Problem with NTP Server PDC

Paco Gaspar 91 Reputation points
2020-08-12T11:00:45.997+00:00

I am the administrator of an Active Directory that consists of 4 domain controllers. 3 of them are Windows 2012 R2, and one Windows 2008 R2. Our Palo Alto firewall is ntp time syncronized against the PDC domain controller, one of the Windows 2012 R2. Yesterday I removed the Windows 2008 R2 DC, and set it one DC under Windows 2019. I gave the same name and IP than the removed server, but firts, I assured that no rests of the older domain controller was in the domain. Everything works well, except the NTP Palo alto against Windows 2012 Domain controller. PDC is configured as authoritative NTP server, synchronized correctly against external NTP servers, and the rest of Domain Controllers, Member servers and client domain computers are configured with default settings, I.E NT5DS, and everything works perfect. But Palo Alto throws a 'rejected' error when use Windows PDC time server as NTPServer. The logs says 'Authentication error'. The same error occurs if we configure any of the domain controllers as NTP provider in Palo Alto configuration. The only way to syncronize Palo Alto is using external servers. Is there any way to solve this? Why yesterday worked well and today it doesn't? What can have changed? Thanks

Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
6,671 questions
0 comments No comments
{count} votes

Accepted answer
  1. Thameur-BOURBITA 33,086 Reputation points
    2020-08-13T08:54:55.9+00:00

    Hi,

    You should be sure that you don't have network flow blocked. you can download the free tools provided by Microsoft to do check if the NTP port is well opened:

    https://www.microsoft.com/en-us/download/details.aspx?id=24009

    0 comments No comments

3 additional answers

Sort by: Most helpful
  1. Anonymous
    2020-08-12T13:22:53.287+00:00

    Not clear but it sounds like the palo alto firewall no longer can get time from PDCe? If so I'd probably ask the firewall hardware vendor for help.

    --please don't forget to Accept as answer if the reply is helpful--

    0 comments No comments

  2. Hannah Xiong 6,276 Reputation points
    2020-08-13T06:06:43.287+00:00

    Hello,

    Thank you so much for posting here.

    According to our description, everything works perfect except the Palo Alto firewall throws error. Agree with Dave, it is suggested that we could contact the firewall vendor for assistance.

    Thanks for your time and support.

    Best regards,
    Hannah Xiong

    0 comments No comments

  3. Paco Gaspar 91 Reputation points
    2020-08-14T11:13:20.707+00:00

    Thanks for your help. A restart of NTP Domain controller server made it work again.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.