Hi,
I’m another one who is struggling to make NTP (both server and client) works on my CRS326-24G-2S+ device.
NTP client:
/system/ntp/server/print
enabled: yes
broadcast: yes
multicast: yes
manycast: yes
broadcast-addresses:
use-local-clock: no
local-clock-stratum: 5
auth-key: none
NTP server:
/system/ntp/server/print
enabled: yes
broadcast: yes
multicast: yes
manycast: yes
broadcast-addresses:
use-local-clock: no
local-clock-stratum: 5
auth-key: none
Here is the output from Ubuntu trying to manually sync time from this device:
ntpdate -q 192.168.0.1
server 192.168.0.1, stratum 6, offset -0.249185, delay 0.02592
18 Jul 10:56:39 ntpdate[10106]: no server suitable for synchronization found
The most interesting part - that during device restart it’s able to provide data to the clients, but during normal operation - it doesn’t work.
Your help is very appreciated.
Whole config also attached:
/export terse
# jul/18/2022 11:03:32 by RouterOS 7.3.1
# model = CRS326-24G-2S+
/interface bridge add name=bridge1
/interface ethernet set [ find default-name=ether3 ] disabled=yes
/interface ethernet set [ find default-name=ether5 ] disabled=yes
/interface ethernet set [ find default-name=ether6 ] disabled=yes
/interface ethernet set [ find default-name=ether7 ] disabled=yes
/interface ethernet set [ find default-name=ether8 ] disabled=yes
/interface ethernet set [ find default-name=ether9 ] disabled=yes
/interface ethernet set [ find default-name=ether10 ] disabled=yes
/interface ethernet set [ find default-name=ether11 ] disabled=yes
/interface ethernet set [ find default-name=ether12 ] disabled=yes
/interface ethernet set [ find default-name=ether13 ] disabled=yes
/interface ethernet set [ find default-name=ether14 ] disabled=yes
/interface ethernet set [ find default-name=ether15 ] disabled=yes
/interface ethernet set [ find default-name=ether16 ] disabled=yes
/interface ethernet set [ find default-name=ether17 ] disabled=yes
/interface ethernet set [ find default-name=ether18 ] disabled=yes
/interface ethernet set [ find default-name=ether19 ] disabled=yes
/interface ethernet set [ find default-name=ether20 ] disabled=yes
/interface ethernet set [ find default-name=ether21 ] disabled=yes
/interface ethernet set [ find default-name=ether22 ] disabled=yes
/interface ethernet set [ find default-name=ether23 ] disabled=yes
/interface ethernet set [ find default-name=ether24 ] disabled=yes
/interface ethernet set [ find default-name=sfp-sfpplus1 ] disabled=yes
/interface ethernet set [ find default-name=sfp-sfpplus2 ] disabled=yes
/interface list add name=WAN
/interface list add name=LAN
/interface lte apn set [ find default=yes ] ip-type=ipv4 use-network-apn=no
/interface wireless security-profiles set [ find default=yes ] supplicant-identity=MikroTik
/port set 0 name=serial0
/interface bridge port add bridge=bridge1 ingress-filtering=no interface=ether2
/interface bridge port add bridge=bridge1 ingress-filtering=no interface=ether3
/interface bridge port add bridge=bridge1 ingress-filtering=no interface=ether4
/interface bridge port add bridge=bridge1 ingress-filtering=no interface=ether5
/interface bridge port add bridge=bridge1 ingress-filtering=no interface=ether6
/interface bridge port add bridge=bridge1 ingress-filtering=no interface=ether7
/interface bridge port add bridge=bridge1 ingress-filtering=no interface=ether8
/interface bridge port add bridge=bridge1 ingress-filtering=no interface=ether9
/interface bridge port add bridge=bridge1 ingress-filtering=no interface=ether10
/interface bridge port add bridge=bridge1 ingress-filtering=no interface=ether11
/interface bridge port add bridge=bridge1 ingress-filtering=no interface=ether12
/interface bridge port add bridge=bridge1 ingress-filtering=no interface=ether13
