cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1584
Views
10
Helpful
17
Replies

FTDv managed by FMC ntp issue

mhdganji110
Level 1
Level 1

Hi,

I'm using FTDv 7 managed by FMC v7. Logging issues are there and there is an error about FTD not synced.

So, first step seems to solve the ntp issues.

 

FMC GUI is there for ntp which I set and it seems to be ok, but I cannot find where is the ntp settings for FTD device (I go to FMC, devices, choose the FTD device, ... nothing there)

Also when I SSH to FTD and run ntpd -u ntpserver, it says operation not permitted. I set the time exactly as the same with FMC (with date -s command and copy the same output of date command on SSH session of FMC) but the problem is still there)

 

Any idea?

 

Regards

17 Replies 17

A firewall, just like most PCs, has a system clock with an internal battery-power source. It keeps track of time even when the device is powered off. In the absence of an external time source like ntp, that clock can still provide (usually) accurate time.

I recently saw similar behaviour on a customer deployment and had to change the NTP for the FTD devices to be something different than the FMC. Nothing wrong with pointing the FTD to your domain controllers for example if they have the NTP services enabled, or, pointing even to an external trusted NTP server as long as both the FTDs and the FMC do not have any time skew.

mhdganji110
Level 1
Level 1

I managed to solve the problem in this way

 

Went to FMC and my created FTD policy and chose a timezone (it was blank). Applied it to my FTD and all is ok now.

Review Cisco Networking for a $25 gift card