Has anyone else encountered this issue?
I have several 2200 appliances running R80.10 with Jumbo Hotfix Accumulator 189 and I cannot get them to sync with any NTP server. I have tried us.pool.ntp.org, pool.ntp.org, individual public NTP servers by IP.
I have a firewall policy rule allowing these security gateways to any destination for service "NTP" and any to these security gateways for service "NTP".
DNS resolves domain names fine on these gateways.
I have tried stopping and starting the NTP service. cpstop/cpstart and even a reload.
tcpdump -i eth1 dst port 123 shows packets to and from the chosen NTP server but I can't get a synchronization to happen:
tcpdump -i eth1 dst port 123
tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
listening on eth1, link-type EN10MB (Ethernet), capture size 96 bytes
10:41:31.052665 IP 96-80-255-145-static.hfc.comcastbusiness.net.ntp > quirk.faceprint.com.ntp: NTPv1, Client, length 48
10:41:31.090541 IP quirk.faceprint.com.ntp > 96-80-255-145-static.hfc.comcastbusiness.net.ntp: NTPv1, Server, length 48
10:42:36.051960 IP 96-80-255-145-static.hfc.comcastbusiness.net.ntp > quirk.faceprint.com.ntp: NTPv1, Client, length 48
10:42:36.096849 IP quirk.faceprint.com.ntp > 96-80-255-145-static.hfc.comcastbusiness.net.ntp: NTPv1, Server, length 48
10:43:40.052196 IP 96-80-255-145-static.hfc.comcastbusiness.net.ntp > quirk.faceprint.com.ntp: NTPv1, Client, length 48
10:43:40.092700 IP quirk.faceprint.com.ntp > 96-80-255-145-static.hfc.comcastbusiness.net.ntp: NTPv1, Server, length 48
10:44:46.051565 IP 96-80-255-145-static.hfc.comcastbusiness.net.ntp > quirk.faceprint.com.ntp: NTPv1, Client, length 48
ntpq peers shows the following:
[Expert@shelby-gw:0]# ntpq
ntpq> peers
remote refid st t when poll reach delay offset jitter
==============================================================================
quirk.faceprint .INIT. 16 u - 256 0 0.000 0.000 0.000
ntpq>