I'm in the process of decomissioning two old Server 2008 R2 DCs.
I've installed AD DS on two new Server 2022's (now DCs!). I had notes from way back when I setup the 2008 R2's, but those were the first DCs in the forest so there wasn't any migration.
On the PDC emulator role (Server 2008 R2) I had opened Command Prompt and entered the following command:
w32tm /config /syncfromflags:manual /manualpeerlist:0.pool.ntp.org,1.pool.ntp.org,2.pool.ntp.org,3.pool.ntp.org /reliable:yes /update
This has worked since 2013 w/o any issues.
There isn't any issue now, but I want to avoid any before I decomission and shutdown the old DCs!!
I have setup DHCP, DNS, and moved the FSMO roles to one of the new 2022 DCs. It's been a week for DHCP and DNS and those are working perfectly. I entered the same command on this new DC for ntp, but other servers are still showing the old DC as their source when I run: w32tm /query /source
I migrated the FSMO roles today. Have I not waited long enough for it to propigate? Or is there something I'm missing. Do I need to do anything to the old DC that's been running NTP? I'm not sure if there is a decomissioning for that service or not.
comments, recommendations - all appreciated. TY.
edit: I know NTP uses port 123 UDP. I’m not sure if by default that port is allowed in/out on the Windows Firewall? I don’t remember opening anything previously.
I've installed AD DS on two new Server 2022's (now DCs!). I had notes from way back when I setup the 2008 R2's, but those were the first DCs in the forest so there wasn't any migration.
On the PDC emulator role (Server 2008 R2) I had opened Command Prompt and entered the following command:
w32tm /config /syncfromflags:manual /manualpeerlist:0.pool.ntp.org,1.pool.ntp.org,2.pool.ntp.org,3.pool.ntp.org /reliable:yes /update
This has worked since 2013 w/o any issues.
There isn't any issue now, but I want to avoid any before I decomission and shutdown the old DCs!!
I have setup DHCP, DNS, and moved the FSMO roles to one of the new 2022 DCs. It's been a week for DHCP and DNS and those are working perfectly. I entered the same command on this new DC for ntp, but other servers are still showing the old DC as their source when I run: w32tm /query /source
I migrated the FSMO roles today. Have I not waited long enough for it to propigate? Or is there something I'm missing. Do I need to do anything to the old DC that's been running NTP? I'm not sure if there is a decomissioning for that service or not.
comments, recommendations - all appreciated. TY.
edit: I know NTP uses port 123 UDP. I’m not sure if by default that port is allowed in/out on the Windows Firewall? I don’t remember opening anything previously.
Last edited: