Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Clock Issue

    Scheduled Pinned Locked Moved Hardware
    31 Posts 5 Posters 2.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      jp141 @fireodo
      last edited by

      @fireodo Thanks, yeah I have that setup but it doesn't seem to keep it in check, looking at the logs it looks like its working ok until the clock gets too far out then I see errors

      03dd1ecd-52ac-4965-9adf-141e2b7b5d0d-image.png
      03cb0ee5-c385-4e17-8a19-858da0ce8cd2-image.png
      f1d11acd-5801-4d89-aa83-f802f9bf10be-image.png

      1 Reply Last reply Reply Quote 0
      • J
        jp141
        last edited by

        However arnt these the settings for the NTP service that the firewall puts out to the lan, not the NTP receiver service?

        fireodoF 1 Reply Last reply Reply Quote 0
        • fireodoF
          fireodo @jp141
          last edited by

          @jp141 said in Clock Issue:

          However arnt these the settings for the NTP service that the firewall puts out to the lan, not the NTP receiver service?

          Both, receiver & service. Is your WAN_VODAFONE included or excludet?

          Kettop Mi4300YL CPU: i5-4300Y @ 1.60GHz RAM: 8GB Ethernet Ports: 4
          SSD: SanDisk pSSD-S2 16GB (ZFS) WiFi: WLE200NX
          pfsense 2.8.0 CE
          Packages: Apcupsd, Cron, Iftop, Iperf, LCDproc, Nmap, pfBlockerNG, RRD_Summary, Shellcmd, Snort, Speedtest, System_Patches.

          E J 2 Replies Last reply Reply Quote 0
          • E
            elvisimprsntr @fireodo
            last edited by elvisimprsntr

            @jp141

            1. Looks like your NTP server cannot reach your configured WAN NTP pools. What's the status of the following command
            ntpq -pn
            

            Example

            /root: ntpq -pn
                 remote           refid      st t when poll reach   delay   offset  jitter
            ==============================================================================
            o127.127.20.0    .GPS.            0 l    2    8  377    0.000   +0.002   0.003
             time.nist.gov   .POOL.          16 p    -   64    0    0.000   +0.000   0.000
            +132.163.96.4    .NIST.           1 u   51   64  377   50.868   +0.618   0.366
            +132.163.97.6    .NIST.           1 u   30   64  377   49.819   +0.604   0.366
            +132.163.97.4    .NIST.           1 u   17   64  377   49.849   +0.427   0.431
            
            1. Did you confiture a NTP server under System -> General?

            Screenshot 2025-03-13 at 10.08.36 AM.png

            1 Reply Last reply Reply Quote 0
            • J
              jp141 @fireodo
              last edited by

              @fireodo Its excluded, thats the main WAN, I was under the impression you selected internal interfaces on that page thats the way I have used PFSense on other hardware for years, is that wrong?

              fireodoF 1 Reply Last reply Reply Quote 0
              • J
                jp141
                last edited by jp141

                Interestingly the time corrects itself on a full system restart but not an NTP service restart

                @elvisimprsntr I get this if I run that command:

                0fa53d95-1ee9-4502-af45-dcd256d031a5-image.png

                1 Reply Last reply Reply Quote 0
                • fireodoF
                  fireodo @jp141
                  last edited by

                  @jp141 said in Clock Issue:

                  Its excluded, thats the main WAN

                  Probably this is the cause your box cannot reach the NTP servers so it cannot synchronize ...

                  Kettop Mi4300YL CPU: i5-4300Y @ 1.60GHz RAM: 8GB Ethernet Ports: 4
                  SSD: SanDisk pSSD-S2 16GB (ZFS) WiFi: WLE200NX
                  pfsense 2.8.0 CE
                  Packages: Apcupsd, Cron, Iftop, Iperf, LCDproc, Nmap, pfBlockerNG, RRD_Summary, Shellcmd, Snort, Speedtest, System_Patches.

                  1 Reply Last reply Reply Quote 0
                  • J
                    jp141
                    last edited by jp141

                    Ahhha @elvisimprsntr @fireodo you both seem to be on to something, I enabled the WAN interface and now I am getting much more NTP info and the clock has corrected itself!! will monitor it but it looks like you may have fixed my issue, many thanks! the wording on that page should really be a bit more helpful, it even says you are selecting the interfaces for it to listen on not send requests out on!

                    6aeaa171-f805-4810-9fe1-20b675fa03f9-image.png

                    fireodoF E 2 Replies Last reply Reply Quote 0
                    • fireodoF
                      fireodo @jp141
                      last edited by

                      @jp141

                      Glad its working now!

