For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

kiko's avatar
kiko
Icon for Nimbostratus rankNimbostratus
Oct 15, 2019

Big-IP AFM is not syncing with the NTP Server

I have recently read an article similar to my concern (https://devcentral.f5.com/s/feed/0D51T00006pYJxWSAW) however the workarounds here still have not solved the issue.

 

Our current setup involves a Big-IP LTM and a Big-IP AFM, with the external interface of the Big-IP AFM connected

to the internal interface of the Big-IP LTM.

 

Below is a list of the current configurations and workarounds that we have done. Note that Big-IP LTM is currently not having any issues syncing with the NTP server and initially the Big-IP AFM is not able to reach the NTP server via ping.:

  • configuring a policy in the Big-IP AFM to which we think is not specified, therefore is being directed to the global drop rule; this did not produce any change to the initial scenario
  • configuring a management route for the Big-IP AFM; this made it possible for the Big-IP AFM to reach the NTP server via ping, but using the command ntpq -np shows no stats, and is not synchronizing with the NTP server

 

Any kind of help would be greatly appreciated! Thanks in advance!

 

}}} kiko

1 Reply

  • did you restart ntpd after these changes? my experience is that it doesn't pick up changes very fast.