/interface bridge port add bridge=bridge1 ingress-filtering=no interface=ether14
/interface bridge port add bridge=bridge1 ingress-filtering=no interface=ether15
/interface bridge port add bridge=bridge1 ingress-filtering=no interface=ether16
/interface bridge port add bridge=bridge1 ingress-filtering=no interface=ether17
/interface bridge port add bridge=bridge1 ingress-filtering=no interface=ether18
/interface bridge port add bridge=bridge1 ingress-filtering=no interface=ether19
/interface bridge port add bridge=bridge1 ingress-filtering=no interface=ether20
/interface bridge port add bridge=bridge1 ingress-filtering=no interface=ether21
/interface bridge port add bridge=bridge1 ingress-filtering=no interface=ether22
/interface bridge port add bridge=bridge1 ingress-filtering=no interface=ether23
/interface bridge port add bridge=bridge1 ingress-filtering=no interface=ether24
/interface bridge port add bridge=bridge1 ingress-filtering=no interface=sfp-sfpplus1
/interface bridge port add bridge=bridge1 ingress-filtering=no interface=sfp-sfpplus2
/ip neighbor discovery-settings set discover-interface-list=!dynamic
/ip settings set accept-redirects=yes accept-source-route=yes max-neighbor-entries=8192
/ipv6 settings set disable-ipv6=yes
/interface list member add interface=ether1 list=WAN
/interface list member add interface=bridge1 list=LAN
/interface ovpn-server server set auth=sha1,md5
/ip address add address=XXX.XXX.XXX.30/25 interface=ether1 network=XXX.XXX.XXX.0
/ip address add address=192.168.0.1/23 interface=bridge1 network=192.168.0.0
/ip address add address=XXX.XXX.XXX.31/25 interface=ether1 network=XXX.XXX.XXX.0
/ip address add address=XXX.XXX.XXX.32/25 interface=ether1 network=XXX.XXX.XXX.0
/ip address add address=XXX.XXX.XXX.33/25 interface=ether1 network=XXX.XXX.XXX.0
/ip address add address=XXX.XXX.XXX.34/25 interface=ether1 network=XXX.XXX.XXX.0
/ip address add address=XXX.XXX.XXX.35/25 interface=ether1 network=XXX.XXX.XXX.0
/ip address add address=XXX.XXX.XXX.36/25 interface=ether1 network=XXX.XXX.XXX.0
/ip address add address=XXX.XXX.XXX.37/25 interface=ether1 network=XXX.XXX.XXX.0
/ip address add address=XXX.XXX.XXX.38/25 interface=ether1 network=XXX.XXX.XXX.0
/ip address add address=XXX.XXX.XXX.39/25 interface=ether1 network=XXX.XXX.XXX.0
/ip cloud set ddns-update-interval=30m
/ip dhcp-client add disabled=yes interface=ether1
/ip dns set servers=XXX.XXX.XXX.4,8.8.8.8
/ip firewall address-list add address=192.168.0.2-192.168.1.254 list=allowed_to_router
/ip firewall address-list add address=XX.XXX.XXX.XX list=allowed_to_router
/ip firewall address-list add address=0.0.0.0/8 comment=RFC6890 list=not_in_internet
/ip firewall address-list add address=172.16.0.0/12 comment=RFC6890 list=not_in_internet
/ip firewall address-list add address=192.168.0.0/16 comment=RFC6890 list=not_in_internet
/ip firewall address-list add address=10.0.0.0/8 comment=RFC6890 list=not_in_internet
/ip firewall address-list add address=169.254.0.0/16 comment=RFC6890 list=not_in_internet
/ip firewall address-list add address=127.0.0.0/8 comment=RFC6890 list=not_in_internet
/ip firewall address-list add address=224.0.0.0/4 comment=Multicast list=not_in_internet
/ip firewall address-list add address=198.18.0.0/15 comment=RFC6890 list=not_in_internet
/ip firewall address-list add address=192.0.0.0/24 comment=RFC6890 list=not_in_internet
/ip firewall address-list add address=192.0.2.0/24 comment=RFC6890 list=not_in_internet
/ip firewall address-list add address=198.51.100.0/24 comment=RFC6890 list=not_in_internet
/ip firewall address-list add address=203.0.113.0/24 comment=RFC6890 list=not_in_internet
/ip firewall address-list add address=100.64.0.0/10 comment=RFC6890 list=not_in_internet
