<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ACS 5.3 ntp authentication support in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-5-3-ntp-authentication-support/m-p/2290922#M111309</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No it is not. I spent sometime looking for a way to do that but I found none.&lt;/P&gt;&lt;P&gt;You can only configure NTP without doing any kind of auth.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Amjad&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: blue;"&gt;Rating useful replies is more useful than saying &lt;SPAN style="color: green;"&gt; "&lt;SPAN style="text-decoration: underline;"&gt;Thank you&lt;/SPAN&gt;"&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 29 Aug 2013 05:58:29 GMT</pubDate>
    <dc:creator>Amjad Abdullah</dc:creator>
    <dc:date>2013-08-29T05:58:29Z</dc:date>
    <item>
      <title>ACS 5.3 ntp authentication support</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-3-ntp-authentication-support/m-p/2290920#M111307</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does any one know if ntp authentication is supported in ACS version 5.3?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 03:46:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-3-ntp-authentication-support/m-p/2290920#M111307</guid>
      <dc:creator>pmlam3274</dc:creator>
      <dc:date>2019-03-11T03:46:09Z</dc:date>
    </item>
    <item>
      <title>ACS 5.3 ntp authentication support</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-3-ntp-authentication-support/m-p/2290921#M111308</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am not sure about ACS 5.3 but ACS 5.4 supports authenticated NTP mode. You can see the below link for release node.&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_system/5.4/release/notes/acs_54_rn.html"&gt;http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_system/5.4/release/notes/acs_54_rn.html&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Aug 2013 02:10:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-3-ntp-authentication-support/m-p/2290921#M111308</guid>
      <dc:creator>Ravi Singh</dc:creator>
      <dc:date>2013-08-29T02:10:40Z</dc:date>
    </item>
    <item>
      <title>ACS 5.3 ntp authentication support</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-3-ntp-authentication-support/m-p/2290922#M111309</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No it is not. I spent sometime looking for a way to do that but I found none.&lt;/P&gt;&lt;P&gt;You can only configure NTP without doing any kind of auth.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Amjad&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: blue;"&gt;Rating useful replies is more useful than saying &lt;SPAN style="color: green;"&gt; "&lt;SPAN style="text-decoration: underline;"&gt;Thank you&lt;/SPAN&gt;"&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Aug 2013 05:58:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-3-ntp-authentication-support/m-p/2290922#M111309</guid>
      <dc:creator>Amjad Abdullah</dc:creator>
      <dc:date>2013-08-29T05:58:29Z</dc:date>
    </item>
    <item>
      <title>ACS 5.3 ntp authentication support</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-3-ntp-authentication-support/m-p/2290923#M111310</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ravi:&lt;/P&gt;&lt;P&gt;What is the command to configure the NTP with authentication on ACS 5.4?&lt;/P&gt;&lt;P&gt;In the CLI guide for ACS 5.4 they are not mentioning anything about configuring the authentication:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://goo.gl/e4ruV8"&gt;http://goo.gl/e4ruV8&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: blue;"&gt;Rating useful replies is more useful than saying &lt;SPAN style="color: green;"&gt; "&lt;SPAN style="text-decoration: underline;"&gt;Thank you&lt;/SPAN&gt;"&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Aug 2013 06:02:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-3-ntp-authentication-support/m-p/2290923#M111310</guid>
      <dc:creator>Amjad Abdullah</dc:creator>
      <dc:date>2013-08-29T06:02:21Z</dc:date>
    </item>
    <item>
