VMware Cloud Community
pooriya_a
Contributor
Contributor

ESXi Deos not sync with Windows DC

Hi,

I have got a vCenter environment compromising of 5 ESXi machines. One of the machines does not belong to an HA/DRS cluster, but the other 4 are part of the cluster. I configured everything as per VMware  VMware KB: Synchronizing ESXi/ESX time with a Microsoft Domain Controller

article. All my clients automatically sync to a time server, but not the ones that I specified. All of them have the same time, but it is different than the time on my DCs and the rest of the network. Even when I turn off the NTP server on my ESXi host and also turn off NTP client on my ESXi hosts and set the time manually, the time returns back within 30 seconds to the time before. This does not happen on the ESXi host that is not part of the cluster. I mean when I set the time manually on the ESXi host that is not part of my cluster, the time does not change. On all the other hosts, the time returns back to the same time with NTP server enables or not. Please helpppppppppppppppp.

0 Kudos
10 Replies
abhilashhb
VMware Employee
VMware Employee

Hi pooriya_a,

Have you made your AD sync time from internet? Because if AD id not staying updated on time it will not be able to provide right time to its clients.

Abhilash B
LinkedIn : https://www.linkedin.com/in/abhilashhb/

0 Kudos
pooriya_a
Contributor
Contributor

Hi Abhilash,

Yes. AD is providing the right time to whole network. It is just my ESXi hosts that are not synchronizing time with AD. Furthermore, the hosts sync with a time source because they all have the same time and when I change the time, it returns to the same previous time.

0 Kudos
SatyS
Hot Shot
Hot Shot

Hi

I think the time sync is creating a problem here.

For syncing the ESX host with AD please go through

VMware KB: Synchronizing ESXi/ESX time with a Microsoft Domain Controller

Hope this helps

SatyS

----------------------------

If you find this helpful,mark as correct or helpful answer

If you find this useful,please mark the answer as correct/helpful

Regards,
SatyS
http://myvirtuallearning.wordpress.com/

0 Kudos
pooriya_a
Contributor
Contributor

Hi Satys,

Perhaps you did not read my thread completely. I exactly did as the link you provided. I even provided the link I used. I does not work. My machines are synchronizing with a source as all of the ESXi host have the same time, but it is not my time server.

0 Kudos
MarVista
Enthusiast
Enthusiast

Had you join these esxi machines to the domain? if not, try to join them. it will sync to domain controller automatically.

if you find this helpful, mark it as correct.

Yours,
Mar Vista

0 Kudos
a_p_
Leadership
Leadership

Hard to say what's causing this. Maybe tracing the NTP communication can help (see http://kb.vmware.com/kb/1005092)

André

0 Kudos
pooriya_a
Contributor
Contributor

Hi,

Yes the hosts are joined to the domain. When I trace the communication to the NTP server, the hosts go to the right server.

0 Kudos
OzerS
Enthusiast
Enthusiast

If host is added to AD, doesnt matter if you configure the NTP or not, it will always sync the time with AD. So it is 30 seconds off, well i am not sure why.

But KB mentioned earlier has this

/etc/likewise/lsassd.conf

change this to no, default is yes (just un comment it)

sync-system-time = no

Have you done this? If not try and set your NTP client again and restart the NTP.

0 Kudos
abhilashhb
VMware Employee
VMware Employee

Try pointing one of the hosts to AD and then point all the other hosts to that one host that gets time from AD. Let me know if it works.

Abhilash B
LinkedIn : https://www.linkedin.com/in/abhilashhb/

0 Kudos
pooriya_a
Contributor
Contributor

I have done all mentioned by you. I did thing for /etc/likewise/lsassd.conf. The issue is this. My hosts are synchronizing with a source I am sure. Because all of them even when I turn the NTP service off and adjust the time manually, it is reverted to the previous time. This happens to all my hosts on a HA/DRS enabled cluster. When I watch the ntp traffic by watch ntpq -p server-ip-address, it shows the host is synchronizing with the DC, but it is not since the time difference is very big and the host time return to a specific time.

0 Kudos