Forum Discussion
Why does NTP needs frequent restarts
We have viprions with 4 guests each running 11.3 HF8. NTP needs to be restarted randomly. This is discovered with the failure of a SAML application. I believe that the refid is in an init state (ntpq -p command) until the restart. Each guest references 3 domain controllers for NTP, so I am assuming they all fail (the process on the F5 fails) at the same time. Is it version related? Can I cron a job to restart ntp daily? (band aid approach) Any suggestions would be appreciated.
Thanks, jkrum
4 Replies
- samstep
Cirrocumulus
Is NTP server accessible on a management port or traffic VLANs?
There is a known issue: ID247909, CR138146"You might encounter an issue in which the NTP servers do not sync after a system reboot. You can recognize this by running the command ntpq -p to determine whether some of the NTP servers continue to have a refid of .INIT. You might find the issue more pronounced on the VIPRION platform because every blade is an NTP peer of every other blade. (Note that a refid of .INIT is normal for any system with no defined NTP server. F5 strongly recommends defining an NTP server.) This appears to occur only on networks accessible through VLANs, and does not occur with NTP servers serviced by the management port. The issue can be particularly problematic for IPv6 addresses because the system caches the unreachable destination information. To work around the issue, when tmm is up and servicing traffic, run the command bigstart restart ntpd to restart the ntpd process."
Also check out SOL7017
- jkrumenacher_13
Nimbostratus
samstep, These don't necessarily happen after a reboot, but maybe a failover. I'm not sure how long it takes for time to drift to the point of erroring out the app. I am not sure I understand when you say accessible on the management port? The management network does have access to to the various networks that the AD controllers are on.
thanks jkrum
- samstep
Cirrocumulus
Read carefully the solution SOL7017 http://support.f5.com/kb/en-us/solutions/public/7000/000/sol7017.html - I think you have this problem (only fixed in v11.4.0). Try the workarounds described in the solution - if this does not work - raise a support case with F5.
- jkrumenacher_13
Nimbostratus
samestep, Thanks, I do believe that is exactly what I am seeing and have modified my user_alert file. I am doing a failover tonight so I will watch NTP.
Thanks again.
jkrum
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com