Hello,
we have a Fortigate 300E with v7.0.0 build0066 (GA), we are using our Fortigate as a second NTP Server, everything was working, but since a couple days the NTP on the Fortigate is not reachable.
The Funktion is enable and with "diag sys ntp status" i see that is working
"HA primary: yes, HA primary ip: 1.0.0.0, management_vfid: 0 ha_direct=0, ha_mgmt_vfid=-1 synchronized: yes, ntpsync: enabled, server-mode: enabled ipv6 server(ptbtime3.ptb.de) 2001:638:610:be01::103 -- reachable(0xff) S:2 T:94 server-version=4, stratum=1 reference time is e4b5fecd.a1e46175 -- UTC Thu Aug 5 06:08:13 2021 clock offset is -0.099885 sec, root delay is 0.000015 sec root dispersion is 0.000015 sec, peer dispersion is 2465 msec ipv4 server(ptbtime3.ptb.de) 192.53.103.103 -- reachable(0xff) S:2 T:94 server-version=4, stratum=1 reference time is e4b5fecd.a1e46175 -- UTC Thu Aug 5 06:08:13 2021 clock offset is -0.099629 sec, root delay is 0.000015 sec root dispersion is 0.000015 sec, peer dispersion is 1807 msec"
But the Servers cannot reach the NTP Service on the Fortigate,
i got the message
"ICMP:0ms delay
NTP:error Error_Timeout - no response from server in 1000ms
If i use "diagnose sniffer packet any 'port 123'", i can see the traffic extern and intern, there is communication,
but NTP is not reachable on the Fortigate.
The Fortigate has automatic restart everyday at 3am
I dont have any idee whats the problem
Hi Alexander,
Could you share your NTP configuration and topology diagram?
And you said that FGT restarts at 3 am every day. Is this the expected result? Or is the firewall restarted abnormally?
Looking forward to your reply.
Thank you
Thanks
Kangming
Are you sure the ntp_client is good. I would do a ntptrace or ntpquery
e.g macosx to my fgt ntp-server fortios7
supports-MacBook-Pro:~ ken$ sudo sntp -sS 192.168.1.99sudo: ignoring time stamp from the futurePassword:sntp 4.2.8p10@1.3728-o Tue Mar 21 14:36:42 UTC 2017 (139~6507)kod_init_kod_db(): Cannot open KoD db file /var/db/ntp-kod: No such file or directory2021-09-02 15:00:29.388269 (+0500) +491.1 +/- 327.479966 192.168.1.99 s3 no-leap SOCPUPFGT60F # show sys ntp config system ntp set ntpsync enable set server-mode enable set interface "internal"end Ken Felix
PCNSE
NSE
StrongSwan
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1737 | |
1107 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.