03-28-2018 12:34 AM - edited 02-21-2020 10:52 AM
I have implement Cisco ISE as TACACS server, I configured NTP point to my AD server for time synchronization. Unfortunately ISE always select LOCAL(*127.127.1.0) as a time source. Does we have any configuration to force the ISE to sync time with AD? Thank for your kindly support.
Solved! Go to Solution.
03-28-2018 05:18 AM
The refid ".INIT." and st (stratum) 16 indicates that for whatever reason the ISE server is not getting any NTP synchronization from the AD servers. In such a situation, it will fall back to localhost as the time source.
I'd do a packet capture at each end and see if
a. the ntp requests arrive on the AD servers and
b. if any responses arrive at the ISE server.
03-28-2018 05:18 AM
The refid ".INIT." and st (stratum) 16 indicates that for whatever reason the ISE server is not getting any NTP synchronization from the AD servers. In such a situation, it will fall back to localhost as the time source.
I'd do a packet capture at each end and see if
a. the ntp requests arrive on the AD servers and
b. if any responses arrive at the ISE server.
03-28-2018 12:55 PM
In case you are using Windows as NTP Server. Please check the following.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide