Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
pfSense Forum
pfSense English Support
»
NAT
»
Time sync on all PCs
Username:
Password:
1 Hour
1 Day
1 Week
1 Month
Forever
Home
Help
Search
Login
Register
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: Time sync on all PCs (Read 1761 times)
0 Members and 1 Guest are viewing this topic.
BigTy
Jr. Member
Offline
Posts: 33
Time sync on all PCs
«
on:
April 15, 2007, 08:49:00 am »
Looks like I have one more small issue. Any PC Windows Vista, XP, Mac will not do a time sync is there anything I can do to resolve this small issue?
I do want to thank you guys for all the help with this venture.
Logged
hoba
Administrator
Hero Member
Offline
Posts: 5844
What was the problem to this solution again?
Re: Time sync on all PCs
«
Reply #1 on:
April 15, 2007, 01:58:44 pm »
Where do the clients try to sync to? The pfSense or an external timeserver? If it's the pfSense, did you configure the timeserver for your clients correctly?
Logged
BigTy
Jr. Member
Offline
Posts: 33
Re: Time sync on all PCs
«
Reply #2 on:
April 15, 2007, 03:30:44 pm »
No I tried all external based servers like the two defaults in XP and Vista and time.apple.com on the MAC.
Logged
hoba
Administrator
Hero Member
Offline
Posts: 5844
What was the problem to this solution again?
Re: Time sync on all PCs
«
Reply #3 on:
April 15, 2007, 05:25:32 pm »
I don't see this problem here. Do you use a restrictive ruleset at you LAN interface or are you using the default lan to any allow rule?
Logged
BigTy
Jr. Member
Offline
Posts: 33
Re: Time sync on all PCs
«
Reply #4 on:
April 15, 2007, 07:10:29 pm »
Defualt allow all.
Logged
cmb
Administrator
Hero Member
Offline
Posts: 6054
Re: Time sync on all PCs
«
Reply #5 on:
April 17, 2007, 07:34:39 pm »
Try to sync a machine and check your firewall log. See anything relevant?
Also might want to add a pass rule for UDP port 123, enable logging on it, and put it above your default rule. That way all NTP traffic will be logged and you can see if it's getting permitted.
Logged
pfSense Commercial Support
Paying customers receive support priority and as in depth of assistance as desired through the official commercial support channels at portal.pfsense.org. Forum users receive as much help as time permits.
BigTy
Jr. Member
Offline
Posts: 33
Re: Time sync on all PCs
«
Reply #6 on:
April 20, 2007, 05:30:02 pm »
Good news that did resolve the issue. Any reason as to why that wouldnt work with the default setting?
Logged
hoba
Administrator
Hero Member
Offline
Posts: 5844
What was the problem to this solution again?
Re: Time sync on all PCs
«
Reply #7 on:
April 22, 2007, 09:29:50 am »
What cmb suggested was only needed for debugging. It should work with the default settings and it actually does for me.
Logged
cmb
Administrator
Hero Member
Offline
Posts: 6054
Re: Time sync on all PCs
«
Reply #8 on:
April 22, 2007, 08:42:19 pm »
Yeah what I suggested wouldn't fix the issue, it would just tell you whether or not the NTP traffic was passing the firewall. If your LAN rule was allow all, it wouldn't have changed anything with your rules.
Logged
pfSense Commercial Support
Paying customers receive support priority and as in depth of assistance as desired through the official commercial support channels at portal.pfsense.org. Forum users receive as much help as time permits.
BigTy
Jr. Member
Offline
Posts: 33
Re: Time sync on all PCs
«
Reply #9 on:
April 23, 2007, 05:07:51 pm »
more status on this issue as of today it is no longer working and this is with the other rule in place.
Here are the logs
Apr 23 18:04:39 pf: 10. 726712 rule 38/0(match): pass in on xl0: 192.X.X.X.123 > 207.46.130.100.123: NTPv3, symmetric active, length 48
Apr 23 18:00:32 pf: 156. 377540 rule 38/0(match): pass in on xl0: 192.X.X.123 > 192.43.244.18.123: NTPv3, symmetric active, length 48
Apr 23 17:57:56 pf: 23. 546766 rule 38/0(match): pass in on xl0: 192.X.X.X.123 > 192.43.244.18.123: NTPv3, symmetric active, length 48
Apr 23 17:57:32 pf: 86. 472199 rule 38/0(match): pass in on xl0: 192.X.X.X.123 > 207.46.130.100.123: NTPv3, symmetric active, length 48
Windows reporting time period exspired
Here are the rules
UDP * * * 123 (NTP) * NTP Rule
* LAN net * * * * Default LAN -> any
*Update*
Removed the first rule and it looks to have returned again. I think I may have found something not 100% sure but it does fail on the first appemt but does complete on the second third and forth attempt.
«
Last Edit: April 23, 2007, 05:13:11 pm by BigTy
»
Logged
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
Administrative
-----------------------------
=> Forum rules
=> Messages from the pfSense Team
=> Feedback
-----------------------------
pfSense English Support
-----------------------------
=> Installation and Upgrades
=> General Questions
=> 2.1 Snapshot Feedback and Problems
=> Post a bounty
===> Completed Bounties
===> Expired/Withdrawn Bounties
=> Hardware
=> Firewalling
=> NAT
=> CARP/VIPs
=> Routing and Multi WAN
=> Traffic Shaping
=> DHCP and DNS
=> IPv6
=> IPsec
=> PPTP
=> PPPoE Server
=> Captive Portal
=> webGUI
=> Wireless
=> SNMP
=> Packages
=> Virtualization installations and techniques
=> OpenVPN
=> Gaming
-----------------------------
Development/Documentation
-----------------------------
=> Documentation
=> Development
-----------------------------
General Category
-----------------------------
=> General Discussion
-----------------------------
International Support
-----------------------------
=> Indonesian
=> Deutsch
=> Español
=> Français
=> Italiano
=> Russian
=> Nederlands
=> Norwegian
=> Portuguese
=> Polish
=> Romanian
=> Swedish
=> Turkish
-----------------------------
Retired
-----------------------------
=> 1.2.3-PRERELEASE-TESTING snapshots - RETIRED
=> 1.2.1-RC Snapshot Feedback and Problems-RETIRED
=> 2.0-RC Snapshot Feedback and Problems - RETIRED
=> DNS Server testing area - RETIRED
Loading...