Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    ERROR NTP

    Scheduled Pinned Locked Moved Official Netgate® Hardware
    9 Posts 4 Posters 708 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      Marlon Alvarez
      last edited by

      I updated pfsense from version 2.6.0 to version 2.7.0, the configuration was uploaded, all the services are working but the NTP server service is not working correctly since it is not synchronizing the time to the client hosts, is there any error or option that performed the synchronization correctly

      V 1 Reply Last reply Reply Quote 0
      • V
        viragomann @Marlon Alvarez
        last edited by

        @Marlon-Alvarez
        Are the clients even configured to request pfSense?
        Are they allowed to access it?

        Does the NTP status widget show the correct time?

        1 Reply Last reply Reply Quote 0
        • M
          Marlon Alvarez
          last edited by

          Are the clients even configured to request pfSense?
          If currently the client hosts are configured to request the time from pfsense

          Are they allowed to access it?
          If client hosts are allowed to access it they respond to the pfsense ntp server

          Does the NTP status widget show the correct time?
          if the widget shows the correct time status

          Attached configuration images

          Services Status
          729adce2-6426-4eb9-ae38-a3bbb5a7b256-image.png
          d2b02262-6ede-4238-894e-38816567b2a3-image.png

          On the DHCP is set as "NTP Server 1"

          18ce5d6f-430d-4682-a027-15cbc19b915b-image.png

          Host client

          39a4b7c9-c9c8-4d3e-9c30-83bb38bde102-image.png

          1 Reply Last reply Reply Quote 0
          • stephenw10S
            stephenw10 Netgate Administrator
            last edited by

            Do you see open states on port 123 from clients querying pfSense?

            Do you see ntp listening on port 123 in the output of: sockstat | grep 123 ?

            You LAN firewall rules allow access on port 123?

            Steve

            M 1 Reply Last reply Reply Quote 0
            • M
              Marlon Alvarez @stephenw10
              last edited by

              @stephenw10

              Do you see open states on port 123 from clients querying pfSense?
              yes, currently clients have port 123 enabled
              77d77870-e305-428c-8c1d-94864e86ace3-image.png

              Do you see ntp listening on port 123 in the output of: sockstat | grep 123 ?
              yes, currently pfsense is listening for output port 123

              21ee22ca-6924-478c-aebc-e972c470f0da-image.png

              You LAN firewall rules allow access on port 123?
              Yes, currently pfsense has rules allowed on the LAN

              I don't know if it's because of the new version 2.7.0 that changed something about the ntp synchronization with the client hosts, did you previously have a connection?

              1 Reply Last reply Reply Quote 0
              • stephenw10S
                stephenw10 Netgate Administrator
                last edited by

                But do you see states on pfSense from clients querying the NTP server?

                M 1 Reply Last reply Reply Quote 0
                • M
                  Marlon Alvarez @stephenw10
                  last edited by

                  @stephenw10 How do I see which clients consult NTP server from pfsense?

                  T 1 Reply Last reply Reply Quote 0
                  • T
                    tman222 @Marlon Alvarez
                    last edited by

                    @Marlon-Alvarez said in ERROR NTP:

                    @stephenw10 How do I see which clients consult NTP server from pfsense?

                    One way you could do that: Go to Diagnostics -> pfTop and under Filter expression field put: dst port 123

                    Hope this helps.

                    1 Reply Last reply Reply Quote 0
                    • stephenw10S
                      stephenw10 Netgate Administrator
                      last edited by

                      Yup that or go to Diag > States and filter on the LAN for :123

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.