Доброе времени суток.
Всё началось с того, что передал роль PDC и службу времени другому вновь установленному КД.
На новом КД настроил сервер времени и судя по событиям в журнале, с внешними источниками (pool.ntp.org и time.windows.com) синхронизация проходит нормально.
Но вот второй КД упорно отказывается синхронизировать часы с PDC, перестала запускаться служба времени
«Служба времени обнаружила ошибку и была вынуждена завершить работу. Ошибка: 0x80070002: Не удается найти указанный файл.» В реестре ручками указал сервер времени на PDC
Почти все клиенты тоже перестали синхронизировать свои часы, ошибка: «Службе времени не удалось синхронизовать системное время в течение 49152 сек., поскольку ни один из поставщиков времени не смог предоставить пригодный штамп времени. Системные часы не
синхронизованы.»
Настройки политик связанные со сервером времени — не задано
w32tm /monitor
SRV-DC-2.domain.ru[192.168.10.250:123]:
ICMP: 0ms задержка
NTP: ошибка WSAECONNRESET — ни один сервер не прослушивает NTP-порт
SRV-DC.domain.ru *** PDC ***[[::1]:123]:
ICMP: 0ms задержка
NTP: +0.0000000s смещение относительно SRV-DC.domain.ru
RefID: relay.ccvti.ru [85.234.1.27]
Страта: 3
Предупреждение:
Рекомендуется использовать обратное разрешение имен. Возможно, оно выполнено
неверно, поскольку поле RefID в пакетах времени различается в
разных реализациях NTP и может не использовать IP-адреса.
Мне не понятно откуда берётся RefID: relay.ccvti.ru [85.234.1.27]
Подскажите, что сделал не так?
Заранее благодарю
Hi,
I’ve spent far too long trawling answers on this and exhausted all I can come up with so far. While I can get a stripcheck working fine (which I understand confirms NTP connection with the time source is functioning), I still receive an error.
Steps so far:
Deregistered, re-registered the time service.
Set up to point to local NZ NTP time servers as per http:/ Opens a new window/technet.microsoft.com/en-us/library/cc786897.aspx Opens a new window
>w32tm /config /manualpeerlist:»1.nz.pool.ntp.org,0x1 3.oceania.pool.ntp.org,0x1 2.oceania.pool.ntp.org,0x1″ /syncfromflags:manual /reliable:yes /update
Double checked all registry settings, restart service
Test using /stripchart:
w32tm /stripchart /computer:1.nz.pool.ntp.org /samples:5 /dataonly
Tracking 1.nz.pool.ntp.org [131.203.103.219:123].
Collecting 5 samples.
The current time is 6/01/2014 12:59:54 p.m..
12:59:54, +00.2908765s
12:59:56, +00.2888507s
12:59:58, +00.2873896s
13:00:00, +00.2877402s
13:00:02, +00.2878041s
However, /monitor fails:
C:>w32tm /monitor
pdce.domain.local *** PDC ***[[xxxx]:123]:
ICMP: 0ms delay
NTP: error WSAECONNRESET — no server listening on NTP port
dc.domain.local[xxxx:123]:
ICMP: 0ms delay
NTP: error ERROR_TIMEOUT — no response from server in 1000ms
Resync fails:
>w32tm /resync
Sending resync command to local computer
The computer did not resync because no time data was available.
>w32tm /query /peers
#Peers: 1
Peer: 1.nz.pool.ntp.org,0x1
State: Pending
Time Remaining: 0.0000000s
Mode: 0 (reserved)
Stratum: 0 (unspecified)
PeerPoll Interval: 0 (unspecified)
HostPoll Interval: 0 (unspecified)
I’ve tried different time servers, different servers, all with the same result, which I would guess to then be a general network issue, but then the /stripchart test works.
There are no GPO’s interfering with this.
Any help/advice would be very welcome. Thanks in advance.
Currently, the PCs on our domain appear to be checking a server hierarchy to get their time. When I do a w32tm /monitor, this is what it shows:
TERMSERV1.[domain].com [192.168.100.4]:
ICMP: 0ms delay.
