linux配置ntp服务器的方法
<p><img title="linux配置ntp服务器的方法" alt="linux配置ntp服务器的方法" src="https://zhuji.jb51.net/uploads/img/202305/de45261058e0cfaf21356e8cf2d8839a.jpg"></p>
<p>
<span><strong>一.安装ntp软件</strong></span></p>
<p>
<strong>1.检查是否安装了ntp相关包。</strong><br>
rpm -qa | grep ntp</p>
<p>
<strong>2.安装ntp软件。</strong><br>
yum -y install ntp</p>
<p>
<span><strong>二.参数讲解</strong></span></p>
<p>
ignore :关闭所有的 NTP 联机服务</p>
<p>
nomodify:客户端不能更改服务端的时间参数,但是客户端可以通过服务端进行网络校时。</p>
<p>
notrust :客户端除非通过认证,否则该客户端来源将被视为不信任子网</p>
<p>
noquery :不提供客户端的时间查询:用户端不能使用ntpq,ntpc等命令来查询ntp服务器</p>
<p>
notrap :不提供trap远端登陆:拒绝为匹配的主机提供模式 6 控制消息陷阱服务。陷阱服务是 ntpdq 控制消息协议的子系统,用于远程事件日志记录程序。</p>
<p>
nopeer :用于阻止主机尝试与服务器对等,并允许欺诈性服务器控制时钟</p>
<p>
kod : 访问违规时发送 KoD 包。</p>
<p>
<span><strong>三.修改配置文件</strong></span></p>
<p>
<strong>1.查看未修改的配置文件</strong></p>
<div class="jb51code">
<div>
<div class="syntaxhighlighterxhtml" id="highlighter_140587">
<div class="toolbar">
<span>?</span>
</div>
<table border="0" cellpadding="0" cellspacing="0"><tbody><tr>
<td class="gutter">
<div class="line number1 index0 alt2">
1</div>
<div class="line number2 index1 alt1">
2</div>
<div class="line number3 index2 alt2">
3</div>
<div class="line number4 index3 alt1">
4</div>
<div class="line number5 index4 alt2">
5</div>
<div class="line number6 index5 alt1">
6</div>
<div class="line number7 index6 alt2">
7</div>
<div class="line number8 index7 alt1">
8</div>
<div class="line number9 index8 alt2">
9</div>
<div class="line number10 index9 alt1">
10</div>
<div class="line number11 index10 alt2">
11</div>
<div class="line number12 index11 alt1">
12</div>
</td>
<td class="code">
<div class="container">
<div class="line number1 index0 alt2">
<code class="xhtml plain"># grep ^[^#] /etc/ntp.conf </code>
</div>
<div class="line number2 index1 alt1">
<code class="xhtml plain">driftfile /var/lib/ntp/drift</code>
</div>
<div class="line number3 index2 alt2">
<code class="xhtml plain">restrict default nomodify notrap nopeer noquery</code>
</div>
<div class="line number4 index3 alt1">
<code class="xhtml plain">restrict 127.0.0.1</code>
</div>
<div class="line number5 index4 alt2">
<code class="xhtml plain">restrict ::1</code>
</div>
<div class="line number6 index5 alt1">
<code class="xhtml plain">server 0.centos.pool.ntp.org iburst</code>
</div>
<div class="line number7 index6 alt2">
<code class="xhtml plain">server 1.centos.pool.ntp.org iburst</code>
</div>
<div class="line number8 index7 alt1">
<code class="xhtml plain">server 2.centos.pool.ntp.org iburst</code>
</div>
<div class="line number9 index8 alt2">
<code class="xhtml plain">server 3.centos.pool.ntp.org iburst</code>
</div>
<div class="line number10 index9 alt1">
<code class="xhtml plain">includefile /etc/ntp/crypto/pw</code>
</div>
<div class="line number11 index10 alt2">
<code class="xhtml plain">keys /etc/ntp/keys</code>
</div>
<div class="line number12 index11 alt1">
<code class="xhtml plain">disable monitor</code>
</div>
</div>
</td>
</tr></tbody></table>
</div>
</div>
<div class="codetool" id="codetool">
<div class="code_n">
<textarea></textarea>
</div>
</div>
</div>
<p>
1.设置允许任何IP的客户机都可以进行时间同步(修改后的配置文件)</p>
<div class="jb51code">
<div>
<div class="syntaxhighlighterxhtml" id="highlighter_477294">
<div class="toolbar">
<span>?</span>
</div>
<table border="0" cellpadding="0" cellspacing="0"><tbody><tr>
<td class="gutter">
<div class="line number1 index0 alt2">
1</div>
<div class="line number2 index1 alt1">
2</div>
<div class="line number3 index2 alt2">
3</div>
<div class="line number4 index3 alt1">
4</div>