      <title>ACS 5.3 ntp authentication support</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-3-ntp-authentication-support/m-p/2290924#M111311</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="margin: 0in 0in 0.0001pt 1.5in; text-indent: 0.5in; line-height: normal;"&gt;&lt;STRONG style="text-decoration: underline; "&gt;NTP Configuration on Cisco ACS&lt;/STRONG&gt;&lt;STRONG style="text-decoration: underline; "&gt; &lt;/STRONG&gt;&lt;/P&gt;&lt;P style="margin: 0in 0in 0.0001pt 1.5in; text-indent: 0.5in; line-height: normal;"&gt;&lt;STRONG style="text-decoration: underline; "&gt; &lt;/STRONG&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; text-align: justify; line-height: normal;"&gt;In order to synchronize the time of Cisco ACS with an NTP server, complete these steps:&lt;/P&gt;&lt;OL start="1" style="margin-top: 0in;"&gt;&lt;LI style="margin-bottom: 0.0001pt; text-align: justify; line-height: normal;"&gt;Manually&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; configure the date and time with the &lt;A href="http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_system/5.3/command/reference/cli_app_a.html#wp1889077"&gt;&lt;STRONG&gt;clock set&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;MONTH&gt; &lt;DAY&gt; &lt;MIN:SS&gt; &lt;YYYY&gt;&lt;/YYYY&gt;&lt;/MIN:SS&gt;&lt;/DAY&gt;&lt;/MONTH&gt;&lt;/STRONG&gt;&lt;/A&gt;&lt;STRONG&gt; &lt;/STRONG&gt;command.&lt;/LI&gt;&lt;LI style="margin-bottom: 0.0001pt; text-align: justify; line-height: normal;"&gt;Specify the&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; time zone with the &lt;A href="http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_system/5.3/command/reference/cli_app_a.html#wp1894584"&gt;&lt;STRONG&gt;clock&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; timezone &lt;TIMEZONE&gt;&lt;/TIMEZONE&gt;&lt;/STRONG&gt;&lt;/A&gt;&lt;STRONG&gt; &lt;/STRONG&gt;command.&lt;/LI&gt;&lt;LI style="margin-bottom: 0.0001pt; text-align: justify; line-height: normal;"&gt;Specify the&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; NTP server with the &lt;A href="http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_system/5.3/command/reference/cli_app_a.html#wp1895798"&gt;&lt;STRONG&gt;NTP server&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;IP address="" of="" ntp="" server=""&gt;&lt;/IP&gt;&lt;/STRONG&gt;&lt;/A&gt;&lt;STRONG&gt; &lt;/STRONG&gt;command.&lt;/LI&gt;&lt;/OL&gt;&lt;P style="margin: 0in 0in 0.0001pt 0.5in; text-align: justify; line-height: normal;"&gt;NTP follows a client-server hierarchy. When an NTP client is configured with an NTP server, the &lt;EM&gt;Reference Clock&lt;/EM&gt; of the NTP server is passed to the client. It takes approximately 10-20 minutes to get the accurate time from the NTP server and depends on the delay occurs in order to reach the NTP server.&lt;/P&gt;&lt;P style="margin: 0in 0in 0.0001pt 0.5in; text-align: justify; line-height: normal;"&gt;Cisco ACS uses the NTP daemon in order to synchronize its clock with the NTP server. It does not support the Simple NTP, SNTP. When the NTP daemon starts, ACS sends a packet to the NTP server that contains its original time (Local). Then NTP server replies to the packet with the insertion of its Reference Clock time. Once the NTP client receives this packet, it logs the packet with its own local time in order to validate the traveling time taken by the packet. Several such packet exchanges occur in order to calculate the exact round trip delay time and offset values and finally the local time of NTP client is synchronized with the Reference Clock of the NTP server.&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; text-align: justify; line-height: normal;"&gt;&lt;STRONG&gt;Verify&lt;/STRONG&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; text-align: justify; line-height: normal;"&gt;Use this section in order to confirm that your configuration works properly.&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; text-align: justify; line-height: normal;"&gt;In order to verify the configuration details, refer to these command output snippets.&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; text-align: justify; line-height: normal;"&gt;acs51/admin#&lt;STRONG&gt;show clock&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; text-align: justify; line-height: normal;"&gt;Wed Jun 13 11:02:00 IST 2012&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; text-align: justify; line-height: normal;"&gt;acs51/admin#&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; text-align: justify; line-height: normal;"&gt;acs51/admin(config)#&lt;STRONG&gt;ntp server 192.168.26.55&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; text-align: justify; line-height: normal;"&gt;The NTP server was modified.&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; text-align: justify; line-height: normal;"&gt;If this action resulted in a clock modification, you must restart ACS.