NTP - Remote Domain Computers


if have gpo have windows clients sync time external sources instead of domain hierarchy (dcs, pdc emulator role server, etc.), clients still (by virtual of being joined domain) want communicate domain controller time source? testing gpo remote users have them sync time externally, noticed when in vpn still trying talk dcs via udp 123. possibly related crosssitesyncflags value being 2?

thanks,

jefrodhusker

p.s.

forest functional level 2003

domain functional level 2008

hi,

with manually-specified synchronization, can designate single peer or list of peers computer obtains time. if computer not member of domain, computer must manually configured synchronize specified time source. default, computer member of domain configured synchronize domain hierarchy. manually-specified synchronization useful forest root of domain or computers not joined domain. manually specifying external ntp server synchronize authoritative computer domain provides reliable time. however, configuring authoritative computer domain synchronize hardware clock better solution provide high accuracy , improved security domain.

note manually specified time sources not authenticated unless specific time provider written them, , therefore vulnerable attacks. also, if computer synchronizes manually-specified source instead of authenticating domain controller, 2 computers might out of synchronization, , kerberos authentication therefore fail. other actions require network authentication, such printing or file sharing, fail. if forest root configured synchronize external source, other computers within forest remain synchronized each other, making replay attacks difficult.

microsoft recommends configure authoritative time server obtain time hardware source. when configure authoritative time server sync internet time source, there no authentication. microsoft recommends lower time correction settings servers , stand-alone clients. these recommendations provide more accuracy , greater security domain.

more information:

how configure authoritative time server in windows xp

http://support.microsoft.com/kb/314054

the relate third party article:

how configure windows server use external time source

http://blog.techgalaxy.net/archives/4116

hope helps.


we trying better understand customer views on social support experience, participation in interview project appreciated if have time.
helping make community forums great place.



Windows Server  >  Windows Server General Forum



Comments

Popular posts from this blog

server manager error: ADAM.events.xml could not be enumerated.

Cannot access Anywhere Access using domain name?

WMI Failure: Unable to update Local Resource Group