NTP - Remote Domain Computers
if have gpo have windows clients sync time external sources instead of domain hierarchy (dcs, pdc emulator role server, etc.), clients still (by virtual of being joined domain) want communicate domain controller time source? testing gpo remote users have them sync time externally, noticed when in vpn still trying talk dcs via udp 123. possibly related crosssitesyncflags value being 2?
thanks,
jefrodhusker
p.s.
forest functional level 2003
domain functional level 2008
hi,
with manually-specified synchronization, can designate single peer or list of peers computer obtains time. if computer not member of domain, computer must manually configured synchronize specified time source. default, computer member of domain configured synchronize domain hierarchy. manually-specified synchronization useful forest root of domain or computers not joined domain. manually specifying external ntp server synchronize authoritative computer domain provides reliable time. however, configuring authoritative computer domain synchronize hardware clock better solution provide high accuracy , improved security domain.
note manually specified time sources not authenticated unless specific time provider written them, , therefore vulnerable attacks. also, if computer synchronizes manually-specified source instead of authenticating domain controller, 2 computers might out of synchronization, , kerberos authentication therefore fail. other actions require network authentication, such printing or file sharing, fail. if forest root configured synchronize external source, other computers within forest remain synchronized each other, making replay attacks difficult.
microsoft recommends configure authoritative time server obtain time hardware source. when configure authoritative time server sync internet time source, there no authentication. microsoft recommends lower time correction settings servers , stand-alone clients. these recommendations provide more accuracy , greater security domain.
more information:
how configure authoritative time server in windows xp
http://support.microsoft.com/kb/314054
the relate third party article:
how configure windows server use external time source
http://blog.techgalaxy.net/archives/4116
hope helps.
Windows Server > Windows Server General Forum
Comments
Post a Comment