目录

 

 

1 ntp时间服务器同步环境准备... 2

1.1 检查系统是否安装ntp服务... 2

1.2 配置ntp服务的配置文件... 2

1.3 重启ntp服务... 3

1.4 检查ntp服务是否运行... 4

1.5 检查ntp服务器与上层授时服务器的连通与状态... 4

1.6 ntp服务重启写入开机启动... 4

2客户端时间同步配置... 5

2.1 修改本地hosts文件... 5

2.2 ~检查命令行内是否能够同步... 5

2.3 写入定时任务中... 5

2.4 验证时间同步定时任务... 5

3故障排错... 6

3.1 防火墙没有关闭... 6(非常重要)

3.2 ntp-serverntp服务没有开启... 6


    

第1章 ntp时间服务器同步环境准备

1.1 检查系统是否安装ntp服务

[root@schools02 ~]# rpm -qa ntp              没有显示结果,系统没有安装ntp服务

[root@schools02 ~]# yum install ntp –y         安装ntp服务 –y不显示报错

Loaded plugins: fastestmirror

Setting up Install Process

base                                                                               | 3.7 kB     00:00    

base/primary_db                                                                    | 4.7 MB     00:03

Dependency Installed:

 libedit.x86_64 0:2.11-4.20080712cvs.1.el6            ntpdate.x86_640:4.2.6p5-10.el6.centos.1          

 

Complete!                                 安装完毕

[root@schools02 ~]# rpm -qa ntp            

ntp-4.2.6p5-10.el6.centos.1.x86_64             安装成功

1.2 配置ntp服务的配置文件

[root@schools02 ~]# vi /etc/ntp.conf

 

# For more information about this file, see the manpages

# ntp.conf(5), ntp_acc(5), ntp_auth(5),ntp_clock(5), ntp_misc(5), ntp_mon(5).

 

driftfile /var/lib/ntp/drift

 

# Permit time synchronization with our time source,but do not

# permit the source to query or modify the serviceon this system.

restrict default kod nomodify notrap  noquery         默认是拒绝所有客户机同步时间在下一行加入:

restrict 172.16.2.0 mask 255.255.255.0 nomodify       仅在此网段的客户机可以同步时间

restrict -6 default kod nomodify notrap nopeernoquery

 

# Permit all access over the loopbackinterface.  This could

# be tightened as well, but to do so would effectsome of

# the administrative functions.

restrict 127.0.0.1

restrict -6 ::1

 

# Hosts on local network are less restricted.

#restrict 172.16.2.0 mask 255.255.255.0 nomodifynotrap

 

# Use public servers from the pool.ntp.org project.

# Please consider joining the pool(http://www.pool.ntp.org/join.html).

server 0.centos.pool.ntp.org prefer             设置首选的ntp –server同步服务器

server 1.centos.pool.ntp.org iburst

server 2.centos.pool.ntp.org iburst

server 3.centos.pool.ntp.org iburst

 

#broadcast 192.168.1.255 autokey        # broadcast server

#broadcastclient                       # broadcastclient

#broadcast 224.0.1.1 autokey            # multicast server

#multicastclient 224.0.1.1              # multicast client

#manycastserver 239.255.254.254         # manycast server

#manycastclient 239.255.254.254 autokey # manycastclient

 

# Enable public key cryptography.

#crypto

 

includefile /etc/ntp/crypto/pw

 

# Key file containing the keys and key identifiersused when operating

# with symmetric key cryptography.

keys /etc/ntp/keys

 

# Specify the key identifiers which are trusted.

#trustedkey 4 8 42

 

#statistics clockstats cryptostats loopstatspeerstats

"/etc/ntp.conf" 53L, 1771C written

此配置环境是客户机ntp-server可以访问外网。既有上层的ntp-server

在此文档里边仅需更改限制时间同步的网段即可                                                                                        

 

 

1.3 重启ntp服务

[root@schools02 ~]# /etc/init.d/ntpd restart

Shutting down ntpd: [  OK  ]

Starting ntpd: [ OK  ]

1.4 检查ntp服务是否运行

[root@schools02 ~]# netstat -lntup|grep ntp

udp       0      0 172.16.2.146:123            0.0.0.0:*                               1599/ntpd          

udp       0      0 127.0.0.1:123               0.0.0.0:*                               1599/ntpd          

udp       0      0 0.0.0.0:123                 0.0.0.0:*                               1599/ntpd          

udp       0      0 ::1:123                     :::*                                    1599/ntpd          

udp       0      0 :::123                      :::*                                    1599/ntpd   

 

