- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
FortiGate Firewall Local NTP Server Not Sync
Hi All ,
We've FortiGate Firewalls running Active-Passive HA. We've enabled VDOMs and root VDOM is the management VDOM.
We have local NTP server. But FortiGate time is not syncing with local NTP server.
FGT-INR03 (global) # execute time
current time is: 16:08:13
last ntp sync: never
sys_update_timer_func:1755 synchronized=0
Sorted NTP endpoints.
NTP daemon uses a upper end of -2000000000.000000 and a lower end of 2000000000.000000.
no server suitable for synchronization found
ntp_dns_cb:1926 in_flight=0 resolved=0 ipv6=0
ntp_dns_cb:1926 in_flight=0 resolved=0 ipv6=0
waiting for 9 seconds .
Our FortiGate has no internet access, so it's impossible to reach FortiGuard and we must sync with local NTP server.Can you please help me how can I sync with Local NTP server on VDOM enabled HA environment?
Thank you
Solved! Go to Solution.
- Labels:
-
FortiGate
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Can you confirm if the NTP server reachable is via dedicated mgmt interface or not? If it is via dedicated mgmt interface, make sure you have enabled HA direct.
If it is not via the dedicated mgmt interface, are you able to ping the server? Can you run a sniffer to capture NTP traffic?
NTP Sniffer: https://community.fortinet.com/t5/FortiGate/Technical-Tip-Troubleshoot-NTP-synchronization-issue/ta-...
HA-direct : https://docs.fortinet.com/document/fortigate/7.2.4/administration-guide/313152/out-of-band-managemen...
Suraj
- Have you found a solution? Then give your helper a "Kudos" and mark the solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Can you confirm if the NTP server reachable is via dedicated mgmt interface or not? If it is via dedicated mgmt interface, make sure you have enabled HA direct.
If it is not via the dedicated mgmt interface, are you able to ping the server? Can you run a sniffer to capture NTP traffic?
NTP Sniffer: https://community.fortinet.com/t5/FortiGate/Technical-Tip-Troubleshoot-NTP-synchronization-issue/ta-...
HA-direct : https://docs.fortinet.com/document/fortigate/7.2.4/administration-guide/313152/out-of-band-managemen...
Suraj
- Have you found a solution? Then give your helper a "Kudos" and mark the solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thank you and let me check again today
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello Evan,
If it's not responding to FortiGuard Servers try setting custom NTP Server [ time.google.com ]. You can only set custom NTP server using CLI. Take the debugs and sniffer whether you see traffic for port 123 or not.
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Custom-NTP-server-configuration/ta-p/19192...