&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; text-align: justify; line-height: normal;"&gt;acs51/admin(config)#&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; text-align: justify; line-height: normal;"&gt;acs51/admin#&lt;STRONG&gt;show ntp&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; text-align: justify; line-height: normal;"&gt;Primary NTP&amp;nbsp;&amp;nbsp; : 192.168.26.55&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; text-align: justify; line-height: normal;"&gt;&lt;STRONG&gt;synchronised to NTP server (192.168.26.55) at stratum 2&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; text-align: justify; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp; time correct to within 27 ms&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; text-align: justify; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp; polling server every 64 s&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; text-align: justify; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; remote&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; refid&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; st t when poll reach&amp;nbsp;&amp;nbsp; delay&amp;nbsp;&amp;nbsp; offset&amp;nbsp; jitter&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; text-align: justify; line-height: normal;"&gt;==============================================================================&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; text-align: justify; line-height: normal;"&gt;127.127.1.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; LOCAL(0)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10 l&amp;nbsp;&amp;nbsp; 29&amp;nbsp;&amp;nbsp; 64&amp;nbsp;&amp;nbsp; 17&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.000&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.000&amp;nbsp;&amp;nbsp; 0.001&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; text-align: justify; line-height: normal;"&gt;*192.168.26.55&amp;nbsp;&amp;nbsp; .LOCL.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 u&amp;nbsp;&amp;nbsp; 33&amp;nbsp;&amp;nbsp; 64&amp;nbsp;&amp;nbsp; 17&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.285&amp;nbsp;&amp;nbsp; -9.900&amp;nbsp;&amp;nbsp; 2.733&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; text-align: justify; line-height: normal;"&gt;Warning: Output results may conflict during periods of changing synchronization.&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; text-align: justify; line-height: normal;"&gt;&lt;STRONG&gt;Note: &lt;/STRONG&gt; &lt;EM&gt;Stratum&lt;/EM&gt; is a measure that specifies how close is the NTP server to the Primary Reference Clock. Each NTP client that is synchronized with a stratum &lt;EM&gt;n&lt;/EM&gt; server is termed as at stratum n+1 level.&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; text-align: justify; line-height: normal;"&gt;Refer to these application log messages from ACS in order to verify the NTP Synchronization details.&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; text-align: justify; line-height: normal;"&gt;acs51/admin# show logging application | in ntp&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; text-align: justify; line-height: normal;"&gt;Jun 13 13:51:59 acs51 ntpd[20259]: ntpd 4.2.0a@1.1190-r Mon Jul 28 11:03:50 EDT 2008 (1)&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; text-align: justify; line-height: normal;"&gt;Jun 13 13:51:59 acs51 ntpd[20259]: precision = 1.000 usec&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; text-align: justify; line-height: normal;"&gt;Jun 13 13:51:59 acs51 ntpd[20259]: Listening on interface wildcard, 0.0.0.0#123&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; text-align: justify; line-height: normal;"&gt;Jun 13 13:51:59 acs51 ntpd[20259]: Listening on interface wildcard, ::#123&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; text-align: justify; line-height: normal;"&gt;Jun 13 13:51:59 acs51 ntpd[20259]: Listening on interface lo, 127.0.0.1#123&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; text-align: justify; line-height: normal;"&gt;Jun 13 13:51:59 acs51 ntpd[20259]: Listening on interface eth0, 192.168.26.51#123&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; text-align: justify; line-height: normal;"&gt;Jun 13 13:51:59 acs51 ntpd[20259]: kernel time sync status 0040&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; text-align: justify; line-height: normal;"&gt;Jun 13 13:51:59 acs51 ntpd[20259]: frequency initialized 0.000 PPM from /var/lib/ntp/drift&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; text-align: justify; line-height: normal;"&gt;Jun 13 13:51:59 acs51 ntpd: &lt;STRONG&gt;ntpd startup succeeded&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; text-align: justify; line-height: normal;"&gt;Jun 13 13:55:15 acs51 ntpd[20259]: &lt;STRONG&gt;synchronized to 192.168.26.55, stratum 2&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; text-align: justify; line-height: normal;"&gt;&lt;EM&gt; &lt;/EM&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; text-align: justify; line-height: normal;"&gt;&lt;EM&gt;!