cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1963
Views
0
Helpful
6
Replies

Cannot check system time on AD server

David Da Costa
Level 1
Level 1

I recently had to rebuild a wsa S170 installation, and when I created the real and tried getting the device to join the domain I got this error Cannot check system time on AD server , TAC support advised I need to upgrade to ver 8.54 and to enable SMBv1 on 2012R2 AD servers I have done all this yet the problem still persists, I am at my wits end now and would appreciate any help. The WSA hangs off a DMZ on a Cisco ASA5512 and I have allowed implicit bidirectional traffic between the WSA and the AD servers.

6 Replies 6

Philip D'Ath
VIP Alumni
VIP Alumni

This is NTP time synchronisation, right?  If a server is an AD server you don't need to do anything extra on an AD server to enable NTP queries against it.

How about trying to sync against the public NTP pool?  pool.ntp.org.  You need to allow outbound udp/123 from the WSA.

It is reading the time correctly from the NTP server it is when trying to get the new realm to join the AD , it wants to check the AD servers for Synchronization or if there is a time skew, but it is failing to communicate, I was told by the escalation engineer that it was due to SMB v1 not been enabled on AD 2012 R2.

The proxy is configured on a DMZ of a ASA 5512 while the AD controllers are on the inside network, even though I have an implicit rule between the WSA and AD server I am going to take another device and restore the config onto it and put it on the inside network and see if this will make a difference. 

Is there a rule to allow it to talk to all AD controllers?

I think I would go with your plan, move it to the inside network, do the AD join, and then move it back.

WSA is working as a security gateway, normally it will only handle outbound traffic. Therefore usually we don't suggest put WSA into DMZ as it is not necessary for WSA to receive any request inbound from Internet.  

Some Feedback , I have configured another device and imported the configuration onto it, and changed the IP , the WSA is now on the same vlan as the AD servers and still getting the same issue wher the WSA cant check the system time on the AD servers to join the domain I am at a loss now..

I am getting the same problem. Where you able to solve the problem?