• VMware ESX 3.5 ntpdate strangeness

    We just noticed that the time was very far off on our sparkly new VMware EXS 3.5 server. When I went to run ntpdate to bring it up to sync, I was suprised to find that it could not make a connection to the time server because outbound UDP 123 traffic was blocked by the internal firewall. Here is what I got:

    # /usr/sbin/ntpdate -u time.nist.gov
    9 Apr 03:47:53 ntpdate[20245]: sendto(192.43.244.18): Operation not permitted
    9 Apr 03:47:54 ntpdate[20245]: sendto(192.43.244.18): Operation not permitted
    9 Apr 03:47:55 ntpdate[20245]: sendto(192.43.244.18): Operation not permitted
    9 Apr 03:47:56 ntpdate[20245]: sendto(192.43.244.18): Operation not permitted
    9 Apr 03:47:57 ntpdate[20245]: no server suitable for synchronization found

    Normally I would just add a rule to the “/etc/sysconfig/iptables” file to allow traffic out on this port, but Vmware ESX server does not use iptables… It uses its own firewall, so I had to figure out how to change it. Happily, it turns out that there is a handy “esxcfg-firewall” command built just for such things.

    Running this:
    /usr/sbin/esxcfg-firewall -q | grep 123

    12300 1803K valid-tcp-flags  tcp  --  *   *     0.0.0.0/0        0.0.0.0/0

    Confirmed that UDP port 123 outbound was disallowed.

    Running this opened it up:
    /usr/sbin/esxcfg-firewall -e ntpClient

    Grep out “123″ again just to be sure:
    /usr/sbin/esxcfg-firewall -q | grep 123

    1  76 ACCEPT  udp  --  *    *    0.0.0.0/0      0.0.0.0/0     udp dpt:123

    And you can now run ntpdate to sync up the time:
    /usr/sbin/ntpdate -u time.nist.gov

    9 Apr 09:52:54 ntpdate[20319]: step time server 192.43.244.18 offset 21689.039217 sec
    This entry was posted on Wednesday, April 9th, 2008 at 10:07 am and is filed under Data and Technology. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.
  • 0 Comments

    Take a look at some of the responses we've had to this article.

  • Leave a Reply

    Let us know what you thought.

  • Name (required):

    Email (required):

    Website:

    Message:

Visitors have tagged this post: ntpdate operation not permitted (174) - ntpdate (156) - t (145) - esx iptables (68) - esxcfg-firewall command not found (68) - bash: esxcfg-firewall: command not found (60) - esx ntpdate (54) - vmware ntpdate (53) - vmware esx iptables (40) - esxcfg command not found (40) - ntpdate sendto Operation not permitted (38) - ESX no server suitable for synchronization found (37) - esx 3.5 ntp (35) - ntpd sendto operation not permitted (31) - iptables esx (29) - ntpdate esx (27) - ntpdate no server suitable for synchronization found (26) - esx set time (26) - esxcfg-firewall ntp (26) - ntpdate vmware (25) - esxcfg-firewall not found (25) - vmware ntp (24) - vmware esx time (24) - esx ntpdate operation not permitted (23) - NTP ESX 3.5 (22) - vmware no server suitable for synchronization found (21) - no server suitable for synchronization found ESX (18) - vmware esx ntp (18) - esxcfg-firewall: command not found (18) - vmware esx set time (17) - vmware ntpd (16) - no server suitable for synchronization found vmware (16) - esx ntp (15) - change time vmware esx (15) - vmware esx firewall (14) - ntpd vmware (14) - bash: ntpdate: command not found (14) - esx ntp log (14) - ntpdate port (13) - set time on esx server (13) - set time esx (13) - esx time command (13) - vmware set time (12) - ntp vmware (12) - ntp vmware esx (12) - esx iptable (12) - esx firewall commands (12) - ESX set date (11) - esxcfg-firewall (10) - esx 3 5 ntp (10) - vmware udp (10) - vmware ntp server (10) - vmware firewall ports (10) - no server suitable for synchronization found (10) - Vmware ESX ntpdate (10) - vmware esx change time (10) - esxcfg-firewall: not found (10) - Installing and Configuring NTP on VMware ESX Server 3.5 (10) - vmware esx 3.5 ntp (10) - esxcfg not found (10) - esx service command not found (10) - linux ntpdate operation not permitted (9) - vmware esx time sync (9) - esx firewall ntp (9) - esx change date (9) - esx server iptables (9) - ESX Operation not permitted (9) - esx 3.5 commands (9) - iptables vmware esx (9) - set time vmware esx (9) - vmware esx 3.5 time sync (9) - esxcfg-auth command not found (9) - esx 3.5 time sync (9) - f (8) - ntpdate[]: sendto(): Operation not permitted (8) - ntp Operation not permitted (8) - set time on esx (8) - esx 0.0.0.0 (8) - esx ntp command (8) - vmware ntpdate Operation not permitted (8) - Operation not permitted ntpdate (8) - set date esx 3.5 (8) - esx ntp logs (8) - ntpdate \"Operation not permitted\ (8) - ntpdate sendto (7) - Vmware ESX time off (7) - esx bash (7) - ntpdate firewall (7) - esx command not found (7) - bash: esxcfg-auth: command not found (7) - esx change ssh port (7) - esx ntpdate no server suitable for synchronization found (7) - change date in esx (7) - vmware time synchronization (7) - esxcfg esx 3.5 (7) - ESX 3.5 ntpdate (7) - esx 3.5 change date (7) - ntp sendto Operation not permitted (7) - change time on esx (7) - esx ntp firewall (7) - esx 3.5 firewall commands (7) - esx ntp no server suitable for synchronization found (7) - ntpdate sendto not permitted (6) - VMware ESX ntpdate Operation not permitted (6) - ntpdate Operation not permitted esx (6) - ESX change time (6) - esx time (6) - vmware esx set date (6) - set time in esx (6) - vmware esx 0.0.0.0 (6) - vmware esx 3.5 time (6) - service command not found esx (6) - esx ssh port (6) - vmware time command (6) - vmware 3.5 ntp (6) - vmware esx 3.5 ntpd (6) - esx change ntp (6) - iptable esx (6) - Operation not permitted esx (5) - firewall esx (5) - ntpdate no server suitable esx (5) - change time on esx server (5) - set time vmware (5) - vmware esx firewall port (5) - vmware esx time synchronization (5) - change time esx (5) - vmware ntp client (5) - enable esx firewall (5) - vmware ntp port (5) - esx ntpd operation not permitted (5) - ntpdate operation not permitted vmware (5) - esx firewall command (5) - ntp server vmware esx (5) - set date on ESX 3.5 (5) - vmware esx 3.5 firewall (5) - esx 4 (5) - Installing and Configuring NTP on VMware ESX Server (5) - esx 3.5 esxcfg-firewall not found (5) - -ash: esxcfg-firewall: not found (5) - ntpdate: command not found (5) - mss (4) - ntp esx 3 5 (4) - vmware ntp no server suitable for synchronization found (4) - esxcfg-firewall -o (4) - esx firewall port (4) - esx bash command not found (4) - vmware ntp log (4) - esx time synchronization (4) - esx ntp operation not permitted (4) - esx 3 5 firewall commands (4) -