--- Output suppressed–&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; text-align: justify; line-height: normal;"&gt;The &lt;A href="https://www.cisco.com/cgi-bin/Support/OutputInterpreter/home.pl"&gt;Output Interpreter Tool&lt;/A&gt; (&lt;A href="http://tools.cisco.com/RPF/register/register.do"&gt;registered&lt;/A&gt; customers only) (OIT) supports certain &lt;STRONG&gt;show&lt;/STRONG&gt; commands. Use the OIT to view an analysis of &lt;STRONG&gt;show&lt;/STRONG&gt; command output.&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; text-align: justify; line-height: normal;"&gt;&lt;STRONG&gt;Troubleshoot&lt;/STRONG&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; text-align: justify; line-height: normal;"&gt;This section provides information you can use to troubleshoot your configuration. &lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; text-align: justify; line-height: normal;"&gt;&lt;STRONG&gt;Problem: Clock drifts too much and NTP fails when ACS is installed on a VMWare machine&lt;/STRONG&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; text-align: justify; line-height: normal;"&gt;Cisco ACS is configured to use the NTP server as the clock source but it continually changes to the internal time source. When this happens, it does notallow users to authenticate from Active Directory as Kerberos only supports 300 seconds of time difference.&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; text-align: justify; line-height: normal;"&gt;&lt;STRONG&gt;Solution&lt;/STRONG&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; text-align: justify; line-height: normal;"&gt;When the ESXi host has high CPU utilization, then it does not serve VMs as frequently as normal. This affects the clocks inside VMs and actually cause clock drift from a Windows Domain Controller that exceeds five minutes. It causes the Kerberos to fail. This would impact a Windows VM without NTP or host clock sync as well. As the virtual clock presented to Cisco ACS is not stable enough for NTP to keep up with the drift, it eventually reverts to using itself as a time source.&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; text-align: justify; line-height: normal;"&gt;&lt;STRONG&gt;Note: &lt;/STRONG&gt;The NTP daemon adjusts the clock in several exchanges and continues until the client obtain the accurate time. However, when the delay between NTP Server and the NTP Client become too big, then the NTP daemon gets terminated and you need to adjust the time manually and re-start the NTP daemon.&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; text-align: justify; line-height: normal;"&gt;This problem is set to be resolved when you integrate the VMWare tools support into Cisco ACS, which is available with Cisco ACS release 5.4 that is yet to be released. Refer to Cisco bug ID &lt;A href="http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;amp;bugId=CSCtg50048"&gt;CSCtg50048&lt;/A&gt; (&lt;A href="http://tools.cisco.com/RPF/register/register.do"&gt;registered&lt;/A&gt; customers only) for more information. As a temporary workaround, you could try these steps:&lt;/P&gt;&lt;UL style="margin-top: 0in;"&gt;&lt;LI style="margin-bottom: 0.0001pt; text-align: justify; line-height: normal;"&gt;Stop ACS&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; services with the &lt;STRONG&gt;ACS stop&lt;/STRONG&gt; command .&lt;/LI&gt;&lt;LI style="margin-bottom: 0.0001pt; text-align: justify; line-height: normal;"&gt;Remove all&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; NTP configuration and save the configuration with a &lt;STRONG&gt;write mem&lt;/STRONG&gt; command.&lt;/LI&gt;&lt;LI style="margin-bottom: 0.0001pt; text-align: justify; line-height: normal;"&gt;Reboot Cisco&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ACS.&lt;/LI&gt;&lt;LI style="margin-bottom: 0.0001pt; text-align: justify; line-height: normal;"&gt;Make sure&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; all services are running with the &lt;STRONG&gt;show application status acs&lt;/STRONG&gt; command.&lt;/LI&gt;&lt;LI style="margin-bottom: 0.0001pt; text-align: justify; line-height: normal;"&gt;Set the&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; clock to be as close to real time as possible, to the second before of the&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; offset requirement on NTP.&lt;/LI&gt;&lt;LI style="margin-bottom: 0.0001pt; text-align: justify; line-height: normal;"&gt;Make sure&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Timezone is correct one.&lt;/LI&gt;&lt;LI style="margin-bottom: 0.0001pt; text-align: justify; line-height: normal;"&gt;Re-add NTP&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; configuration and save it.