/ip firewall address-list add address=240.0.0.0/4 comment=RFC6890 list=not_in_internet
/ip firewall address-list add address=192.88.99.0/24 comment="6to4 relay Anycast [RFC 3068]" list=not_in_internet
/ip firewall filter add action=accept chain=forward dst-address=0.0.0.0 src-address=192.168.0.0/23
/ip firewall filter add action=accept chain=forward comment="HTTP/S accept" dst-address=XXX.XXX.XXX.30 dst-port=80 protocol=tcp
/ip firewall filter add action=accept chain=forward dst-address=XXX.XXX.XXX.30 dst-port=443 protocol=tcp
/ip firewall filter add action=accept chain=forward dst-address=XXX.XXX.XXX.31 dst-port=80 protocol=tcp
/ip firewall filter add action=accept chain=forward dst-address=XXX.XXX.XXX.31 dst-port=443 protocol=tcp
/ip firewall filter add action=accept chain=forward dst-address=XXX.XXX.XXX.32 dst-port=80 protocol=tcp
/ip firewall filter add action=accept chain=forward dst-address=XXX.XXX.XXX.32 dst-port=443 protocol=tcp
/ip firewall filter add action=accept chain=forward dst-address=XXX.XXX.XXX.33 dst-port=80 protocol=tcp
/ip firewall filter add action=accept chain=forward dst-address=XXX.XXX.XXX.33 dst-port=443 protocol=tcp
/ip firewall filter add action=accept chain=forward dst-address=XXX.XXX.XXX.34 dst-port=80 protocol=tcp
/ip firewall filter add action=accept chain=forward dst-address=XXX.XXX.XXX.34 dst-port=443 protocol=tcp
/ip firewall filter add action=accept chain=forward dst-address=XXX.XXX.XXX.35 dst-port=80 protocol=tcp
/ip firewall filter add action=accept chain=forward dst-address=XXX.XXX.XXX.35 dst-port=443 protocol=tcp
/ip firewall filter add action=accept chain=forward dst-address=XXX.XXX.XXX.36 dst-port=80 protocol=tcp
/ip firewall filter add action=accept chain=forward dst-address=XXX.XXX.XXX.36 dst-port=443 protocol=tcp
/ip firewall filter add action=accept chain=forward dst-address=XXX.XXX.XXX.37 dst-port=80 protocol=tcp
/ip firewall filter add action=accept chain=forward dst-address=XXX.XXX.XXX.37 dst-port=443 protocol=tcp
/ip firewall filter add action=accept chain=forward dst-address=XXX.XXX.XXX.38 dst-port=80 protocol=tcp
/ip firewall filter add action=accept chain=forward dst-address=XXX.XXX.XXX.38 dst-port=443 protocol=tcp
/ip firewall filter add action=accept chain=forward dst-address=XXX.XXX.XXX.39 dst-port=80 protocol=tcp
/ip firewall filter add action=accept chain=forward dst-address=XXX.XXX.XXX.39 dst-port=443 protocol=tcp
/ip firewall filter add action=accept chain=forward comment=skbl_ext dst-address=XXX.XXX.XXX.30 dst-port=22 protocol=tcp
/ip firewall filter add action=accept chain=forward comment="Accept GRE connection to be forwarded" dst-address=XXX.XXX.XXX.30 protocol=gre
/ip firewall filter add action=accept chain=input comment="Accept PPTP connection to be forwarded" dst-address=XXX.XXX.XXX.30 dst-port=1723 protocol=tcp
/ip firewall filter add action=fasttrack-connection chain=forward comment=FastTrack connection-state=established,related hw-offload=yes
/ip firewall filter add action=accept chain=forward comment="Established, Related" connection-state=established,related
/ip firewall filter add action=drop chain=forward comment="Drop invalid" connection-state=invalid log=yes log-prefix=invalid
/ip firewall filter add action=drop chain=forward comment="Drop tries to reach not public addresses from LAN" dst-address-list=not_in_internet in-interface=bridge1 log=yes log-prefix=!public_from_LAN out-interface=!bridge1
/ip firewall filter add action=drop chain=forward comment="Drop incoming packets that are not NATted" connection-nat-state=!dstnat connection-state=new in-interface=ether1 log=yes log-prefix=!NAT
/ip firewall filter add action=drop chain=forward comment="Drop incoming from internet which is not public IP" in-interface=ether1 log=yes log-prefix=!public src-address-list=not_in_internet
