偏移量与抖动更优的首选NTP服务器遭拒绝问题排查
Let’s walk through the most likely reasons your internal primary NTP server (169.254.1.51) isn’t being used—even though its offset and jitter perform better—and how to fix them:
1. Your Preferred Server Isn’t in the NTP Config
Looking at the ntp.conf snippet you shared, I notice you haven’t added 169.254.1.51 to the server list—you only have the 10.241.34.x servers listed. NTP can only sync to servers you explicitly configure, so this is the biggest red flag.
Fix this by adding your preferred server to the config, and use the prefer flag to tell NTP to prioritize it over others:
# Add this above your existing server entries server 169.254.1.51 iburst prefer
2. Missing Restrict Rule for the Preferred Server
Your config includes restrict rules for the 10.241.34.x servers, but none for 169.254.1.51. Without a restrict rule allowing communication, NTP may block sync attempts with this server.
Add a matching restrict rule for your internal server:
restrict 169.254.1.51 mask 255.255.255.255 nomodify notrap noquery
This rule lets your client pull time from the server while preventing unwanted interactions (like modifying the server’s config).
3. Verify Network Reachability and Server Health
Even with the right config, network issues or a misbehaving NTP server can cause rejection:
- Test basic connectivity: Run
ping 169.254.1.51from the client to ensure the server is reachable. - Check NTP port access: Confirm no firewalls (client or server-side) are blocking UDP port 123 (the default NTP port).
- Inspect peer status: Use
ntpq -pon the client to see if 169.254.1.51 appears in the list. Look for the status column—if it showsREJECT, that means the client is actively refusing the server (often due to config or server-side issues). - Check the server’s NTP service: On 169.254.1.51, verify the NTP daemon is running and no errors are logged (check
/var/log/messagesor usesystemctl status ntpd).
4. Ensure Config Changes Take Effect
After updating ntp.conf, restart the NTP service to apply changes:
# For systemd-based systems systemctl restart ntpd # For SysVinit systems service ntp restart
Wait 5-10 minutes for NTP to re-evaluate peers, then run ntpq -p again to confirm your preferred server is now being used.
内容的提问来源于stack exchange,提问作者ananTgarg

