<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NTP clock sync not working on cloudguard R80.10 HA in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/NTP-clock-sync-not-working-on-cloudguard-R80-10-HA/m-p/32087#M3152</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Maybe add a cronjob that periodically calls ntpdate?&lt;/P&gt;&lt;P&gt;TAC would have to get involved to troubleshoot ntp not syncing properly.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 14 Feb 2019 21:23:34 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2019-02-14T21:23:34Z</dc:date>
    <item>
      <title>NTP clock sync not working on cloudguard R80.10 HA</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/NTP-clock-sync-not-working-on-cloudguard-R80-10-HA/m-p/32082#M3147</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All...&lt;/P&gt;&lt;P&gt;I have successfully deployed Checkpoint cloudguard HA cluster running R80.10 using &lt;A class="link-titled" href="https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_IaaS_HighAvailability_for_Azure/html_frameset.htm" title="https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_IaaS_HighAvailability_for_Azure/html_frameset.htm"&gt;Check Point CloudGuard IaaS High Availability for Microsoft Azure R80.10 and above Deployment Guide&lt;/A&gt; ..&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: comic sans ms, sans-serif; color: #800080;"&gt;Internet ---- eth0 (172.19.16.20(FW2 21)/28) &lt;SPAN style="font-size: 22px;"&gt;&lt;STRONG&gt;FW1&lt;/STRONG&gt;&lt;/SPAN&gt; eth1 (172.19.16.37(FW2 38)/28) -------Inside (towards on-premise NTP server)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;As per the template the FW is deployed wth a backend loadbalancer with an IP of &lt;STRONG&gt;172.19.16.36&lt;/STRONG&gt;. No frontend-lb has been deployed&lt;/P&gt;&lt;P&gt;My NTP server sits on-premise network with IP address of 10.64.17.10&lt;/P&gt;&lt;P&gt;I have added the route for NTP server on the firewall pointing towards 172.19.16.33 (first IP on the inside eth1 subnet)&lt;/P&gt;&lt;P&gt;However I see a strange behaviour where the initial NTP packet is sourced from the backend-lb IP address (172.19.16.36) towards NTP server which then replies back to the FW1 IP address (.37) followed by an ICMP unreachable sourced from backend-lb to the NTP server&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="78342" class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/78342_pastedImage_2.png" /&gt;&lt;/P&gt;&lt;P&gt;As soon as I remove the route via eth1 interface (forcing traffic to go out via default route on eth0 interface) I can see bi-directional comms between the FW eth0 interface and the NTP server&lt;/P&gt;&lt;PRE&gt;&lt;SPAN style="font-family: courier new, courier, monospace; color: #0000ff;"&gt;15:00:13.292177 IP 172.19.16.20.entextmed &amp;gt; 10.64.17.10.ntp: NTPv3, Client, length 48&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new, courier, monospace; color: #0000ff;"&gt;15:00:13.317949 IP 10.64.17.10.ntp &amp;gt; 172.19.16.20.entextmed: NTPv3, Server, length 48&lt;/SPAN&gt;&lt;/PRE&gt;&lt;P&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif; color: #000000;"&gt;However even with this bi-directional comms, the output of &lt;EM&gt;show ntp current&lt;/EM&gt; displays&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff; font-family: courier new, courier, monospace;"&gt;No server has yet to be synchronized&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I have attached wireshark captures from both eth0 and eth1 interface&lt;/P&gt;&lt;P&gt;The end goal here is to get NTP (and all other comms to on-premise network) working via the inside interface&lt;/P&gt;&lt;P&gt;Any ideas ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Feb 2019 15:25:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/NTP-clock-sync-not-working-on-cloudguard-R80-10-HA/m-p/32082#M3147</guid>
      <dc:creator>Usman_Shaikh</dc:creator>
      <dc:date>2019-02-11T15:25:38Z</dc:date>
