VMware ESX 3.5 ntpdate strangeness

We just noticed that the time was very far off on our sparkly new VMware EXS 3.5 server. When I went to run ntpdate to bring it up to sync, I was suprised to find that it could not make a connection to the time server because outbound UDP 123 traffic was blocked by the internal firewall.

Here is what I got:
/usr/sbin/ntpdate -u time.nist.gov
9 Apr 03:47:53 ntpdate[20245]: sendto(192.43.244.18): Operation not permitted
9 Apr 03:47:54 ntpdate[20245]: sendto(192.43.244.18): Operation not permitted
9 Apr 03:47:55 ntpdate[20245]: sendto(192.43.244.18): Operation not permitted
9 Apr 03:47:56 ntpdate[20245]: sendto(192.43.244.18): Operation not permitted
9 Apr 03:47:57 ntpdate[20245]: no server suitable for synchronization found

Normally I would just add a rule to the “/etc/sysconfig/iptables” file to allow traffic out on this port, but Vmware ESX server does not use iptables… It uses its own firewall, so I had to figure out how to change it. Happily, it turns out that there is a handy “esxcfg-firewall” command built just for such things.

Running this:
/usr/sbin/esxcfg-firewall -q | grep 123

12300 1803K valid-tcp-flags  tcp  --  *   *     0.0.0.0/0        0.0.0.0/0

Confirmed that UDP port 123 outbound was disallowed.

Running this opened it up:
/usr/sbin/esxcfg-firewall -e ntpClient

Grep out “123″ again just to be sure:
/usr/sbin/esxcfg-firewall -q | grep 123

1  76 ACCEPT  udp  --  *    *    0.0.0.0/0      0.0.0.0/0     udp dpt:123

And you can now run ntpdate to sync up the time:
/usr/sbin/ntpdate -u time.nist.gov
9 Apr 09:52:54 ntpdate[20319]: step time server 192.43.244.18 offset 21689.039217 sec

Discuss This Article


Got something to say?






Post Tags (user submitted): t (145) - ntpdate (40) - esxcfg-firewall command not found (33) - ntpdate operation not permitted (32) - esx iptables (24) - esxcfg command not found (21) - esx set time (20) - bash: esxcfg-firewall: command not found (18) - vmware ntpdate (18) - esx ntpdate (16) - ntpd sendto operation not permitted (13) - ntpdate no server suitable for synchronization found (12) - esxcfg-firewall: command not found (11) - NTP ESX 3.5 (11) - vmware ntp (10) - esx 3 5 ntp (10) - ntpdate vmware (10) - set time esx (10) - esx 3.5 ntp (10) - iptables esx (9) - ntpdate esx (9) - vmware ntpd (8) - f (8) - vmware esx iptables (8) - ESX no server suitable for synchronization found (8) - vmware set time (8) - ESX set date (8) - esxcfg-firewall (7) - esx ntp (7) - esxcfg-firewall not found (7) - vmware esx firewall (7) - esx change date (7) - set time on esx server (7) - set time on esx (7) - vmware esx set time (6) - esx command not found (6) - ntpd vmware (6) - ntpdate sendto Operation not permitted (6) - set time in esx (6) - esx service command not found (6) - esx ntpdate operation not permitted (5) - ntpdate sendto (5) - Vmware ESX time off (5) - vmware esx time sync (5) - firewall esx (5) - no server suitable for synchronization found vmware (5) - vmware esx change time (5) - mss (4) - ntp esx 3 5 (4) - vmware ntp no server suitable for synchronization found (4) - vmware udp (4) - ntpdate[]: sendto(): Operation not permitted (4) - vmware esx time (4) - vmware ntp server (4) - ntpdate Operation not permitted esx (4) - esx 3 5 firewall commands (4) - vmware esx firewall port (4) - vmware ntpdate no server suitable for synchronization f (4) - ESX change time (4) - vmware ntp client (4) - vmware esx 3.5 enable ssh (4) - vmware esx set date (4) - ntpdate operation not permitted vmware (4) - esx firewall command (4) - change time vmware esx (4) - esxcfg not found (4) - esx ntp sett (4) - esxcfg-firewall command (3) - esx firewall port (3) - vmware operation not permitted (3) - esx time synchronization (3) - esx bash (3) - configure ntp esx 3 5 (3) - ESX 3 5 time (3) - esxcfg ssh command not found (3) - vmware firewall ports (3) - ntpdate no server suitable esx (3) - esx firewall ntp (3) - esx firewall ports (3) - esx firewall start (3) - ssh is not working on esx 3 5 (3) - change time on esx server (3) - set time vmware (3) - vmware esx 3 5 ntp (3) - bash: esxcfg-auth: command not found (3) - vmware ntp not working (3) - esxcfg firewall commands (3) - vmware esx time synchronization (3) - vmare esxcfg-firewall sample (3) - enable esx firewall (3) - esx time (3) - esx ntpd operation not permitted (3) - esx ntpdate no server suitable for synchronization found (3) - ssh esx (3) - vmware esx 0.0.0.0 (3) - set time esx 3.5 (3) - change date in vmware esx (3) - how to change firewall ports on esx (3) - ntp vmware (3) - esxcfg-firewall commands (3) - Installing and Configuring NTP on VMware ESX Server 3.5 (3) - operation not permitted vmware (3) - service command not found esx (3) - ntp vmware esx (3) - ssh ESX 3.5 (3) - vmware time ntp (3) - vmware time command (3) - ntp not working esx (3) - VMware ntp esx (3) - vmware ntp ports (3) - enable ntp port on ESX server (3) - ntpdate port (2) - http://www google com/ig (2) - esx 3 5 time sync (2) - esx 3 5 esxcfg-firewall command not found (2) - no server suitable for synchronization found ESX (2) - How to change ports on ESX 3 5 firewall for ssh server (2) - esxcfg-firewall esx 3 5 (2) - esxcfg-firewall -o (2) - ntpdate no server suitable (2) - esx bash command not found (2) - ntpdate sendto not permitted (2) - esx bash history (2) - ntpd vmware esx (2) - vmware 3 5 firewall (2) - vmware esx open firewall port (2) - ntp no server suitable for synchronization found (2) - ntp client wont start esx 3 5 (2) - vmware no server suitable for synchronization found (2) - esx 3 5 time sync through command (2) - vmware ntp log (2) - ntp esx-firewall (2) - esx time sync (2) - Operation not permitted ntpdate ESX (2) - esxcfg bash:: command not found (2) - open esx firewall port (2) - esx 3 5 ssh firewall (2) - ntpdate firewall (2) - ntp Operation not permitted (2) - esx firewall off (2) - ntpdate: Operation not permitted vmware (2) - changing time in VMWare (2) - esx start ntp client (2) - vmware open firewall port (2) - how to change time on esx 3 5 (2) - configure VMWare Esx Firewall (2) - set time command on esx 3 5 server (2) - vmware ntp setting (2) - time esx (2) - vmware esx 3 5 open firewall (2) -