From: Ace Fekay [MVP] on
In news:%23LEO6E3pHHA.960(a)TK2MSFTNGP03.phx.gbl,
Paul Bergson [MVP-DS] <pbergson(a)allete_nospam.com> typed:
> I agree that the PDCe holds the master time service, but all clients
> don't go back to the PDCe for their time.
>
> The link below will explain what I was trying to explain much better,
> but couldn't find earlier. It is for 2000 but believe this hasn't
> changed for 2003.
>
> http://support.microsoft.com/?kbid=224799

I was looking for that article. Thanks. So here's the key sentence:

"All client desktops select an authenticating domain controller (the domain
controller returned by DSGetDCName()) as their time source. If this domain
controller becomes unavailable, the client re-issues its request for a
domain controller."

So it';snot the PDC but the authenticating DC and if not available, it looks
at the next closest one in the client's Site (assuming sites are configured,
if, not it takes the next one in the list of returned DCs when it runs the
DSGetDCName. In a multi domain forest, it appears the PDC Emulator of the
Forest parent becomes the ultimate time source, which should be synched
externally.

Cool! Glad you found this. Thanks!

Ace


From: Paul Bergson [MVP-DS] on
Yup, agreed

--
Paul Bergson
MVP - Directory Services
MCT, MCSE, MCSA, Security+, BS CSci
2003, 2000 (Early Achiever), NT

http://www.pbbergs.com

Please no e-mails, any questions should be posted in the NewsGroup
This posting is provided "AS IS" with no warranties, and confers no rights.

"Ace Fekay [MVP]" <PleaseAskMe(a)SomeDomain.com> wrote in message
news:Oa7MBz8pHHA.4544(a)TK2MSFTNGP02.phx.gbl...
> In news:%23LEO6E3pHHA.960(a)TK2MSFTNGP03.phx.gbl,
> Paul Bergson [MVP-DS] <pbergson(a)allete_nospam.com> typed:
>> I agree that the PDCe holds the master time service, but all clients
>> don't go back to the PDCe for their time.
>>
>> The link below will explain what I was trying to explain much better,
>> but couldn't find earlier. It is for 2000 but believe this hasn't
>> changed for 2003.
>>
>> http://support.microsoft.com/?kbid=224799
>
> I was looking for that article. Thanks. So here's the key sentence:
>
> "All client desktops select an authenticating domain controller (the
> domain controller returned by DSGetDCName()) as their time source. If this
> domain controller becomes unavailable, the client re-issues its request
> for a domain controller."
>
> So it';snot the PDC but the authenticating DC and if not available, it
> looks at the next closest one in the client's Site (assuming sites are
> configured, if, not it takes the next one in the list of returned DCs when
> it runs the DSGetDCName. In a multi domain forest, it appears the PDC
> Emulator of the Forest parent becomes the ultimate time source, which
> should be synched externally.
>
> Cool! Glad you found this. Thanks!
>
> Ace
>


From: Ace Fekay [MVP] on
In news:e9ksSfDqHHA.3892(a)TK2MSFTNGP05.phx.gbl,
Paul Bergson [MVP-DS] <pbergson(a)allete_nospam.com> typed:
> Yup, agreed

It's always nice to take the time to learn about time... :-)


From: Keli on
Hi,

I put external ntp servers as you suggest, and it worked. So problem was in
may network, mapping and policies.

After changes on that segment, I put router as ntp server and it works :)

(for now in test environment - I hope that it 'll work in production also :)))

again, thank you Ace for your suggestions !!

Keli

"Ace Fekay [MVP]" wrote:

> In news:5ED3D0BF-2CD5-4C6D-9720-1ABF9685B780(a)microsoft.com,
> Keli <Keli(a)discussions.microsoft.com> typed:
> > ok, I know, but I read article before your answer :)
> >
> > I am cheking my network and I hope to find some solution ....
> >
> >
> > thanks Ace,
> >
> >
> > keli
>
> Oh, forgot one thing. If you have McAfee, or any other antivirus software on
> the PDC Emulator, it may be stopping that type of traffic too. Check it out.
>
> Ace
>
>
>
From: Ace Fekay [MVP] on
In news:9B16F395-3FFD-4EE3-9770-1D118AF3CD29(a)microsoft.com,
Keli <Keli(a)discussions.microsoft.com> typed:
> Hi,
>
> I put external ntp servers as you suggest, and it worked. So problem
> was in may network, mapping and policies.
>
> After changes on that segment, I put router as ntp server and it
> works :)
>
> (for now in test environment - I hope that it 'll work in production
> also :)))
>
> again, thank you Ace for your suggestions !!
>
> Keli

You are welcome Keli. As you see, there isn't much to this service. It is
rather simple. :-)

Cheers!

Ace