Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Bogus time in NTP status widget

    Scheduled Pinned Locked Moved webGUI
    19 Posts 6 Posters 1.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • provelsP
      provels @johnpoz
      last edited by

      @johnpoz said in Bogus time in NTP status widget:

      w32tm /monitor /computers:192.168.9.100,192.168.9.253,192.168.3.32

      Thanks for the command. For some reason my host won't give me the time, but I wasn't really concerned. Everyone goes to pool.ntp.org anyway. Just thought the disparity in the display was unusual.
      b38ea381-bc4f-4ae7-a91b-8844ee0938f6-image.png

      Peder

      MAIN - pfSense+ 24.11-RELEASE - Adlink MXE-5401, i7, 16 GB RAM, 64 GB SSD. 500 GB HDD for SyslogNG
      BACKUP - pfSense+ 23.01-RELEASE - Hyper-V Virtual Machine, Gen 1, 2 v-CPUs, 3 GB RAM, 8GB VHDX (Dynamic)

      johnpozJ 1 Reply Last reply Reply Quote 0
      • johnpozJ
        johnpoz LAYER 8 Global Moderator @provels
        last edited by

        @provels said in Bogus time in NTP status widget:

        Everyone goes to pool.ntp.org anyway

        No not everyone ;) You have all your devices go to out to the internet to pool? Why would they not sync either off pfsense or your local ntp server?

        My ntp server participates by being a server in the pool.. But no I don't sync time from there.

        If you have client A syncing to pool, and client B syncing to pool - they could have quite a bit of difference in time, when it comes to what is possible with ntp.. Vs all clients syncing to the same source like your pfsense, even if pfsense syncs from pool.

        Your talking milliseconds normally here.. But when it comes to ntp, 80ms and 1ms is a big difference ;) heheh Normally like to be sub ms range.

        Pfsense time looks to be fine, and would assume your client the same, etc. I think the whole issue here is trying to express time in a browser widget ;)

        I would assume when @rmaeder refreshes his browsers any large differences in the widgets goes away.

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.8, 24.11

        rmaederR kiokomanK provelsP 3 Replies Last reply Reply Quote 0
        • rmaederR
          rmaeder @johnpoz
          last edited by

          @johnpoz said in Bogus time in NTP status widget:

          I would assume when @rmaeder refreshes his browsers any large differences in the widgets goes away.

          when I put the pfsense window into the background for 10 minutes, then bring it back, the time in the ntp widget is off by about 5 minutes.

          1 Reply Last reply Reply Quote 0
          • kiokomanK
            kiokoman LAYER 8 @johnpoz
            last edited by kiokoman

            it's a simple php line

            <div id="datetime"><?= date("D M j G:i:s T Y"); ?></div>
            

            with a functuon that update every 6

            function stats(x) {
            ...
            updateDateTime(values[6]);
            ...
            }
            

            it is not meant to be a precision time keeper,
            it's more like a "snapshot" for when you go to the dashboard

            ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
            Please do not use chat/PM to ask for help
            we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
            Don't forget to Upvote with the 👍 button for any post you find to be helpful.

            1 Reply Last reply Reply Quote 0
            • provelsP
              provels @johnpoz
              last edited by provels

              @johnpoz said in Bogus time in NTP status widget:

              Why would they not sync either off pfsense or your local ntp server?

              This, pfSense. NTP listening on LAN or ALL.
              5623eb1b-9eab-4ddd-9938-73e4c252f16d-image.png

              If you have client A syncing to pool, and client B syncing to pool - they could have quite a bit of difference in time

              Understood, thanks.

              Peder

              MAIN - pfSense+ 24.11-RELEASE - Adlink MXE-5401, i7, 16 GB RAM, 64 GB SSD. 500 GB HDD for SyslogNG
              BACKUP - pfSense+ 23.01-RELEASE - Hyper-V Virtual Machine, Gen 1, 2 v-CPUs, 3 GB RAM, 8GB VHDX (Dynamic)

              johnpozJ 1 Reply Last reply Reply Quote 0
              • johnpozJ
                johnpoz LAYER 8 Global Moderator @provels
                last edited by johnpoz

                What are you lan rules - the any any rule? Are you forcing traffic out a gateway? Do you have floating rules?

