[INSTRM-391] NTP setting on MCS VM(133.40.164.208) Created: 23/Jun/18  Updated: 31/Mar/23  Resolved: 31/Mar/23

Status: Won't Fix
Project: Instrument control development
Component/s: None
Affects Version/s: None
Fix Version/s: None

Type: Task Priority: Normal
Reporter: kyono Assignee: Unassigned
Resolution: Won't Fix Votes: 0
Labels: None
Remaining Estimate: Not Specified
Time Spent: Not Specified
Original Estimate: Not Specified


 Description   

mcs(133.40.164.208) vm guest is trying to communicate with outside NTP server.

[Ref]

ccs# show logging ip access-list cache

Src IP        Dst IP     S-Port    D-Port    Src Intf         Protocol     Hits    

------------------------------------------------------------------------------------------------

91.189.94.4      133.40.164.208     123     46789     Ethernet7/48 (17)UDP                1 

91.189.89.199    133.40.164.208     123     52822     Ethernet7/48 (17)UDP                1

 

Please check ntp setting to see if it is using ntp-ics(133.40.164.50). Otherwise it may not have or end up not having correct time...

Not sure who manages it and no pfs user login on mcs vm as of now. 

 

Regards,

Eiji



 Comments   
Comment by cloomis [ 23/Jun/18 ]

I'll quietly and gently point out that if the mcs host was using a DHCP server it could get the NTP server address dynamically. chyan

Comment by shimono [ 23/Jun/18 ]

following listings in SSN-00028 as recommended configuration,
> https://github.com/Subaru-PFS/ics_doc/blob/master/SSN-00028/index.rst#site-specific-dnsmasq-configurations
> Some of this section is RECOMMENDED for instrument development sites (or branch in git repository) but is NOT REQUIRED.
> dhcp-authoritative: In the PFS network, the dnsmasq service is the only one DHCP server on a network, and this should be set (but could work without this configuration).

we have a line of ntp-server configuration in our dnsmasq
> dnsmasq-site.subaru:dhcp-option=option:ntp-server,133.40.164.50

is this what cloomis wants?

so, seems host side is not on/using dhcp.

Comment by chyan [ 24/Jun/18 ]

I have changed the setting of NTP server on MCS.  Now it is pointed to 133.40.164.50.   kyono Please let me know if it is still trying to connect to outside world.  Thanks

Comment by kyono [ 24/Jun/18 ]

No logs for mcs communicating with outside NTP service now, but it can be because of polling time. 

Can you do "ntpstat" on mcs vm?

Although i am not sure change you made, based on Craig and Shimono-san's comments, is how PFS ICS should be, you can check ntp status like below. chyan

[command]

pfs@gw-ics:~$ ntpstat

synchronised to NTP server (133.40.164.50) at stratum 4

   time correct to within 76 ms

   polling server every 1024 s

 

Comment by shimono [ 26/Jun/18 ]

we have 'ntp-ics' service name registered in dnsmasq, and I suppose we may be better to use canonical name rather than having ip address directly.

Comment by cloomis [ 26/Jun/18 ]

I would prefer all hosts to use DHCP, and thus allow both consistent and simple (re-)configuration of NTP/DNS servers. And slightly better tracking of booting/liveness, etc.

If a host is configured manually it should use hostnames, except for DNS servers which must obviously be by IP.

One advantage of using DHCP would show up if we wanted to switch from a single server NTP config to a multiple server config. Since we are not using a dedicated clock we might want to at some point. Seeing that "stratum 4" above is not very comforting.

[ I think this particular ticket can be closed. It has been fixed. ]

Comment by kyono [ 26/Jun/18 ]

This is just comment, but I now see that mcs machine is not vm running on ICS.

Sorry for confusion...

Comment by shimono [ 26/Jun/18 ]
  • if this host is configured by dhcp for address-ish things, i agree that we shall follow dhcp-way.
  • i agree we shall have another ticket for further server side configuration.
  • i don't think we can prepare four ntp servers within PFS-LAN, so i assume we will not go to multiple ntp server configuration using physical hosts.
  • both dns and dhcp configuration should work for multiple server configuration (e.g. using chrony for client). in any case we need both, for boxes (non-pc) need to be configured statically.
Comment by yuki.moritani [ 31/Mar/23 ]

This was for the old mcs PC.

Generated at Sat Feb 10 16:24:31 JST 2024 using Jira 8.3.4#803005-sha1:1f96e09b3c60279a408a2ae47be3c745f571388b.