NTP: +0.1663766s offset from DC01.[domain].com
RefID: DC01.[domain].com [192.168.100.50]
TERMSERV2.[domain].com [192.168.100.5]:
ICMP: 0ms delay.
NTP: error WSAECONNRESET — no server listening on NTP port
DIGGERS-DC01.[domain].com *** PDC *** [192.168.100.50]:
ICMP: 1ms delay.
NTP: +0.0000000s offset from DC01.[domain].com
RefID: nist1-chi.ustiming.org [208.66.175.36]
I would like it if the PCs only checked the DC01 server and not the other 2. How do I go about setting up the PCs on the domain to only check that particular server for their time? Or at least set the order so they check that one first?
Windows Server 2008Windows XP
Not exactly the question you had in mind?
Sign up for an EE membership and get your own personalized solution. With an EE membership, you can ask unlimited troubleshooting, research, or opinion questions.
ask a question
Not exactly the question you had in mind?
Sign up for an EE membership and get your own personalized solution. With an EE membership, you can ask unlimited troubleshooting, research, or opinion questions.
ask a question
I started with Experts Exchange in 2004 and it’s been a mainstay of my professional computing life since. It helped me launch a career as a programmer / Oracle data analyst
- Remove From My Forums
-
Question
-
Now the time in our child domain is fast 2 Mins than parent domain, how to sync the time by what command ?
Answers
-
hey
please run «w32tm /resync» on child domain to sync up with the P DC,if the time reverts back so there is something syncing your child domain time to the other values,if you have your child domain on Virtual environment it might be getting the time
synced by the host (which you should disable then under integrationservices in the machine settings)lemme know by the results plz
G luck
_____________________________________________________________________________________
SeyedHoodad HashemiNoudehi
MCSA 2008, MCITP: Enterprise Administrator, MCITP: Server Administrator, MCSE:2003 Security,MCSA:2003 Security , MCTS , MCP , Comptia Security+ ce , ITIL V3.0 , BEng CEn
-
Edited by
Wednesday, December 25, 2013 6:35 AM
-
Marked as answer by
Frank Shen5
Tuesday, January 7, 2014 1:55 AM
-
Edited by
-
Hi,
By default, the PDC Emulator of the Forest Root Domain is considered as the best time source in an Active Directory forest. Other domain controllers
in the Forest Root Domain use it for time synchronization while domain controllers in child domains use the PDC Emulator or any domain controller from parent domain for time synchronization. Member servers and Workstation use domain controllers in their domain
for time synchronization. With this hierarchy, we can maintain a reliable time synchronization system that allows avoiding Kerberos failure issues in an Active Directory domain. This configuration is by default in an Active Directory forest and does not need
to be changed.As mentioned by SH.Hashemi, we can run command
w32tmresync to resynchronize the clock as soon as possible, disregarding all accumulated error statistics.Regarding time synchronization in active directory, the following articles can be referred to for more information.
Time Synchronization in Active Directory Forests
https://social.technet.microsoft.com/wiki/contents/articles/18573.time-synchronization-in-active-directory-forests.aspx
How the Windows Time Service Works
http://technet.microsoft.com/en-us/library/cc773013(v=ws.10).aspx
W32tm
http://technet.microsoft.com/en-us/library/bb491016.aspx
Best regards,
Frank Shen
-
Marked as answer by
Frank Shen5
Tuesday, January 7, 2014 1:55 AM
-
Marked as answer by
- Remove From My Forums
-
Question
-
Now the time in our child domain is fast 2 Mins than parent domain, how to sync the time by what command ?
