cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1804
Views
15
Helpful
2
Replies

ISE Time Source Issue

PutmanoAIT
Level 1
Level 1

I have implement Cisco ISE as TACACS server, I configured NTP point to my AD server for time synchronization. Unfortunately ISE always select LOCAL(*127.127.1.0) as a time source. Does we have any configuration to force the ISE to sync time with AD? Thank for your kindly support.

ISE-NTP.png

1 Accepted Solution

Accepted Solutions

Marvin Rhoads
Hall of Fame
Hall of Fame

The refid ".INIT." and st (stratum) 16 indicates that for whatever reason the ISE server is not getting any NTP synchronization from the AD servers. In such a situation, it will fall back to localhost as the time source.

 

I'd do a packet capture at each end and see if

 

a. the ntp requests arrive on the AD servers and

b. if any responses arrive at the ISE server.

View solution in original post

2 Replies 2

Marvin Rhoads
Hall of Fame
Hall of Fame

The refid ".INIT." and st (stratum) 16 indicates that for whatever reason the ISE server is not getting any NTP synchronization from the AD servers. In such a situation, it will fall back to localhost as the time source.

 

I'd do a packet capture at each end and see if

 

a. the ntp requests arrive on the AD servers and

b. if any responses arrive at the ISE server.

ajc
Level 7
Level 7

In case you are using Windows as NTP Server. Please check the following.

 

https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/119371-technote-ise-00.html