                Windows should sync time with ntp on pfsense, if ntp services are running and in sync and you have the firewall rules to allow it.

                I personally run actual ntp on my windows machine vs the built in service.. But that is just me..

                But windows way still works

                server.png

                sync.png

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.8, 24.11

                provelsP 1 Reply Last reply Reply Quote 0
                • provelsP
                  provels @johnpoz
                  last edited by

                  @johnpoz
                  Tried hitting Update again a few more times, then it worked. 🤷 LAN rules are pfBlockerNG generated plus LAN/ANY. I don't think LAN rules should be required to use NTP. I'm pretty sure I remember having clients set to pfSense time in the past, but the times getting out of whack so I went back to pools.

                  4aa342b8-89d2-4a5a-9118-0151e15783c1-image.png

                  Peder

                  MAIN - pfSense+ 24.11-RELEASE - Adlink MXE-5401, i7, 16 GB RAM, 64 GB SSD. 500 GB HDD for SyslogNG
                  BACKUP - pfSense+ 23.01-RELEASE - Hyper-V Virtual Machine, Gen 1, 2 v-CPUs, 3 GB RAM, 8GB VHDX (Dynamic)

                  johnpozJ 1 Reply Last reply Reply Quote 0
                  • johnpozJ
                    johnpoz LAYER 8 Global Moderator @provels
                    last edited by johnpoz

                    @provels said in Bogus time in NTP status widget:

                    I don't think LAN rules should be required to use NTP.

                    Not if they default any any.. But if you had modified the rules in a such a manner then sure you could block them. I do not believe there are hidden rules like there is with dhcp.. But maybe there is. I would have to look.. BRB

                    yeah I don't see hidden rules that allow ntp when you enable it, like what happens with dhcpd.. So yeah it would be quite possible for a user to block ntp in their firewall rules. Out of the box no, the default any any rule would allow it.

                    Personally the built in time sync of windows is a bit lacking ;) I just disable it and use the actual client from ntp.org - you can grab a windows copy here
                    https://www.meinbergglobal.com/english/sw/ntp.htm

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 24.11 | Lab VMs 2.8, 24.11

                    provelsP 1 Reply Last reply Reply Quote 1
                    • provelsP
                      provels @johnpoz
                      last edited by

                      @johnpoz said in Bogus time in NTP status widget:

                      I just disable it and use the actual client from ntp.org

                      Thanks, maybe I'll try that.
                      They say the man with 2 watches never really knows what time it is... :)

                      Peder

                      MAIN - pfSense+ 24.11-RELEASE - Adlink MXE-5401, i7, 16 GB RAM, 64 GB SSD. 500 GB HDD for SyslogNG
                      BACKUP - pfSense+ 23.01-RELEASE - Hyper-V Virtual Machine, Gen 1, 2 v-CPUs, 3 GB RAM, 8GB VHDX (Dynamic)

                      johnpozJ 1 Reply Last reply Reply Quote 0
                      • johnpozJ
                        johnpoz LAYER 8 Global Moderator @provels
                        last edited by

                        ut-oh ;) we may have a future stratum 1 time server owner soon..

                        ntp is fascinating to me.. There are few around here as well that run their own.. It can be done fairly cheaply with pi and a gps hat for it.

                        Some interesting threads if you look for them.. Some have some really great setups, mine is bit older and not as accurate as it could be.. It sub 1ms, have seen like 20ns setups..

                        I have not gotten into the tinker with it mood in quite some time to play around with tweaking it to see if could get it to be more stable. Last thing I did with it really was switch it to running ntpsec... I should prob reset up my monitoring of it I guess ;) To better track how well its doing..

                        pi@ntp:~ $ ntpq
                        ntpq> pe
                             remote                                   refid      st t when poll reach   delay   offset   jitter
                        =======================================================================================================
                        *SHM(1)                                  .PPS.            0 l    -    8  377   0.0000  -0.0388   0.0088
                        

                        Looks to be within 40ns - but should prob graph that to see how its drifting, etc.

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 24.11 | Lab VMs 2.8, 24.11

                        1 Reply Last reply Reply Quote 2
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.