内网ntp时间同步

注:如果防火墙开启,请开辟123端口

firewall-cmd --permanent --add-port=123/udp

firewall-cmd --reload

 

当前有10.0.0.149   和10.0.0.151两台(全内网)

1,.选择10.0.0.151主机设为主时间.10.0.0.149主机以此主机为准

安装ntp服务

ntp相关rpm包获取地址:https://pan.baidu.com/s/1ZWn5JOeQsCGvqjQDimpDdg

rpm -Uvh autogen-libopts-5.18-5.el7.x86_64.rpm

rpm -Uvh ntpdate-4.2.6p5-25.el7.centos.x86_64.rpm

rpm -ivh ntp-4.2.6p5-25.el7.centos.x86_64.rpm

 

安装完ntpd服务后,打开/etc/ntp.conf文件

注:红色为新增部分

# For more information about this file, see the man pages

# ntp.conf(5), ntp_acc(5), ntp_auth(5), ntp_clock(5), ntp_misc(5), ntp_mon(5).

driftfile /var/lib/ntp/drift

# Permit time synchronization with our time source, but do not

# permit the source to query or modify the service on this system.

restrict default kod nomodify notrap nopeer noquery

# Permit all access over the loopback interface.  This could

# be tightened as well, but to do so would effect some of

# the administrative functions.

restrict 127.0.0.1

restrict -6 ::1

# Hosts on local network are less restricted.

# 允许内网其他机器同步时间 改为自己的网段

restrict 10.0.0.0 mask 255.255.255.0 nomodify notrap

# Use public servers from the pool.ntp.org project.

# Please consider joining the pool (http://www.pool.ntp.org/join.html).

#broadcast 192.168.1.255 autokey        # broadcast server

#broadcastclient                        # broadcast client

#broadcast 224.0.1.1 autokey            # multicast server

#multicastclient 224.0.1.1              # multicast client

#manycastserver 239.255.254.254         # manycast server

#manycastclient 239.255.254.254 autokey # manycast client

# allow update time by the upper server 

# Undisciplined Local Clock. This is a fake driver intended for backup

# and when no outside source of synchronized time is available. 

# 因为是内网,以本地时间作为时间服务

server  127.127.1.0     # local clock

fudge   127.127.1.0 stratum 10

# Enable public key cryptography.

#crypto

includefile /etc/ntp/crypto/pw

# Key file containing the keys and key identifiers used when operating

# with symmetric key cryptography. 

keys /etc/ntp/keys

# Specify the key identifiers which are trusted.

#trustedkey 4 8 42

# Specify the key identifier to use with the ntpdc utility.

#requestkey 8

# Specify the key identifier to use with the ntpq utility.

#controlkey 8

# Enable writing of statistics records.

#statistics clockstats cryptostats loopstats peerstats

2.开启服务: service ntpd start

3.设置开机自启动

4.查看服务是否开启

ntpstat

显示synchronised to local net at stratum 11

    time correct to within 12 ms

     polling server every 64 s

则以本地时间为准,主机设置完成

二,在10.0.0.149主机设置定时任务,定时同步主机时间

 crontab  -e

添加新的定时任务

0 6 * * * /usr/sbin/ntpdate -u 10.0.0.151

 然后重新加载定时任务

 service crond restart

三、客户端配置ntp服务

server 172.17.0.85

restrict 172.17.0.85 nomodify notrap noquery

server 127.0.0.1 # local clock
fudge 127.0.0.1 stratum 10

四、强制时间同步

如果时间相差太大,可能不能同步,强制同步如下:

https://www.cnblogs.com/liushui-sky/p/9203657.html

参考

https://blog.csdn.net/a18838964650/article/details/86084790

https://blog.csdn.net/tomspcc/article/details/52944868

https://blog.csdn.net/qq_38591756/article/details/85243965?utm_medium=distribute.pc_relevant_t0.none-task-blog-BlogCommendFromMachineLearnPai2-1.nonecase&depth_1-utm_source=distribute.pc_relevant_t0.none-task-blog-BlogCommendFromMachineLearnPai2-1.nonecase

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值