Answers
-
hey
please run «w32tm /resync» on child domain to sync up with the P DC,if the time reverts back so there is something syncing your child domain time to the other values,if you have your child domain on Virtual environment it might be getting the time
synced by the host (which you should disable then under integrationservices in the machine settings)lemme know by the results plz
G luck
_____________________________________________________________________________________
SeyedHoodad HashemiNoudehi
MCSA 2008, MCITP: Enterprise Administrator, MCITP: Server Administrator, MCSE:2003 Security,MCSA:2003 Security , MCTS , MCP , Comptia Security+ ce , ITIL V3.0 , BEng CEn
-
Edited by
Wednesday, December 25, 2013 6:35 AM
-
Marked as answer by
Frank Shen5
Tuesday, January 7, 2014 1:55 AM
-
Edited by
-
Hi,
By default, the PDC Emulator of the Forest Root Domain is considered as the best time source in an Active Directory forest. Other domain controllers
in the Forest Root Domain use it for time synchronization while domain controllers in child domains use the PDC Emulator or any domain controller from parent domain for time synchronization. Member servers and Workstation use domain controllers in their domain
for time synchronization. With this hierarchy, we can maintain a reliable time synchronization system that allows avoiding Kerberos failure issues in an Active Directory domain. This configuration is by default in an Active Directory forest and does not need
to be changed.As mentioned by SH.Hashemi, we can run command
w32tmresync to resynchronize the clock as soon as possible, disregarding all accumulated error statistics.Regarding time synchronization in active directory, the following articles can be referred to for more information.
Time Synchronization in Active Directory Forests
https://social.technet.microsoft.com/wiki/contents/articles/18573.time-synchronization-in-active-directory-forests.aspx
How the Windows Time Service Works
http://technet.microsoft.com/en-us/library/cc773013(v=ws.10).aspx
W32tm
http://technet.microsoft.com/en-us/library/bb491016.aspx
Best regards,
Frank Shen
-
Marked as answer by
Frank Shen5
Tuesday, January 7, 2014 1:55 AM
-
Marked as answer by
Здравствуйте. История следующая, до 15:00 23.07.2015 я был в числе пользователей adsl byfly (модем ZTE H208N Промсвязь, тариф Домосед Классик). Связи с чем, до данного времени проблем с синхронизацией времени с ntp-серверами: belgim.by, by.pool.ntp.org и т.д. я не испытывал. Но, после 15:00 23.07.2015 меня перевели в число пользователей xPON (модем Huawei Echolife HG8245A, не промсвязь, тариф Рекорд 20). Так вот, при подключении к сети интернет, через данный момент я при первом соединении обнаружил, что сбилось время на ПК, после чего я зашёл и попытался синхронизировать время с ntp-сервером, на что собственно получил флаг в руки:
- код выделить все
Ошибка при выполнении синхронизации с belgim.by. Возврат из операции произошёл из-за превышения времени ожидания.
Данную ошибку я также получал при использовании любого другого ntp-сервера, не важно, находится сервер в Беларуси, России или в какой-то Германии.
После чего я принял раскопки модема, особых ошибок не нашёл. Начал выключать по разным способам (правка реестра, fix.it) ipv6 протокол, но к сожалению это не решило проблему. После чего я ради интереса переустановил Windows 8.1 Pro x64 и после ещё раз проверил, результат нулевой. После попробовал воспользоваться утилитой PortQry Command Line Port Scanner Version 2.0 и через консоль проверил:
- код выделить все
C:PortQryV2>PortQry.exe -n belgim.by -e 123 -p udp
Querying target system called:
belgim.by
Attempting to resolve name to IP address...
Name resolved to 178.124.164.107
querying...
UDP port 123 (ntp service): LISTENING or FILTERED
C:PortQryV2>
Тогда пришла мысль воспользоваться следующим вариантом: Установил OpenVPN-клиент, подсунул ключ от сервера расположенного в Белтелекоме (ЦОД на Уборевича) и проверил синхронизацию времени, и что вы думаете? Заработала синхронизация!!! Выключаю OpenVPN-сеть, и опять тишина!
Звонил в 123 но мне там отказали в помощи решения проблемы. Ссылаясь на то, что с их стороны проблем нет, проблема у меня))
Вопрос, сталкивался ли кто с подобным?