    </item>
    <item>
      <title>Re: NTP clock sync not working on cloudguard R80.10 HA</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/NTP-clock-sync-not-working-on-cloudguard-R80-10-HA/m-p/32083#M3148</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have you configured the necessary UDRs in Azure?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Feb 2019 04:56:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/NTP-clock-sync-not-working-on-cloudguard-R80-10-HA/m-p/32083#M3148</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-02-13T04:56:38Z</dc:date>
    </item>
    <item>
      <title>Re: NTP clock sync not working on cloudguard R80.10 HA</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/NTP-clock-sync-not-working-on-cloudguard-R80-10-HA/m-p/32084#M3149</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The UDR has been setup correctly to use the eth1 interface.. I got the traffic flow issue resolved by changing the eth1 to be just a Syn interface and eth0 to be the cluster interface with cluster ip set to virtual-ip on eth0 interface .. So we now see two-way traffic between gateway and the NTP server&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However the clock still wouldn't sync as the offset and jitter are too high..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the output from the firewall&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[Expert@fw1:0]# ntpq -p&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; remote&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; refid&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; st t when poll reach&amp;nbsp;&amp;nbsp; delay&amp;nbsp;&amp;nbsp; offset&amp;nbsp; jitter&lt;BR /&gt;==============================================================================&lt;BR /&gt;&amp;nbsp;10.112.17.10&amp;nbsp;&amp;nbsp;&amp;nbsp; 169.254.0.1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3 u&amp;nbsp;&amp;nbsp; 41&amp;nbsp;&amp;nbsp; 64&amp;nbsp; 377&amp;nbsp;&amp;nbsp; 18.479&amp;nbsp; -224130 6225.18&lt;BR /&gt;&amp;nbsp;10.64.17.10&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 195.66.241.3&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2 u&amp;nbsp;&amp;nbsp; 48&amp;nbsp;&amp;nbsp; 64&amp;nbsp; 377&amp;nbsp;&amp;nbsp; 25.672&amp;nbsp; -223593 4348.23&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ntpq&amp;gt; associations&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ind assID status&amp;nbsp; conf reach auth condition&amp;nbsp; last_event cnt&lt;BR /&gt;===========================================================&lt;BR /&gt;&amp;nbsp; 1 14834&amp;nbsp; 9024&amp;nbsp;&amp;nbsp; yes&amp;nbsp;&amp;nbsp; yes&amp;nbsp; none&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;STRONG&gt;reject&lt;/STRONG&gt;&amp;nbsp;&amp;nbsp; reachable&amp;nbsp; 2&lt;BR /&gt;&amp;nbsp; 2 14835&amp;nbsp; 9024&amp;nbsp;&amp;nbsp; yes&amp;nbsp;&amp;nbsp; yes&amp;nbsp; none&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;STRONG&gt; reject&lt;/STRONG&gt;&amp;nbsp;&amp;nbsp; reachable&amp;nbsp; 2&lt;BR /&gt;&lt;BR /&gt;ntpq&amp;gt; rv 14834&lt;BR /&gt;assID=14834 status=9024 reach, conf, 2 events, event_reach,&lt;BR /&gt;srcadr=10.112.17.10, srcport=123, dstadr=172.19.16.37, dstport=123,&lt;BR /&gt;leap=00, stratum=3, precision=-23, rootdelay=10.849,&lt;BR /&gt;rootdispersion=6.653, refid=169.254.0.1, reach=377, unreach=0, hmode=3,&lt;BR /&gt;pmode=4, hpoll=6, ppoll=6, flash=&lt;STRONG&gt;400&lt;/STRONG&gt; peer_dist, keyid=0, ttl=0,&lt;BR /&gt;offset=-2241300.599, delay=18.479, dispersion=4.444, jitter=4674.461,&lt;BR /&gt;reftime=e00fa28e.f5e2a217&amp;nbsp; Thu, Feb 14 2019&amp;nbsp; 8:17:18.960,&lt;BR /&gt;org=e00fa2a3.f188753b&amp;nbsp; Thu, Feb 14 2019&amp;nbsp; 8:17:39.943,&lt;BR /&gt;rec=e00fab6d.355bf748&amp;nbsp; Thu, Feb 14 2019&amp;nbsp; 8:55:09.208,&lt;BR /&gt;xmt=e00fab6d.304cedeb&amp;nbsp; Thu, Feb 14 2019&amp;nbsp; 8:55:09.188,&lt;BR /&gt;filtdelay=&amp;nbsp;&amp;nbsp;&amp;nbsp; 