For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

yuanqiang_22112's avatar
yuanqiang_22112
Icon for Nimbostratus rankNimbostratus
May 31, 2016

Ntp Server time correction

Hello everyone: I have two vcmp host "A and B,V11.2.1" ,and set up NTP servers,A host NTP time is right ,the other B host is wrong ;tcpdump found A host receive packet ,B host none packet,but A host NTP time is wrong and B host NTP time is right. I have two question need to be helped (1) why A host send ntp request and receive ntp response ,but it's time is wrong ? B host none packet ,but it's time is right. (2)How long send ntp request for BIG-IP ?

 

8 Replies

  • Can you provide the output of 'ntpq -pn' on both devices ?
  • @ lanB, what's the time calibration mechanism of F5 ? I will give you the output of "ntpq -pn" the second day .
  • I don't understand your question. ntpd uses ntp to keep time like any other unix based device. That's why I need to see the ntp status. A picture of wireshark does not have enough information to draw any conclusions
  • I want to know how long it will take the NTP client sends a synchronization instructions ?
  • Perhaps it would help if you read about the NTP protocol. You could start with wikipedia: ntp

     

    NTP is a protocol designed to bring multiple clocks into synchronisation with each other.

     

  • JG's avatar
    JG
    Icon for Cumulonimbus rankCumulonimbus

    Are you sure you have not mixed up the identities of these two servers? The non-working server is not initialised and does not even know the type of the peer, whilst the working server gets correct time without going to the network!

     

    From your graph, the polling occurs every 1024 seconds.

     

  • In the output you provided, SLB01-LTM-1 is unable to contact the NTP server 3.9.0.1 (or ntpd has only just been started/restarted). .INIT. means it has sent an ntp packet, and is still waiting for a response. It hasn't had any replies (reach is 0). Can you ping 3.9.0.1 from LTM-1 ?

     

    SLB01-LTM-2 is in time sync (the * next to 3.9.0.1 shows that it is in sync), with a stratum 1 time source that claims to be a GPS based clock, and there is no packet loss (reach=0377 octal) to that device.

     

    The output also indicates that your viprion vcmp host (127.3.0.x) is not configured with an NTP source. I suggest you fix that, then your guests can simply sync to that.