Hello All
1) Phisical Domain Controller Windows Server 2008R2 Sp1 have Shema, Domain, PDC, RID, Infrastructure Master role
2) Virtual Domain Controller Windows Server 2008R2 Sp1 have NTP Services
The NTP server are on Domain Controller that is not PDC
may be problem in this?
Must NTP run on PDC?
C:\Users\S>w32tm /query /configuration /verbose[Configuration]
EventLogFlags: 2 (Local)
AnnounceFlags: 10 (Local)
TimeJumpAuditOffset: 28800 (Local)
MinPollInterval: 6 (Local)
MaxPollInterval: 10 (Local)
MaxNegPhaseCorrection: 172800 (Local)
MaxPosPhaseCorrection: 172800 (Local)
MaxAllowedPhaseOffset: 300 (Local)
FrequencyCorrectRate: 4 (Local)
PollAdjustFactor: 5 (Local)
LargePhaseOffset: 50000000 (Local)
SpikeWatchPeriod: 900 (Local)
LocalClockDispersion: 10 (Local)
HoldPeriod: 5 (Local)
PhaseCorrectRate: 7 (Local)
UpdateInterval: 100 (Local)
FileLogName: (Undefined or NotUsed)
FileLogEntries: (Undefined or NotUsed)
FileLogSize: 0 (Undefined or NotUsed)
FileLogFlags: 0 (Undefined or NotUsed)
[TimeProviders]
NtpClient (Local)
DllName: C:\Windows\system32\w32time.dll (Local)
Enabled: 1 (Local)
InputProvider: 1 (Local)
CrossSiteSyncFlags: 2 (Local)
AllowNonstandardModeCombinations: 1 (Local)
ResolvePeerBackoffMinutes: 15 (Local)
ResolvePeerBackoffMaxTimes: 7 (Local)
CompatibilityFlags: 2147483648 (Local)
EventLogFlags: 1 (Local)
LargeSampleSkew: 3 (Local)
SpecialPollInterval: 3600 (Local)
Type: NT5DS (Local)
NtpServer: (Undefined or NotUsed)
NtpServer (Local)
DllName: C:\Windows\system32\w32time.dll (Local)
Enabled: 1 (Local)
InputProvider: 0 (Local)
AllowNonstandardModeCombinations: 1 (Local)
EventLogFlags: 0 (Undefined or NotUsed)
VMICTimeProvider (Local)
DllName: C:\Windows\System32\vmictimeprovider.dll (Local)
Enabled: 1 (Local)
InputProvider: 1 (Local)
We try backup virtual server(ESX 5.0)
There are errors On Domain Controller
Event Id 142 The time service has stopped advertising as a time source because the local clock is not synchronized.
Today some clients have errosr
The system time was changed.Subject:
Security ID: SYSTEM
Account Name: S67$
Account Domain:SAP-ABB
Logon ID: 0x3e7
Process Information:
Process ID: 0x6c4
Name:C:\Program Files\VMware\VMware Tools\vmtoolsd.exe (Указывает какой процесс вызвал изменения)
Previous Time:2013-08-07T23:11:22.258553300Z
New Time:2013-08-07T23:20:22.313000000Z
This event is generated when the system time is changed. It is normal for the Windows Time Service, which runs with System privilege, to change the system time on a regular basis. Other system time changes may be indicative of attempts to tamper with the computer.
9:16:33 am 08.08.2013
The system time was changed.
Subject:
Security ID: LOCAL SERVICE
Account Name: LOCAL SERVICE
Account Domain:NT AUTHORITY
Logon ID: 0x3e5
Process Information:
Process ID: 0x390
Name:C:\Windows\System32\svchost.exe
Previous Time:2013-08-08T05:25:31.982552500Z
New Time:2013-08-08T05:16:33.758082800Z
This event is generated when the system time is changed. It is normal for the Windows Time Service, which runs with System privilege, to change the system time on a regular basis. Other system time changes may be indicative of attempts to tamper with the computer.
System log
3:20:22 am 08.08.2013
The system time has changed to 2013-08-07T23:20:22.313000000Z from 2013-08-07T23:11:22.258553300Z.
How can we fix it? Can anybody help?