Security

last person joined: 7 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

ClearPass Clock Syncronisation

This thread has been viewed 4 times
  • 1.  ClearPass Clock Syncronisation

    Posted Mar 07, 2017 05:15 AM

    Hello

    We have a ClearPass running on a Microsoft HyperV Host. After some Time (Days or Weeks) the clock runs out of sync and that even with configured NTP-Servers.

    Had anyone else discovered the same problem?

    Is there any way to configure a cronjob like in unices? With that i can set ntpdate with the parameter '-b' to set the clock every 5 minutes.

    Sorry for my poor englisch...

    Best Regards

    Oliver



  • 2.  RE: ClearPass Clock Syncronisation

    Posted Mar 07, 2017 08:17 AM

    English was perfect!!!!   I never had this issue with my CPPM servers but I am running Aruba appliances not VM versions.  What are you using for NTP servers?  

     

    Have you opened a case with support?

     



  • 3.  RE: ClearPass Clock Syncronisation

    EMPLOYEE
    Posted Mar 07, 2017 08:19 AM
    Make sure you disable host time sync in the VM settings.


  • 4.  RE: ClearPass Clock Syncronisation

    Posted Mar 07, 2017 11:07 AM

    Thank you for your input. I asked our HyperV Admin and after some searching he find this option and disabled it for me. I will restart the CPPM tonight and have an eye onto the clock.

     

    btw. is this a known Problem with HyperV? I experienced this Problem also on other non Windows based Virtual Appliances.



  • 5.  RE: ClearPass Clock Syncronisation

    EMPLOYEE
    Posted Mar 07, 2017 11:12 AM
    It’s a default setting so it can cause problems when it’s checked.


  • 6.  RE: ClearPass Clock Syncronisation

    Posted Mar 08, 2017 05:49 AM

    Hi Tim

    After the reboot yesterday, the clock sync works without the lost of any single second (until now).

    I will continue to monitor the clock, because sometimes it runs stable for weeks until its get out of sync.

    Thank you very much!



  • 7.  RE: ClearPass Clock Syncronisation

    Posted Mar 07, 2017 11:01 AM

    Thank you for you reply.

    I don't think the NTP-Servers are responsible for this errror as all other (non HyperV) Hosts works perfectly. I have diffrent NTP-Servers Linux and Microsoft based but it dosn't make any diffrence from which one's CPPM does syncronize.



  • 8.  RE: ClearPass Clock Syncronisation

    Posted Mar 07, 2017 11:23 AM

    I agree I was just asking out of curiousity because we use to point some of our other hardware (not Aruba) to NTP servers that were Cisco routers and switches.  Worked for years but some of the Linux servers we always slipping time when pointed to these.  We since replaced with a dedicated NTP appliance and its been much better.  Additionally the Linux servers we we using had an NTP bug that we had patched for.  All better lately.