                      Kettop Mi4300YL CPU: i5-4300Y @ 1.60GHz RAM: 8GB Ethernet Ports: 4
                      SSD: SanDisk pSSD-S2 16GB (ZFS) WiFi: WLE200NX
                      pfsense 2.8.0 CE
                      Packages: Apcupsd, Cron, Iftop, Iperf, LCDproc, Nmap, pfBlockerNG, RRD_Summary, Shellcmd, Snort, Speedtest, System_Patches.

                      J 1 Reply Last reply Reply Quote 0
                      • J
                        jp141 @fireodo
                        last edited by jp141

                        @fireodo Thanks for your help :) this has been driving me nuts for weeks

                        1 Reply Last reply Reply Quote 0
                        • E
                          elvisimprsntr @jp141
                          last edited by elvisimprsntr

                          @jp141

                          I don't think you want to enable the WAN interface on the NTP server settings unless you are planning to advertise your personal NTP server on the public internet. See example

                          Screenshot 2025-03-13 at 10.22.40 AM.png

                          Check your System -> General setting.

                          J 1 Reply Last reply Reply Quote 0
                          • J
                            jp141 @elvisimprsntr
                            last edited by

                            @elvisimprsntr Well see thats what I thought, this is the general setting, I didnt have anything in the DNS servers until earlier, I added 127.0.0.1, im using the local resolver, possibly it needs something in there even if its just 127.0.0.1

                            02193e8e-556f-41ea-8574-7ce99198bf70-image.png

                            E 1 Reply Last reply Reply Quote 0
                            • E
                              elvisimprsntr @jp141
                              last edited by

                              @jp141

                              You will want to add a valid external DNS server to the System -> General settings.

                              Otherwise it will not be able to resolve DNS names

                              Screenshot 2025-03-13 at 10.27.30 AM.png

                              J fireodoF 2 Replies Last reply Reply Quote 0
                              • J
                                jp141
                                last edited by jp141

                                Without the wan selected I get this:

                                6815a612-5677-466f-b2f3-14227b020b7b-image.png

                                With the WAN selected I get this:

                                50a18493-8bf1-4449-83ed-23dda6c9294e-image.png

                                So that must need to be selected, as long as I don't have a firewall rule allowing NTP on the WAN interface it shouldn't be accessible from the outside world right?

                                E 1 Reply Last reply Reply Quote 1
                                • J
                                  jp141 @elvisimprsntr
                                  last edited by

                                  @elvisimprsntr Im using the DNS Resolver Service, never had an issue with the firewall installing packages or updates so it can resolve ok with just that and this command was working fine ntpdate -q 0.pfsense.pool.ntp.org

                                  1 Reply Last reply Reply Quote 1
                                  • fireodoF
                                    fireodo @elvisimprsntr
                                    last edited by

                                    @elvisimprsntr said in Clock Issue:

                                    You will want to add a valid external DNS server to the System -> General settings.

                                    Only if you want to forward to this DNS Servers. Pfsense can resolve out from the box ...

                                    Kettop Mi4300YL CPU: i5-4300Y @ 1.60GHz RAM: 8GB Ethernet Ports: 4
                                    SSD: SanDisk pSSD-S2 16GB (ZFS) WiFi: WLE200NX
                                    pfsense 2.8.0 CE
                                    Packages: Apcupsd, Cron, Iftop, Iperf, LCDproc, Nmap, pfBlockerNG, RRD_Summary, Shellcmd, Snort, Speedtest, System_Patches.

                                    1 Reply Last reply Reply Quote 0
                                    • E
                                      elvisimprsntr @jp141
                                      last edited by elvisimprsntr

                                      @jp141

                                      You have likely made too many changes from the defaults that are conflicting with each other.

                                      If you are relatively new to pfSense, you should use the defaults unless you are a spefiic reason to change them. Then only change them one at a time.

                                      J 1 Reply Last reply Reply Quote 0
                                      • J
                                        jp141 @elvisimprsntr
                                        last edited by

                                        @elvisimprsntr Not new been using it for 15-20 years 😆

                                        E 1 Reply Last reply Reply Quote 0
                                        • E
                                          elvisimprsntr @jp141
                                          last edited by

                                          @jp141

                                          Suggest changing the following setting

                                          Screenshot 2025-03-13 at 10.37.43 AM.png

                                          J 1 Reply Last reply Reply Quote 1
                                          • J
                                            jp141 @elvisimprsntr
                                            last edited by

                                            @elvisimprsntr Yeah I will set that and a google DNS server just incase there is ever an issue with the resolver.

                                            E 1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.