Connecting to Local NTP server with usg flex 500
Comments
-
Hi @AlexRiviera,
I tested this symptom in our labs it works normal.
Can you share some information with us;
1- Do you have route to your internal NTP Server?
Can you test with following path;
Maintenance > Diagnostics > Network Tool > PING IPv4
2- Did you try to disable your NTP Server’s firewall or open port for NTP (UDP port 123)
3- Can you clarify that related service is running on NTP Server?(e.g. Windows Time)
4- For troubleshooting purposes, can you capture packets when syncing Time with NTP Server?
For that you can find the following path;
Maintenance > Diagnostics > Packet Capture > Choose Interfaces > Capture
5- If public NTP servers work properly but your local NTP Server can’t sync time it’s probably related to your NTP Server’s configuration.
0 -
Thx for your extended Feedback.
1- Do you have route to your internal NTP Server?
-> Yes i get answer and 0% packetloss. So a route is there.2- Did you try to disable your NTP Server’s firewall or open port for NTP (UDP port 123)
Firewall where ntp server is running is "down" / not running
3- Can you clarify that related service is running on NTP Server?(e.g. Windows Time)
Yes my Workstation as other servers are getting sync from ntp. (Tested again)
4- For troubleshooting purposes, can you capture packets when syncing Time with NTP Server?
Will do that.
The ntp server is running on a vlan in/on ethernet (zone) lan1. From which interface is the ntp client on the zywall making the request? WAN interface?0 -
Pakets captured, seems like the timeserver is giving an answer:Frame 2: 90 bytes on wire (720 bits), 90 bytes captured (720 bits)Ethernet II, Src: NTPServer [entry modified because of privacy], Dst: ZyxelCom_[entry modified because of privacy]
Internet Protocol Version 4, Src: [correct IP] , [Dst: correct IP]User Datagram Protocol, Src Port: 123, Dst Port: 53011Network Time Protocol (NTP Version 4, server)Flags: 0x24, Leap Indicator: no warning, Version number: NTP Version 4, Mode: server[Request In: 1][Delta Time: 0.000172000 seconds]Peer Clock Stratum: secondary reference (2)Peer Polling Interval: invalid (3)Peer Clock Precision: 0.000000 secondsRoot Delay: 0.016098 secondsRoot Dispersion: 0.045975 secondsReference ID: 84.16.67.12Reference Timestamp: Apr 6, 2021 18:04:03.410726043 UTCOrigin Timestamp: Apr 6, 2021 18:37:40.054865730 UTCReceive Timestamp: Apr 6, 2021 18:37:40.053579426 UTCTransmit Timestamp: Apr 6, 2021 18:37:40.053663200 UTC
Any ideas what's going wrong here?0 -
Hi @AlexRiviera,
I tested put NTP Server into VLAN. It can still sync time.
Can you try to capture packets for LAN interfaces and share in this topic?
0 -
Hi, thx for the answer. Well the capture is in my post above. Do you also need the request?0
-
Hi @AlexRiviera,
Can you capture packets from LAN interfaces and send .cap file to me by private message so I can check for you?
0 -
check your mailbox please.0
-
Hi @AlexRiviera,
Unfortunately attached file is not readable.
Can you try following steps for .cap file and send me again by private message:
1 -First, start capturing packets:
In Web GUI, Maintenance > Diagnostics > Packet Capture > Capture:
2- Sync time with NTP Server:
3- After synchronizing is failed go back to Maintenance > Diagnostics > Packet Capture > Capture menu and stop capturing.
4- Download the captured .cap file and send me by private message without changing the extension.
0 -
cap is not allowd in PN. So i zipped it ok?0
-
Hi @AlexRiviera,
In the packets you provided, I see request and reply.
In the second cycle's response I see:
=======================================================
Flags: 0xe4, Leap Indicator: unknown (clock unsynchronized), Version number: NTP Version 4, Mode: server
Reference ID: Unidentified reference source 'RATE'
=======================================================
What is the NTP Server’s operating system?
In the RFC document section 7.4 you can see explanation of "RATE" code. (https://tools.ietf.org/html/rfc5905)
Can you try to sync your time with a Windows Client?
For that you have to modify following registry entries;
Computer\HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W32Time\TimeProviders\NtpServer\Enabled = 1
Computer\HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W32Time\Config\AnnounceFlags = 5
0
Categories
- All Categories
- 415 Beta Program
- 2.4K Nebula
- 144 Nebula Ideas
- 94 Nebula Status and Incidents
- 5.6K Security
- 237 USG FLEX H Series
- 267 Security Ideas
- 1.4K Switch
- 71 Switch Ideas
- 1.1K Wireless
- 40 Wireless Ideas
- 6.3K Consumer Product
- 247 Service & License
- 384 News and Release
- 83 Security Advisories
- 29 Education Center
- 10 [Campaign] Zyxel Network Detective
- 3.2K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 83 About Community
- 71 Security Highlight