&lt;/LI&gt;&lt;LI style="margin-bottom: 0.0001pt; text-align: justify; line-height: normal;"&gt;Perform the &lt;STRONG&gt;show&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ntp&lt;/STRONG&gt; command in order to verify if the output is the same.&lt;/LI&gt;&lt;/UL&gt;&lt;P style="margin-bottom: 0.0001pt; text-align: justify; line-height: normal;"&gt;&lt;STRONG&gt;Note: &lt;/STRONG&gt;If these steps do not resolve the issue, you are advised to contact &lt;A href="http://www.cisco.com/en/US/support/tsd_cisco_worldwide_contacts.html"&gt;Cisco TAC&lt;/A&gt;.&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; text-align: justify; line-height: normal;"&gt;&lt;STRONG&gt;NTP Synchronization lost after the interface IP address of ACS is changed&lt;/STRONG&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; text-align: justify; line-height: normal;"&gt;If you change the IP address of ACS NIC, this makes the NTP go out of sync.&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; text-align: justify; line-height: normal;"&gt;&lt;STRONG&gt;Solution&lt;/STRONG&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; text-align: justify; line-height: normal;"&gt;This behavior is observed and logged in Cisco bug ID &lt;A href="http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;amp;bugId=CSCtk76151"&gt;CSCtk76151&lt;/A&gt; (&lt;A href="http://tools.cisco.com/RPF/register/register.do"&gt;registered&lt;/A&gt; customers only) . When the ACS IP address is modified, it restarts the ACS application but not the NTP daemon. It is fixed in ACS version 5.3.0.23. In order to resolve this issue in prior versions, complete these steps:&lt;/P&gt;&lt;OL start="1" style="margin-top: 0in;"&gt;&lt;LI style="margin-bottom: 0.0001pt; text-align: justify; line-height: normal;"&gt;Issue the &lt;STRONG&gt;no&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ntp server&lt;/STRONG&gt; command in order to stop the NTP process.&lt;/LI&gt;&lt;LI style="margin-bottom: 0.0001pt; text-align: justify; line-height: normal;"&gt;Re-issue the&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;STRONG&gt;ntp server&lt;/STRONG&gt; command in order to restart the NTP process.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; text-align: justify;"&gt;&lt;STRONG&gt;Note:&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; text-align: justify;"&gt;For more information please visit:&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; text-align: justify;"&gt;&lt;A href="http://www.cisco.com/en/US/products/ps9911/products_configuration_example09186a0080bc612b.shtml"&gt;&lt;STRONG&gt;http://www.cisco.com/en/US/products/ps9911/products_configuration_example09186a0080bc612b.shtml&lt;/STRONG&gt;&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Aug 2013 10:34:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-3-ntp-authentication-support/m-p/2290924#M111311</guid>
      <dc:creator>aqjaved</dc:creator>
      <dc:date>2013-08-29T10:34:26Z</dc:date>
    </item>
    <item>
      <title>ACS 5.3 ntp authentication support</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-3-ntp-authentication-support/m-p/2290925#M111312</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok Aqeel and how can all that long text answer the answer? it does not really do.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: blue;"&gt;Rating useful replies is more useful than saying &lt;SPAN style="color: green;"&gt; "&lt;SPAN style="text-decoration: underline;"&gt;Thank you&lt;/SPAN&gt;"&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Aug 2013 10:39:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-3-ntp-authentication-support/m-p/2290925#M111312</guid>
      <dc:creator>Amjad Abdullah</dc:creator>
      <dc:date>2013-08-29T10:39:29Z</dc:date>
    </item>
    <item>
      <title>ACS 5.3 ntp authentication support</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-3-ntp-authentication-support/m-p/2290926#M111313</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No, it's not supported in ACS 5.3. It was added in ACS 5.4&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;System Operations Enhancements&lt;/P&gt;&lt;P&gt;Network Time Protocol (NTP)&lt;/P&gt;&lt;P&gt;ACS 5.4 supports authenticated NTP mode and the existing nonauthenticated NTP mode. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;~BR &lt;BR /&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt;**Do rate helpful posts**&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Aug 2013 11:18:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-3-ntp-authentication-support/m-p/2290926#M111313</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-08-29T11:18:03Z</dc:date>
    </item>
  </channel>
</rss>

