Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Alexander_Mueller
New Contributor

Fortigate and NTP Server not working

Hello,

 

we have a Fortigate 300E with v7.0.0 build0066 (GA), we are using our Fortigate as a second NTP Server, everything was working, but since a couple days the NTP on the Fortigate is not reachable.

The Funktion is enable and with "diag sys ntp status" i see that is working

 

"HA primary: yes, HA primary ip: 1.0.0.0, management_vfid: 0 ha_direct=0, ha_mgmt_vfid=-1 synchronized: yes, ntpsync: enabled, server-mode: enabled ipv6 server(ptbtime3.ptb.de) 2001:638:610:be01::103 -- reachable(0xff) S:2 T:94         server-version=4, stratum=1         reference time is e4b5fecd.a1e46175 -- UTC Thu Aug  5 06:08:13 2021         clock offset is -0.099885 sec, root delay is 0.000015 sec         root dispersion is 0.000015 sec, peer dispersion is 2465 msec ipv4 server(ptbtime3.ptb.de) 192.53.103.103 -- reachable(0xff) S:2 T:94         server-version=4, stratum=1         reference time is e4b5fecd.a1e46175 -- UTC Thu Aug  5 06:08:13 2021         clock offset is -0.099629 sec, root delay is 0.000015 sec         root dispersion is 0.000015 sec, peer dispersion is 1807 msec"

 

But the Servers cannot reach the NTP Service on the Fortigate,

i got the message

"ICMP:0ms delay

NTP:error Error_Timeout - no response from server in 1000ms

 

If i use "diagnose sniffer packet any 'port 123'", i can see the traffic extern and intern, there is communication,

but NTP is not reachable on the Fortigate.

 

The Fortigate has automatic restart everyday at 3am

 

I dont have any idee whats the problem

2 REPLIES 2
Kangming
Staff
Staff

Hi Alexander, 

 

Could you share your NTP configuration and topology diagram?

And you said that FGT restarts at 3 am every day. Is this the expected result? Or is the firewall restarted abnormally?

 

Looking forward to your reply.

Thank you

 

Thanks

Kangming

emnoc
Esteemed Contributor III

Are you sure the ntp_client is good. I would do a ntptrace or ntpquery

 

e.g macosx to my fgt ntp-server fortios7

 

supports-MacBook-Pro:~ ken$ sudo sntp -sS 192.168.1.99

sudo: ignoring time stamp from the future

Password:

sntp 4.2.8p10@1.3728-o Tue Mar 21 14:36:42 UTC 2017 (139~6507)

kod_init_kod_db(): Cannot open KoD db file /var/db/ntp-kod: No such file or directory

2021-09-02 15:00:29.388269 (+0500) +491.1 +/- 327.479966 192.168.1.99 s3 no-leap

 

SOCPUPFGT60F # show sys ntp 

config system ntp

    set ntpsync enable

    set server-mode enable

    set interface "internal"

end

 

Ken Felix

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Labels
Top Kudoed Authors