一、环境说明
10.10.117.95 可以访问公网 同步阿里云 NTP 时间服务 作为内网NTP server
10.10.239.117 内网客户机同步内网NTP server
部署NTP server
修改配置文件 添加阿里云NTP服务,关闭内核同步,开启允许客户端访问。
[root@mon ~]# vim /etc/chrony.conf
# Use public servers from the pool.ntp.org project.
# Please consider joining the pool (http://www.pool.ntp.org/join.html).
#server 0.centos.pool.ntp.org iburst # #注释掉系统默认的NTP服务
#server 1.centos.pool.ntp.org iburst
#server 2.centos.pool.ntp.org iburst
#server 3.centos.pool.ntp.org iburst
server ntp1.aliyun.com iburst #添加4台阿里云 NTP服务器
server ntp2.aliyun.com iburst
server ntp3.aliyun.com iburst
server ntp4.aliyun.com iburst
# Record the rate at which the system clock gains/losses time.
driftfile /var/lib/chrony/drift
# Allow the system clock to be stepped in the first three updates
# if its offset is larger than 1 second.
makestep 1.0 3
# Enable kernel synchronization of the real-time clock (RTC).
#rtcsync # 关闭实时时钟内核同步
# Enable hardware timestamping on all interfaces that support it.
#hwtimestamp *
# Increase the minimum number of selectable sources required to adjust
# the system clock.
#minsources 2
# Allow NTP client access from local network.
#allow 192.168.0.0/16
allow 0.0.0.0/0 #允许本地网络的NTP客户端访问
……………………
[root@mon ~]# systemctl enable chronyd #设置开机启动
[root@mon ~]# systemctl restart chronyd # 重启服务
[root@mon ~]# systemctl status chronyd #