cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2613
Views
11
Helpful
38
Replies

NTP Request Reply takes two minutes

Appliance Model : Cisco ASA 5508-X
Firepower Status : Not used 
ASA Version : 9.16.4

I am having trouble using NTP to synchronize time on port 123. I have set up a custom NTP server that listens to port 122, and I have verified that the synchronization works fine using the nettime client on a Windows machine. However, when I try to sync time on port 123, I encounter issues.

I checked the debug monitor on ASDM and noticed that the request is being made to the specific NTP server, but the reply takes approximately two minutes to show up on the monitor.

To clarify, I am trying to sync time using NTP, but I am only experiencing issues with port 123. I have set up a custom NTP server that works fine on port 122, but the problem arises when I use port 123. I have checked the debug monitor on the ASDM, and I can see that the request is being sent to the NTP server, but the response takes a long time to show up.

To fix this issue, I have checked the network and firewall settings to ensure that they are not causing any delays or blocking NTP traffic on port 123. I have also verified that the NTP server is correctly configured and responding to requests in a timely manner. Additionally, I have tried using a different NTP server and client to see if the issue persists.

time between request and reply to show uptime between request and reply to show up

38 Replies 38

yes 

Change source you use to connect asa to server in DMZ' make it INside or mgmt interface.

do you mean switch to local ntp located on the inside interface ? 
but how this is gone fix the issue ? 

packet-tracer input DMZ udp (any ip of dmz sunbet except dmz interface IP) 1234 (ntp server) 123 

 

Share output of above 

is this what you need ? 1.PNG2.PNG

any one knows how to fix the issue ?

 

Thank you all for your help. It turns out that the issue was from the ISP itself.

Can update us what exactly issue?

Thanks 

MHM

The ISP's firewall is misconfigured and is still blocking the port, despite attempts to resolve the issue.

Review Cisco Networking for a $25 gift card