/ip firewall filter add action=drop chain=forward comment="Drop packets from LAN that do not have LAN IP" in-interface=bridge1 log=yes log-prefix=LAN_!LAN src-address=!192.168.0.0/23
/ip firewall filter add action=accept chain=input comment="default configuration" connection-state=established,related
/ip firewall filter add action=accept chain=input src-address-list=allowed_to_router
/ip firewall filter add action=accept chain=input protocol=icmp
/ip firewall filter add action=drop chain=input
/ip firewall nat add action=masquerade chain=srcnat out-interface-list=WAN
/ip firewall nat add action=dst-nat chain=dstnat comment="HTTP/S 30 to 229 " dst-address=XXX.XXX.XXX.30 dst-port=80 protocol=tcp to-addresses=192.168.0.16
/ip firewall nat add action=dst-nat chain=dstnat dst-address=XXX.XXX.XXX.30 dst-port=443 protocol=tcp to-addresses=192.168.0.16
/ip firewall nat add action=dst-nat chain=dstnat dst-address=XXX.XXX.XXX.30 dst-port=22 protocol=tcp to-addresses=192.168.0.229
/ip firewall nat add action=dst-nat chain=dstnat comment="HTTP/S 33 to 30" dst-address=XXX.XXX.XXX.33 dst-port=80 protocol=tcp to-addresses=192.168.0.30
/ip firewall nat add action=dst-nat chain=dstnat dst-address=XXX.XXX.XXX.33 dst-port=443 protocol=tcp to-addresses=192.168.0.30
/ip firewall nat add action=dst-nat chain=dstnat comment="HTTP/S 34 to 10" dst-address=XXX.XXX.XXX.34 dst-port=80 protocol=tcp to-addresses=192.168.0.10
/ip firewall nat add action=dst-nat chain=dstnat dst-address=XXX.XXX.XXX.34 dst-port=443 protocol=tcp to-addresses=192.168.0.10
/ip firewall nat add action=dst-nat chain=dstnat comment="HTTP/S 37 to 218" dst-address=XXX.XXX.XXX.37 dst-port=80 protocol=tcp to-addresses=192.168.0.218
/ip firewall nat add action=dst-nat chain=dstnat dst-address=XXX.XXX.XXX.37 dst-port=443 protocol=tcp to-addresses=192.168.0.218
/ip firewall nat add action=dst-nat chain=dstnat comment="HTTP/S 38 to 216" dst-address=XXX.XXX.XXX.38 dst-port=80 protocol=tcp to-addresses=192.168.0.216
/ip firewall nat add action=dst-nat chain=dstnat dst-address=XXX.XXX.XXX.38 dst-port=443 protocol=tcp to-addresses=192.168.0.216
/ip firewall nat add action=dst-nat chain=dstnat comment="HTTP/S 39 to 15" dst-address=XXX.XXX.XXX.39 dst-port=80 protocol=tcp to-addresses=192.168.0.15
/ip firewall nat add action=dst-nat chain=dstnat dst-address=XXX.XXX.XXX.39 dst-port=443 protocol=tcp to-addresses=192.168.0.15
/ip firewall nat add action=dst-nat chain=dstnat comment="PPTP VPN" dst-address=XXX.XXX.XXX.30 dst-port=1723 port="" protocol=tcp to-addresses=192.168.0.136 to-ports=1723
/ip firewall nat add action=dst-nat chain=dstnat dst-address=XXX.XXX.XXX.30 protocol=gre to-addresses=192.168.0.136
/ip firewall service-port set ftp disabled=yes
/ip firewall service-port set tftp disabled=yes
/ip firewall service-port set irc disabled=yes
/ip firewall service-port set h323 disabled=yes
/ip firewall service-port set sip disabled=yes
/ip firewall service-port set pptp disabled=yes
/ip firewall service-port set udplite disabled=yes
/ip firewall service-port set dccp disabled=yes
/ip firewall service-port set sctp disabled=yes
/ip route add disabled=no dst-address=0.0.0.0/0 gateway=XXX.XXX.XXX.1
/ip service set telnet disabled=yes
/ip service set ftp disabled=yes
/ip service set www disabled=yes
/ip service set ssh disabled=yes port=2202
/ip service set api disabled=yes
/ip service set api-ssl disabled=yes
/system clock set time-zone-name=Europe/Moscow
/system identity set name=gw1.domain.local
/system ntp client set enabled=yes mode=broadcast
/system ntp server set broadcast=yes enabled=yes manycast=yes multicast=yes
/system ntp client servers add address=194.190.168.1
/system routerboard settings set boot-os=router-os