19.71&amp;nbsp;&amp;nbsp; 20.36&amp;nbsp;&amp;nbsp; 19.22&amp;nbsp;&amp;nbsp; 19.35&amp;nbsp;&amp;nbsp; 18.48&amp;nbsp;&amp;nbsp; 18.71&amp;nbsp;&amp;nbsp; 18.72&amp;nbsp;&amp;nbsp; 18.90,&lt;BR /&gt;filtoffset= -224925 -224710 -224477 -224295 -224130 -223959 -223786 -223615,&lt;BR /&gt;filtdisp=&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.00&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.98&amp;nbsp;&amp;nbsp;&amp;nbsp; 1.97&amp;nbsp;&amp;nbsp;&amp;nbsp; 2.96&amp;nbsp;&amp;nbsp;&amp;nbsp; 3.90&amp;nbsp;&amp;nbsp;&amp;nbsp; 4.89&amp;nbsp;&amp;nbsp;&amp;nbsp; 5.85&amp;nbsp;&amp;nbsp;&amp;nbsp; 6.84&lt;BR /&gt;ntpq&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Spoken to TAC and they reckon we need Hotfix for this as per&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk105862"&gt;sk105862&lt;/A&gt; but I am not sure as I expect the clocks to sync initially and then drift but in my case its not syncing at all to start with&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Feb 2019 08:20:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/NTP-clock-sync-not-working-on-cloudguard-R80-10-HA/m-p/32084#M3149</guid>
      <dc:creator>Usman_Shaikh</dc:creator>
      <dc:date>2019-02-14T08:20:34Z</dc:date>
    </item>
    <item>
      <title>Re: NTP clock sync not working on cloudguard R80.10 HA</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/NTP-clock-sync-not-working-on-cloudguard-R80-10-HA/m-p/32085#M3150</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What happens if you use the command ntpdate first to sync the clocks?&lt;/P&gt;&lt;P&gt;This should do a one-time sync of the clocks regardless of the drift involved.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Feb 2019 16:13:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/NTP-clock-sync-not-working-on-cloudguard-R80-10-HA/m-p/32085#M3150</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-02-14T16:13:23Z</dc:date>
    </item>
    <item>
      <title>Re: NTP clock sync not working on cloudguard R80.10 HA</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/NTP-clock-sync-not-working-on-cloudguard-R80-10-HA/m-p/32086#M3151</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ntpdate does the trick but the clocks then start drifting shortly&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Feb 2019 17:22:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/NTP-clock-sync-not-working-on-cloudguard-R80-10-HA/m-p/32086#M3151</guid>
      <dc:creator>Usman_Shaikh</dc:creator>
      <dc:date>2019-02-14T17:22:32Z</dc:date>
    </item>
    <item>
      <title>Re: NTP clock sync not working on cloudguard R80.10 HA</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/NTP-clock-sync-not-working-on-cloudguard-R80-10-HA/m-p/32087#M3152</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Maybe add a cronjob that periodically calls ntpdate?&lt;/P&gt;&lt;P&gt;TAC would have to get involved to troubleshoot ntp not syncing properly.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Feb 2019 21:23:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/NTP-clock-sync-not-working-on-cloudguard-R80-10-HA/m-p/32087#M3152</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-02-14T21:23:34Z</dc:date>
    </item>
    <item>
      <title>Re: NTP clock sync not working on cloudguard R80.10 HA</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/NTP-clock-sync-not-working-on-cloudguard-R80-10-HA/m-p/32088#M3153</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Indeed TAC did get involved and provided a Hotfix as we were hitting the bug outlined in sk105862…once applied the clocks are syncing OK now with NTP server&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Feb 2019 10:28:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/NTP-clock-sync-not-working-on-cloudguard-R80-10-HA/m-p/32088#M3153</guid>
      <dc:creator>Usman_Shaikh</dc:creator>
      <dc:date>2019-02-15T10:28:35Z</dc:date>
    </item>
  </channel>
</rss>

