m-p/251164#M71421</link>
      <description>&lt;P&gt;But at the moment I have "Use Management Interface for all" and this will run. So I get PA Updates and Virusupdates and so on. For my MGT there is the default GW the eth2 and this I see in the Monitor Log.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But no NTP &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Feb 2019 15:34:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-connect-to-pool-ntp-org/m-p/251164#M71421</guid>
      <dc:creator>clonesheep</dc:creator>
      <dc:date>2019-02-25T15:34:49Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to connect to pool.ntp.org</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-connect-to-pool-ntp-org/m-p/251165#M71422</link>
      <description>&lt;P&gt;sorry i did not fully understand your setup.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Feb 2019 15:44:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-connect-to-pool-ntp-org/m-p/251165#M71422</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-02-25T15:44:13Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to connect to pool.ntp.org</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-connect-to-pool-ntp-org/m-p/251167#M71424</link>
      <description>&lt;P&gt;Okay look:&lt;/P&gt;&lt;P&gt;MGT IP 10.0.8.1&lt;/P&gt;&lt;P&gt;eth 1/1 public IP&lt;/P&gt;&lt;P&gt;eth 1/2 10.0.8.2 my trust network&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;defualt virtual router route 0.0.0.0 to eth 1/1.&lt;/P&gt;&lt;P&gt;So my Mgmt Rule Src 10.0.8.1 trust zone goes to untrust destiantion any. This is how PA Updates work fine.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Feb 2019 15:51:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-connect-to-pool-ntp-org/m-p/251167#M71424</guid>
      <dc:creator>clonesheep</dc:creator>
      <dc:date>2019-02-25T15:51:25Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to connect to pool.ntp.org</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-connect-to-pool-ntp-org/m-p/251174#M71425</link>
      <description>&lt;P&gt;what appliance is this on. or is it a VM.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Feb 2019 15:56:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-connect-to-pool-ntp-org/m-p/251174#M71425</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-02-25T15:56:00Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to connect to pool.ntp.org</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-connect-to-pool-ntp-org/m-p/251175#M71426</link>
      <description>&lt;P&gt;Its a PA220&lt;/P&gt;</description>
      <pubDate>Mon, 25 Feb 2019 16:00:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-connect-to-pool-ntp-org/m-p/251175#M71426</guid>
      <dc:creator>clonesheep</dc:creator>
      <dc:date>2019-02-25T16:00:41Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to connect to pool.ntp.org</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-connect-to-pool-ntp-org/m-p/251190#M71432</link>
      <description>&lt;P&gt;Works for me but I do have my DNS currently set to 8.8.8.8 as palo docs state that the dns must have a reverse lookup for the ntp server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cld0CAC" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cld0CAC&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;admin@PA-3020(active)&amp;gt; show ntp&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;NTP state:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; NTP synched to asia.pool.ntp.org&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; NTP server: asia.pool.ntp.org&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; status: synched&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; reachable: yes&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; authentication-type: none&lt;/P&gt;</description>
      <pubDate>Mon, 25 Feb 2019 17:57:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-connect-to-pool-ntp-org/m-p/251190#M71432</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-02-25T17:57:47Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to connect to pool.ntp.org</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-connect-to-pool-ntp-org/m-p/251195#M71434</link>
      <description>&lt;P&gt;Hmmmmmm.... not sure about previous link as set dns to internal and still works ok.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;it does take about 5 mins to be succesful though.....&lt;/P&gt;</description>
      <pubDate>Mon, 25 Feb 2019 19:16:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-connect-to-pool-ntp-org/m-p/251195#M71434</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-02-25T19:16:30Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to connect to pool.ntp.org</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-connect-to-pool-ntp-org/m-p/355540#M87551</link>
      <description>&lt;P&gt;I just encountered what i think is a bug and will report it through the PAN-OS folks.&amp;nbsp; We were setting up connection for NGFW to the Cortex Data Lake.&amp;nbsp; It wouldn't get the CDL cert.&amp;nbsp; we flipped the HA pair and went through same process and it worked.&amp;nbsp; after looking the through the Device/Setup configs, the ONLY difference was that the one that just worked had 0.pool.ntp.org set in its secondary NTP server setting.&amp;nbsp; We added 0.pool.ntp.org as a secondary then it grabbed.&amp;nbsp; So then we just took pool.ntp.org right out of both configs, moved 0.pool.ntp.org to the primary.&amp;nbsp; Again no issues.&amp;nbsp; I think it might be in how we are grabbing those IPs when they resolve, or its taking too long for the main pool to grab the IPs its wants to provide.&amp;nbsp; &amp;nbsp; Earlier above, there was a comment about using a stable time server, which by changing out pool.ntp.org for basically any legit time server, you were probably resolved.&amp;nbsp; If you have any problems with NTP, first thing i would check would be that you aren't using the generic pool.ntp.org.&lt;/P&gt;</description>
      <pubDate>Sat, 10 Oct 2020 04:58:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-connect-to-pool-ntp-org/m-p/355540#M87551</guid>
      <dc:creator>dbilinski</dc:creator>
      <dc:date>2020-10-10T04:58:22Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to connect to pool.ntp.org</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-connect-to-pool-ntp-org/m-p/380883#M89701</link>
      <description>&lt;P&gt;This is correct - i couldnt get NTP to sync on my PA220 when using "pool.ntp.org" - had to change the NTP server address to 0.pool.ntp.org&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jan 2021 20:36:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-connect-to-pool-ntp-org/m-p/380883#M89701</guid>
      <dc:creator>HarshadSowani</dc:creator>
      <dc:date>2021-01-19T20:36:40Z</dc:date>
    </item>
  </channel>
</rss>

