12-05-2021 05:51 PM
Hi Experts!
I have bumped into a somewhat bizarre state of our ASA firewall,
NTP unsynced from show command but show clock says otherwise.
could this be a bug issue?
hope that someone can shed light on this.
Nox S.
12-06-2021 10:23 AM
Can you post :
show ntp associations
show ntp associations detail
show clock
show version
12-06-2021 07:07 PM
FW# show ver
Cisco Adaptive Security Appliance Software Version 9.8(2)20
FW# show clock detail
04:44:12.867 GMT Tue Dec 6 2021
Time source is NTP
Summer time starts 02:00:00 GMT Sun Mar 13 2025
Summer time ends 02:00:00 GMT Sun Nov 6 2025
FW# show ntp associations
address ref clock st when poll reach delay offset disp
~1.1.1.1 0.0.0.0 15 - 64 0 0.0 0.00 15000.
~2.2.2.2 0.0.0.0 15 - 64 0 0.0 0.00 15000.
~3.3.3.3 0.0.0.0 15 - 64 0 0.0 0.00 15000.
* master (synced), # master (unsynced), + selected, - candidate, ~ configured
12-07-2021 02:05 AM
Looks you have configured clock, the NTP servers (they are valid ?) - i do not see any association
From where you got this IP address 1.1.1.1 / 2.2.2.2 / 3.3.3.3 (is this replaced here due to post ? or configured as same)
check reference, required valid NTP Server to associate.
https://www.networkstraining.com/how-to-configure-clock-and-ntp-on-cisco-asa-5500/
12-07-2021 05:16 PM
Yes, I have changed IPs for confidentiality, basically, there are 3 NTP servers. As you say it is the clock setting that is fired up not NTP?
but why show clock shown as:
FW# show clock detail
04:44:12.867 GMT Tue Dec 6 2021
Time source is NTP
Summer time starts 02:00:00 GMT Sun Mar 13 2025
Summer time ends 02:00:00 GMT Sun Nov 6 2025
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide