SLES 11 is not syncing with NTP Server

Hi All,

We are running SLES 11 on VMWare . It is not syncing with NTP Server .I have tried to update the Time manually with NTP Server and it worked for some time .After that the time is getting delayed on the Server. I have tried to restart the NTP Service and synced the system clock to HWclock also. Hw clock is getting delayed after some time.

Please suggest the solution and steps to resolve the issue…

Hi
Seeing traffic on port 123? System up to date? Firewall port open?

There was a vulnerability for ntp services relating to DDOS, have you
tweaked the config for this?
http://lists.opensuse.org/opensuse-security-announce/2014-01/msg00005.html


Cheers Malcolm °¿° LFCS, SUSE Knowledge Partner (Linux Counter #276890)
SUSE Linux Enterprise Desktop 12 GNOME 3.10.1 Kernel 3.12.28-4-default
If you find this post helpful and are logged into the web interface,
please show your appreciation and click on the star below… Thanks!

How to check the traffic and firewall port open ? I see another server in the same network is working fine .

Hi
If you tail /var/log/messages you should see ntp traffic?

To check the firewall, YaST → Firewall → Allowed services, if your
firewall is on, then you need to ensure it’s added.

Now it maybe that your firewall is meant to be off or on?

Run as root user, should show if it’s active or not…

rcSuSEfirewall2 status


Cheers Malcolm °¿° LFCS, SUSE Knowledge Partner (Linux Counter #276890)
SUSE Linux Enterprise Desktop 12 GNOME 3.10.1 Kernel 3.12.28-4-default
If you find this post helpful and are logged into the web interface,
please show your appreciation and click on the star below… Thanks!

Hi kgpunix,

[QUOTE=kgpunix;25114]Hi All,

We are running SLES 11 on VMWare . It is not syncing with NTP Server .I have tried to update the Time manually with NTP Server and it worked for some time .After that the time is getting delayed on the Server. I have tried to restart the NTP Service and synced the system clock to HWclock also. Hw clock is getting delayed after some time.

Please suggest the solution and steps to resolve the issue…[/QUOTE]

it’d be helpful to see how you have set up NTP on your server. Could you please post the console log of running “rcntp status”, “cat /etc/ntp.conf”, “grep NTP /etc/sysconfig/network/config” and “chkconfig ntp”?

Regards,
Jens

On 26/11/2014 18:54, kgpunix wrote:
[color=blue]

How to check the traffic and firewall port open ? I see another server
in the same network is working fine .[/color]

Is the server listening on UDP port 123? Please post the output from
“netstat -an | grep :123”.

HTH.

Simon
SUSE Knowledge Partner


If you find this post helpful and are logged into the web interface,
please show your appreciation and click on the star below. Thanks.

[QUOTE=malcolmlewis;25117]Hi
If you tail /var/log/messages you should see ntp traffic?

To check the firewall, YaST → Firewall → Allowed services, if your
firewall is on, then you need to ensure it’s added.

Now it maybe that your firewall is meant to be off or on?

Run as root user, should show if it’s active or not…

rcSuSEfirewall2 status


Cheers Malcolm °¿° LFCS, SUSE Knowledge Partner (Linux Counter #276890)
SUSE Linux Enterprise Desktop 12 GNOME 3.10.1 Kernel 3.12.28-4-default
If you find this post helpful and are logged into the web interface,
please show your appreciation and click on the star below… Thanks![/QUOTE]

Firewall is not enabled and syslog is not working …

root@lap15:~# /etc/init.d/syslog status
/etc/syslog-ng/syslog-ng.conf does not exist
root@lap15:~# rcSuSEfirewall2 status
Checking the status of SuSEfirewall2 unused
root@lap15:~#

Server listening on UDP port 123.

root@lap15:~# netstat -an | grep :123|grep -i udp
udp 0 0 214.166.92.23:123 0.0.0.0:*
udp 0 0 127.0.0.2:123 0.0.0.0:*
udp 0 0 127.0.0.1:123 0.0.0.0:*
udp 0 0 0.0.0.0:123 0.0.0.0:*
udp 0 0 fe80::250:56ff:fe91:123 :::*
udp 0 0 ::1:123 :::*
udp 0 0 :::123 :::*
root@lap15:~#

root@lap15:~# rcntp status
remote refid st t when poll reach delay offset jitter

ntpfcs.aser.com 130.207.244.240 2 u 42 64 377 0.225 765426. 15644.8

Checking for network time protocol daemon (NTPD): running
root@lap15:~#

root@pbglap00115:~# cat /etc/ntp.conf|grep -v ^#

driftfile /var/lib/ntp/drift/ntp.drift

logfile /var/log/ntp

server 214.166.90.36
root@lap15:~#

root@lap15:~# grep NTP /etc/sysconfig/network/config

Defines the NTP merge policy as documented in netconfig(8) manual page.

Set to “” to disable NTP configuration.

NETCONFIG_NTP_POLICY=“auto”

List of NTP servers.

NETCONFIG_NTP_STATIC_SERVERS=""
root@lap15:~#

root@lap15:~# chkconfig ntp
ntp on
root@lap15:~#

ntpdc -c sysinfo
system peer: 0.0.0.0
system peer mode: unspec
leap indicator: 11
stratum: 16
precision: -20
root distance: 0.00000 s
root dispersion: 0.00436 s
reference ID: [73.78.73.84]
reference time: 00000000.00000000 Thu, Feb 7 2036 1:28:16.000
system flags: auth monitor ntp kernel stats
jitter: 0.000000 s
stability: 0.000 ppm
broadcastdelay: 0.003998 s
authdelay: 0.000000 s

Issue resolved after rebooting the Server. Server was up and running 900+ days …