07-18-2023 09:53 AM
Appliance Model : Cisco ASA 5508-X
Firepower Status : Not used
ASA Version : 9.16.4
I am having trouble using NTP to synchronize time on port 123. I have set up a custom NTP server that listens to port 122, and I have verified that the synchronization works fine using the nettime client on a Windows machine. However, when I try to sync time on port 123, I encounter issues.
I checked the debug monitor on ASDM and noticed that the request is being made to the specific NTP server, but the reply takes approximately two minutes to show up on the monitor.
To clarify, I am trying to sync time using NTP, but I am only experiencing issues with port 123. I have set up a custom NTP server that works fine on port 122, but the problem arises when I use port 123. I have checked the debug monitor on the ASDM, and I can see that the request is being sent to the NTP server, but the response takes a long time to show up.
To fix this issue, I have checked the network and firewall settings to ensure that they are not causing any delays or blocking NTP traffic on port 123. I have also verified that the NTP server is correctly configured and responding to requests in a timely manner. Additionally, I have tried using a different NTP server and client to see if the issue persists.time between request and reply to show up
07-19-2023 05:43 AM
yes
07-19-2023 06:14 AM
Change source you use to connect asa to server in DMZ' make it INside or mgmt interface.
07-19-2023 06:26 AM
do you mean switch to local ntp located on the inside interface ?
but how this is gone fix the issue ?
07-18-2023 02:08 PM
packet-tracer input DMZ udp (any ip of dmz sunbet except dmz interface IP) 1234 (ntp server) 123
Share output of above
07-18-2023 02:32 PM
is this what you need ?
07-18-2023 04:47 PM - edited 07-19-2023 04:35 AM
any one knows how to fix the issue ?
07-25-2023 05:15 AM
Thank you all for your help. It turns out that the issue was from the ISP itself.
07-25-2023 05:24 AM
Can update us what exactly issue?
Thanks
MHM
07-31-2023 09:16 AM
The ISP's firewall is misconfigured and is still blocking the port, despite attempts to resolve the issue.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide