目录
1.5 检查ntp服务器与上层授时服务器的连通与状态... 4
3.1 防火墙没有关闭... 6(非常重要)
第1章 ntp时间服务器同步环境准备
1.1 检查系统是否安装ntp服务
[root@schools02 ~]# rpm -qa ntp 没有显示结果,系统没有安装ntp服务
[root@schools02 ~]# yum install ntp �y 安装ntp服务 �y不显示报错
Loaded plugins: fastestmirror
Setting up Install Process
base| 3.7 kB 00:00
base/primary_db| 4.7 MB 00:03
Dependency Installed:
libedit.x86_64 0:2.11-4.20080712cvs.1.el6 ntpdate.x86_640:4.2.6p5-10.el6.centos.1
Complete! 安装完毕
[root@schools02 ~]# rpm -qa ntp
ntp-4.2.6p5-10.el6.centos.1.x86_64 安装成功
1.2 配置ntp服务的配置文件
[root@schools02 ~]# vi /etc/ntp.conf
# For more information about this file,see the manpages
# ntp.conf(5),ntp_acc(5),ntp_auth(5),ntp_clock(5),ntp_misc(5),ntp_mon(5).
driftfile /var/lib/ntp/drift
# Permit time synchronization with our time source,but do not
# permit the source to query or modify the serviceon this system.
restrict default kod nomodify notrap noquery 默认是拒绝所有客户机同步时间在下一行加入:
restrict 172.16.2.0 mask 255.255.255.0 nomodify 仅在此网段的客户机可以同步时间
restrict -6 default kod nomodify notrap nopeernoquery
# Permit all access over the loopbackinterface. This could
# be tightened as well,but to do so would effectsome of
# the administrative functions.
restrict 127.0.0.1
restrict -6 ::1
# Hosts on local network are less restricted.
#restrict 172.16.2.0 mask 255.255.255.0 nomodifynotrap
# Use public servers from the pool.ntp.org project.
# Please consider joining the pool(http://www.pool.ntp.org/join.html).
server 0.centos.pool.ntp.org prefer 设置首选的ntp �server同步服务器
server 1.centos.pool.ntp.org iburst
server 2.centos.pool.ntp.org iburst
server 3.centos.pool.ntp.org iburst
#broadcast 192.168.1.255 autokey # broadcast server
#broadcastclient# broadcastclient
#broadcast 224.0.1.1 autokey # multicast server
#multicastclient 224.0.1.1 # multicast client
#manycastserver 239.255.254.254 # manycast server
#manycastclient 239.255.254.254 autokey # manycastclient
# Enable public key cryptography.
#crypto
includefile /etc/ntp/crypto/pw
# Key file containing the keys and key identifiersused when operating
# with symmetric key cryptography.
keys /etc/ntp/keys
# Specify the key identifiers which are trusted.
#trustedkey 4 8 42
#statistics clockstats cryptostats loopstatspeerstats
"/etc/ntp.conf" 53L,1771C written
此配置环境是客户机ntp-server可以访问外网。既有上层的ntp-server
在此文档里边仅需更改限制时间同步的网段即可
1.3 重启ntp服务
[root@schools02 ~]# /etc/init.d/ntpd restart
Shutting down ntpd: [ OK ]
Starting ntpd: [OK ]
1.4 检查ntp服务是否运行
[root@schools02 ~]# netstat -lntup|grep ntp
udp0 0 172.16.2.146:123 0.0.0.0:* 1599/ntpd
udp0 0 127.0.0.1:123 0.0.0.0:* 1599/ntpd
udp0 0 0.0.0.0:123 0.0.0.0:* 1599/ntpd
udp0 0 ::1:123 :::* 1599/ntpd
udp0 0 :::123 :::* 1599/ntpd
1.5 检查ntp服务器与上层授时服务器的连通与状态
[root@schools02 ~]# ntpstat
synchronised to NTP server (202.112.29.82) atstratum 3
timecorrect to within 3995 ms
pollingserver every 64 s
[root@schools02 ~]# ntpq -p
remote refid st t when poll reach delayoffset jitter
==============================================================================
*time6.aliyun.co 10.137.38.86 2 u18 64 121.614 18.914 0.000
202.118.1.130.INIT. 16 u -64 0 0.0000.000 0.000
dns1.synet.edu. 202.118.1.46 2 u6 64 192.939 -2.845 7.267
1.6 ntp服务重启写入开机启动
[root@schools02 ~]# echo "/etc/init.d/ntpdrestart" >>/etc/rc.local 开机后服务可以自动重启,开始服务
[root@schools02 ~]# cat /etc/rc.local
#!/bin/sh
# This script will be executed *after* all theother init scripts.
# You can put your own initialization stuff in hereif you don't
# want to do the full Sys V style init stuff.
touch /var/lock/subsys/local
/etc/init.d/ntpd restart
第2章 客户端时间同步配置
2.1 修改本地hosts文件
[root@schools02 ~]# vi /etc/hosts
127.0.0.1localhost localhost.localdomain localhost4 localhost4.localdomain4
::1localhost localhost.localdomain localhost6 localhost6.localdomain6
172.16.2.146ntp-server
"/etc/hosts" 3L,183C written
2.2 检查命令行内是否能够同步
[root@schools02 ~]# ntpdate 172.16.2.146
5 Sep01:44:54 ntpdate[1609]: adjust time server 172.16.2.146 offset 0.058518 sec
[root@schools02 ~]# ntpdate ntp-server
5 Sep01:46:47 ntpdate[1611]: adjust time server 172.16.2.146 offset 0.003564 sec
2.3 写入定时任务中
[root@schools02 ~]# echo "* * * * * /usr/sbin/ntpdate ntp-server" >>/var/spool/cron/root
[root@schools02 ~]# crontab -l
* * * * * /usr/sbin/ntpdatentp-server
[root@schools02 ~]# tail -f /var/log/cron
Sep 501:51:02 schools02 CROND[1617]: (root) CMD (/bin/sh /usr/sbin/ntpdatentp-server)
2.4 验证时间同步定时任务
[root@schools02 ~]# date -s 20160302
Wed Mar 200:00:00 CST 2016
[root@schools02 ~]# tail -f /var/log/cron
Sep 502:03:03 schools02 CROND[1774]: (root) CMD (/usr/sbin/ntpdate ntp-server)
[root@schools02 ~]# date
Mon Sep 502:03:06 CST 2016 更新完毕
第3章 故障排错
3.1 防火墙没有关闭
root@schools02 ~]# chkconfig iptables on 打开ntp-server服务器防火墙
[root@schools02 ~]# /etc/init.d/ntpd restart
Shutting down ntpd: [ OK ]
Starting ntpd: [OK ]
[root@schools02 ~]# chkconfig --list|grep ntp
ntpd0:off 1:off 2:off3:off 4:off 5:off6:off
ntpdate0:off 1:off 2:off3:off 4:off 5:off6:off
[root@schools02 ~]# chkconfig --list|grep iptables
iptables0:off 1:off 2:on3:on 4:on 5:on6:off
[root@schools02 ~]# ntpdate ntp-server 客户端无法同步时间
5 Sep02:11:08 ntpdate[1849]: no server suitable for synchronization found
3.2 ntp-server中ntp服务没有开启
[root@schools02 ~]# pkill ntpd
[root@schools02 ~]# netstat -lntup|grep ntpd
[root@schools02 ~]# ntpdate ntp-server 客户端失败
5 Sep02:14:39 ntpdate[1868]: no server suitable for synchronization found
[root@schools02 ~]# service ntpd start
Starting ntpd: [OK ] [root@schools02 ~]# netstat-lntup|grep ntpd
udp0 0 172.16.2.146:123 0.0.0.0:* 2056/ntpd
udp0 0 127.0.0.1:123 0.0.0.0:* 2056/ntpd
udp0 0 0.0.0.0:123 0.0.0.0:* 2056/ntpd
root@schools02 ~]# ntpdate ntp-server 客户端成功同步
5 Seadjusttime server 172.16.2.146 offset 0.003626 sec
最后放大招:所有的检查都做了,还不能同步。就重启一下系统。