1.5 检查ntp服务器与上层授时服务器的连通与状态

[root@schools02 ~]# ntpstat

synchronised to NTP server (202.112.29.82) atstratum 3

   timecorrect to within 3995 ms

   pollingserver every 64 s

[root@schools02 ~]# ntpq -p

    remote           refid      st t when poll reach   delay  offset  jitter

==============================================================================

*time6.aliyun.co 10.137.38.86     2 u  18   64    1  21.614   18.914   0.000

 202.118.1.130  .INIT.          16 u    -  64    0    0.000   0.000   0.000

 dns1.synet.edu. 202.118.1.46     2 u   6   64    1  92.939   -2.845   7.267

 

 

 

 

 

 

1.6 ntp服务重启写入开机启动

[root@schools02 ~]# echo "/etc/init.d/ntpdrestart" >>/etc/rc.local  开机后服务可以自动重启,开始服务       

[root@schools02 ~]# cat /etc/rc.local              

#!/bin/sh

# This script will be executed *after* all theother init scripts.

# You can put your own initialization stuff in hereif you don't

# want to do the full Sys V style init stuff.

touch /var/lock/subsys/local

/etc/init.d/ntpd restart                            

第2章 客户端时间同步配置

2.1 修改本地hosts文件

[root@schools02 ~]# vi /etc/hosts

127.0.0.1  localhost localhost.localdomain localhost4 localhost4.localdomain4

::1        localhost localhost.localdomain localhost6 localhost6.localdomain6

172.16.2.146 ntp-server

"/etc/hosts" 3L, 183C written

2.2 检查命令行内是否能够同步

[root@schools02 ~]# ntpdate 172.16.2.146

 5 Sep01:44:54 ntpdate[1609]: adjust time server 172.16.2.146 offset 0.058518 sec

[root@schools02 ~]# ntpdate ntp-server

 5 Sep01:46:47 ntpdate[1611]: adjust time server 172.16.2.146 offset 0.003564 sec

2.3 写入定时任务中

[root@schools02 ~]# echo "* * * * *  /usr/sbin/ntpdate ntp-server" >>/var/spool/cron/root

[root@schools02 ~]# crontab -l

* * * * *  /usr/sbin/ntpdatentp-server

[root@schools02 ~]# tail -f /var/log/cron

Sep  501:51:02 schools02 CROND[1617]: (root) CMD (/bin/sh /usr/sbin/ntpdatentp-server)

2.4 验证时间同步定时任务

[root@schools02 ~]# date -s 20160302

Wed Mar  200:00:00 CST 2016

[root@schools02 ~]# tail -f /var/log/cron

Sep  502:03:03 schools02 CROND[1774]: (root) CMD (/usr/sbin/ntpdate ntp-server)

[root@schools02 ~]# date

Mon Sep  502:03:06 CST 2016          更新完毕

第3章 故障排错

3.1 防火墙没有关闭

root@schools02 ~]# chkconfig iptables on            打开ntp-server服务器防火墙

[root@schools02 ~]# /etc/init.d/ntpd restart

Shutting down ntpd: [  OK  ]

Starting ntpd: [ OK  ]

[root@schools02 ~]# chkconfig --list|grep ntp

ntpd           0:off   1:off   2:off  3:off   4:off   5:off  6:off

ntpdate        0:off   1:off   2:off  3:off   4:off   5:off  6:off

[root@schools02 ~]# chkconfig --list|grep iptables

iptables       0:off   1:off   2:on   3:on    4:on    5:on   6:off

[root@schools02 ~]# ntpdate ntp-server             客户端无法同步时间

 5 Sep02:11:08 ntpdate[1849]: no server suitable for synchronization found

3.2 ntp-serverntp服务没有开启

[root@schools02 ~]# pkill ntpd

[root@schools02 ~]# netstat -lntup|grep ntpd

[root@schools02 ~]# ntpdate ntp-server               客户端失败

 5 Sep02:14:39 ntpdate[1868]: no server suitable for synchronization found

[root@schools02 ~]# service ntpd start         

Starting ntpd: [ OK  ] [root@schools02 ~]# netstat-lntup|grep ntpd

udp       0      0 172.16.2.146:123            0.0.0.0:*                               2056/ntpd          

udp       0      0 127.0.0.1:123               0.0.0.0:*                               2056/ntpd          

udp       0      0 0.0.0.0:123                 0.0.0.0:*                               2056/ntpd  

root@schools02 ~]# ntpdate ntp-server            客户端成功同步

 5 Seadjusttime server 172.16.2.146 offset 0.003626 sec


最后放大招:所有的检查都做了,还不能同步。就重启一下系统。