Skip to main content

NTP Server Setup

So some time back I was asked to set up an NTP (Network Time Protocol) server for a client. The particular environment only has a few servers that can access the internet, which were used primarily for WSUS, and the rest of the environment has internet access blocked. So, in this process I'll walk you through installing Meinberg NTP Software (check them out here) and then configuring the PDC's (Primary Domain Controller) registry to obtain time from the newly installed service. I know, I could just set a GPO to order all of the servers in the network to get time from the NTP server, but my goal in this was to limit traffic to the internet connected servers. What I found out is that by default all Windows systems get their time from the PDC by default and update at the time of login. By changing the PDC's registry this default configuration stays in place, and I don't have to wait for the GPO to update throughout the network...

Setup and Instillation

  • Create NTP service account in AD and take note of userID and password
  • On the chosen NTP server create a folder on the C:\ drive named "NTP Files" <this will be our instillation path
  • Download two files from http://www.minbergglobal.com/english/sw/ntp.htm
    • ntp-4.2.6@london-o-lpv-232-setup.exe
    • ntp-time-server-monitor-1.04.exe
  • Instill both files on the chosen NTP server but make sure to direct the instillation path to place the files in the "C:\NTP Files" folder
  • Specify NPT service account
  • Specify NTP Servers as follows:
    • server 0.us.pool.ntp.org
    • server 1.us.pool.ntp.org
    • server 2.us.pool.ntp.org
    • server 3.us.pool.ntp.org
Configuring the PDC

The first think you'll need to do is verify which server is the PDC. This is done by opening a command prompt on one of the DCs and issuing:
  • netdom /query fismo
Once you have verified the PDC, open an Administrative command prompt and issue the following commands:
  • net stop w32time
  • w32tm /config /syncfromflags:manual /manualpeerlist:<hostnameOfServer>
  • w32tm /config /reliable:yes
  • net start w32time
To check the NTP configuration issue command:
  • w32tm /query /configuration
To force the PDC to sync with the time server issue command:
  • w32tm /resync
Check the Event Viewer for any errors, and if this didn't work than you may need to manually edit the registry to point the PDC to the time server. Here's how to do that:
  1. Click Start, click Run, type regedit, then click OK
  2. Locate and select the following registry entry: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W32Time\Parameters
  3. Select the NtpServer  key and in the Value data section add the host name of the server followed by 0x1
    1. EX: server.domain.local,0x1
  4. Open an Administrative command prompt and issue
    1. net stop w32time && net start w32time
Repeat these steps to configure the backup DC to obtain it's time manually from the PDC or the Time Server.

Be sure to get your Googleing experience on if you run into any issues. There is a lot of documentation out there for setting up time servers in Windows. This is just a quick and dirty compressed guide of what worked for me.

Comments

Popular posts from this blog

Getting Samsung Dex Configured to Work with Azure DevOps Repos

Recently, I upgraded my phone to the Samsung Galaxy Note 10+... I'm a big fan of big phones (a perk to being a big guy). I've always been intrigued with the idea of using one device for everything. Well, with the Samsung Dex application that comes built into these next gen phones, it might be possible...?  As a guy that spends a lot of time working on ARM Templates and PowerShell scripts for Azure management, I was curious to see if I could get my phone, using Dex, connected to my Azure DevOps environment and start working with repos.... Well, to my surprise, I was able to, and without much pain. So, in this post, I'll run through how I got my Dex environment setup and working with Azure DevOps Repos. Getting Started With Samsung Dex open, go to the Google Play store and install Termux ( https://play.google.com/store/apps/details?id=com.termux&hl=en_US ) Once that's installed, open it! Next, we need to gift Termux with permissions to a...

Using Python for GPG/PGP File Encryption - Part 1

So, this will be the start of a series that will build a python script for GPG/PGP file encryption. In this post, we'll look at installing gnupg for python and using python to setup the keystore, create a private key, exporting the associated public key, and importing a public key. Now everything done here can be done with simple gnupg commands, but learning how to do this with python will help in understanding the script we'll be building to complete file encryption. I will be covering non-python gnupg commands in a future post. Additionally, the folks at the python-gnupg site over at pythonhosted.org have done a really great job at documenting everything (link to their site at the bottom). The stuff I'll be going over will be more of a start-to-finish for anyone that may get lost in the muck of doing stuff with python. Full Disclosure #1: Any key identifier throughout the series of posts is FICTITIOUS and DOES NOT represent any real key, either associated with myself or...

Amazon and Two-Factor Auth

In this post, I'll go over setting up Two-Factor Authentication for an Amazon account. If you want more information about Two-Factor Authentication and an app recommendation, see my post on the topic HERE . If you're ready to get started, then let's go! As I've said before, this is not meant to be an in-depth guide, but more of a how-to for those that wouldn't normally think of turning on additional security settings. With that, let's get started: 1) Go to Your Account in the upper right, and fine Account Settings toward the bottom of the page: 2) Next you should see an option for Advanced Security Settings, select the Edit button: 3) On the next page you should have the open to turn on Two-Step Verification. Select the Get Started button to turn this on. 4.1) On the next page you'll have the option to either use SMS messaging or an authenticatior app. If you went through my post on 2-factor for all and installed the DUO Mobile app on your de...