After doing upgrade from 220.127.116.11 to 18.104.22.168 for 2100 series FTP box failover pair new FXOS alarm showed up:
Last Transition Time: 2018-12-06T17:20:52.586
Description: Ntp Configuration failed, please check the error message in Ntp host
Affected Object: sys/svc-ext/datetime-svc
Name: Comm Date Time Comm Ntp Configuration Failed
Cause: Ntp Config Failed
Creation Time: 2018-12-06T16:43:12.893
Original Severity: Major
Previous Severity: Cleared
Highest Severity: Major
At the same time NTP configuration is indeed failing:
FTD# show ntp-overall-status
NTP Overall Time-Sync Status: Ntp Config Failed
NTP config is pushed via FMC Platform settings configuration and NTP time is taken from FMC (which synced with NTP further). Tried using external NTP server for Platform settings - same result.
Given this showed up for both HA boxes and it wasn't there - I guess it's a new "feature" in 22.214.171.124. Have anyone seen this?
Given it has been 12+ hours since the update - time should have passed enough.
FMC is synced with NTP. I tried switching sync from FMC to NTP server via Platform setting configuration for FTD - made no difference, error re-appeared.
Is your FMC and FTD in same IP range..??? or if its in different range is there any firewall between that subnet. Check if UDP port 123 is blocking in between the path.
I think you may be hitting the below bug
In Platform Settings configure set my clock for "Via NTP from" and set the IP Address of 127.0.0.2 which will force the NTP service to sync to the FMC over SFTunnel
Thanks, tried using 127.0.0.2, but still failed. This bug could be related to classic Firepower, as in case of FTD Platform Settings are for FXOS and not sure if it can use SFtunnel to sync time from FXOS.
Anyway, in the end added different NTP server instead of FMC and it synced successfully, It could be that NTP I used yesterday wasn't reachable or still some shady behavior. So right now this is good enough - time is in sync, using FMC is not mandatory in my case.
I'm having this same issue as well. Although for me,changing the NTP server to something other than the FMC did not yield any results.