12-06-2018 12:33 PM - edited 02-21-2020 08:32 AM
After doing upgrade from 6.2.3.5 to 6.2.3.7 for 2100 series FTP box failover pair new FXOS alarm showed up:
Severity: Major
Code: F1329
Last Transition Time: 2018-12-06T17:20:52.586
ID: 555499
Status: None
Description: Ntp Configuration failed, please check the error message in Ntp host
Affected Object: sys/svc-ext/datetime-svc
Name: Comm Date Time Comm Ntp Configuration Failed
Cause: Ntp Config Failed
Type: Configuration
Acknowledged: No
Occurrences: 3
Creation Time: 2018-12-06T16:43:12.893
Original Severity: Major
Previous Severity: Cleared
Highest Severity: Major
At the same time NTP configuration is indeed failing:
FTD# show ntp-overall-status
NTP Overall Time-Sync Status: Ntp Config Failed
NTP config is pushed via FMC Platform settings configuration and NTP time is taken from FMC (which synced with NTP further). Tried using external NTP server for Platform settings - same result.
Given this showed up for both HA boxes and it wasn't there - I guess it's a new "feature" in 6.2.3.7. Have anyone seen this?
12-06-2018 11:28 PM
12-07-2018 12:02 AM
Given it has been 12+ hours since the update - time should have passed enough.
FMC is synced with NTP. I tried switching sync from FMC to NTP server via Platform setting configuration for FTD - made no difference, error re-appeared.
12-07-2018 12:09 AM - edited 12-07-2018 12:10 AM
Is your FMC and FTD in same IP range..??? or if its in different range is there any firewall between that subnet. Check if UDP port 123 is blocking in between the path.
HTH
Abheesh
12-07-2018 12:11 AM
Yes.
As mentioned - it was working fine all the way till 6.2.3.5 -> 6.2.3.7 upgrade.
12-07-2018 12:17 AM
I think you may be hitting the below bug
Workaround
In Platform Settings configure set my clock for "Via NTP from" and set the IP Address of 127.0.0.2 which will force the NTP service to sync to the FMC over SFTunnel
HTH
Abheesh
12-07-2018 12:44 AM
Thanks, tried using 127.0.0.2, but still failed. This bug could be related to classic Firepower, as in case of FTD Platform Settings are for FXOS and not sure if it can use SFtunnel to sync time from FXOS.
Anyway, in the end added different NTP server instead of FMC and it synced successfully, It could be that NTP I used yesterday wasn't reachable or still some shady behavior. So right now this is good enough - time is in sync, using FMC is not mandatory in my case.
12-07-2018 12:47 AM
Is your FMC a VM or physical appliance. FMC on VM is not recommended as an NTP server.
12-07-2018 12:50 AM
It is VM indeed. Good to know, missed that recommendation indeed, thanks for noting!
01-11-2019 06:38 AM
I'm having this same issue as well. Although for me,changing the NTP server to something other than the FMC did not yield any results.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide