Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Scottc98
Advisor

NTP server via FQDN - Update ip when DNS changes

In a situation where we are in process of moving our NTP servers to a new location and therefore will have new IP addresses.

All of our CP Firewalls have NTP configured with  FDQNs and the hope is that the resolved IP will update when we update the DNS record used to our new server ip.  

Its looks like when searching around in previous support posts, it sounds like NTP will only resolve the FDQN 'once' and therefore may not update to the new IP.

 

Is this accurate?    Or is there some aged out (cache) that will eventually have it update?

If this is 'sticky' regardless of the DNS change, is there something safely run to each FW to force it to update?   

I believe it i rerun the ntp configuration on the CLI, it would force the update (i.e treat as a new server add) and I am sure that restarting ntpd process would do the same.....but is there anything else option wise?   

 

I want to make sure that our FWs properly point to the new servers before the old ones are decommissioned.

 

Thanks in advance 

2 Replies
the_rock
Legend
Legend

I cant speak for anyone else, but I recall once when I worked with customer in same scenario, we simply ended up reconfiguring ntp via web UI (clish would do as well) and then we ran through some commands from below to confirm and that was it. Took about 10 mins and all synced fine.

Andy

https://support.checkpoint.com/results/sk/sk92602

0 Kudos
PhoneBoy
Admin
Admin

I assume you'd have a similar issue if you change the DNS record when using ntpd on a regular Linux system as well (i.e. this isn't Check Point specific).
Note that changing the ntpd configuration in the Gaia WebUI/clish will cause ntpd to restart.
Forcing a restart on ntpd is probably your only option. 

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events