<div class="line number5 index4 alt2">
5</div>
<div class="line number6 index5 alt1">
6</div>
<div class="line number7 index6 alt2">
7</div>
<div class="line number8 index7 alt1">
8</div>
<div class="line number9 index8 alt2">
9</div>
<div class="line number10 index9 alt1">
10</div>
<div class="line number11 index10 alt2">
11</div>
<div class="line number12 index11 alt1">
12</div>
</td>
<td class="code">
<div class="container">
<div class="line number1 index0 alt2">
<code class="xhtml plain"># grep ^[^#] /etc/ntp.conf </code>
</div>
<div class="line number2 index1 alt1">
<code class="xhtml plain">driftfile /var/lib/ntp/drift</code>
</div>
<div class="line number3 index2 alt2">
<code class="xhtml plain">restrict default nomodify notrap</code>
</div>
<div class="line number4 index3 alt1">
<code class="xhtml plain">restrict 127.0.0.1</code>
</div>
<div class="line number5 index4 alt2">
<code class="xhtml plain">restrict ::1</code>
</div>
<div class="line number6 index5 alt1">
<code class="xhtml plain">server 0.centos.pool.ntp.org iburst</code>
</div>
<div class="line number7 index6 alt2">
<code class="xhtml plain">server 1.centos.pool.ntp.org iburst</code>
</div>
<div class="line number8 index7 alt1">
<code class="xhtml plain">server 2.centos.pool.ntp.org iburst</code>
</div>
<div class="line number9 index8 alt2">
<code class="xhtml plain">server 3.centos.pool.ntp.org iburst</code>
</div>
<div class="line number10 index9 alt1">
<code class="xhtml plain">includefile /etc/ntp/crypto/pw</code>
</div>
<div class="line number11 index10 alt2">
<code class="xhtml plain">keys /etc/ntp/keys</code>
</div>
<div class="line number12 index11 alt1">
<code class="xhtml plain">disable monitor</code>
</div>
</div>
</td>
</tr></tbody></table>
</div>
</div>
<div class="codetool" id="codetool">
<div class="code_n">
<textarea></textarea>
</div>
</div>
</div>
<p>
2.只允许192.168.1.0网段的客户机进行时间同步(修改后的配置文件)</p>
<div class="jb51code">
<div>
<div class="syntaxhighlighterxhtml" id="highlighter_655097">
<div class="toolbar">
<span>?</span>
</div>
<table border="0" cellpadding="0" cellspacing="0"><tbody><tr>
<td class="gutter">
<div class="line number1 index0 alt2">
1</div>
<div class="line number2 index1 alt1">
2</div>
<div class="line number3 index2 alt2">
3</div>
<div class="line number4 index3 alt1">
4</div>
<div class="line number5 index4 alt2">
5</div>
<div class="line number6 index5 alt1">
6</div>
<div class="line number7 index6 alt2">
7</div>
<div class="line number8 index7 alt1">
8</div>
<div class="line number9 index8 alt2">
9</div>
<div class="line number10 index9 alt1">
10</div>
<div class="line number11 index10 alt2">
11</div>
<div class="line number12 index11 alt1">
12</div>
<div class="line number13 index12 alt2">
13</div>
</td>
<td class="code">
<div class="container">
<div class="line number1 index0 alt2">
<code class="xhtml plain"># grep ^[^#] /etc/ntp.conf </code>
</div>
<div class="line number2 index1 alt1">
<code class="xhtml plain">driftfile /var/lib/ntp/drift</code>
</div>
<div class="line number3 index2 alt2">
<code class="xhtml plain">restrict default nomodify notrap nopeer noquery</code>
</div>
<div class="line number4 index3 alt1">
<code class="xhtml plain">restrict 127.0.0.1</code>
</div>
<div class="line number5 index4 alt2">
<code class="xhtml plain">restrict ::1</code>
</div>
<div class="line number6 index5 alt1">
<code class="xhtml plain">restrict 192.168.1.0 mask 255.255.255.0 nomodify notrap</code>
</div>
<div class="line number7 index6 alt2">
<code class="xhtml plain">server 0.centos.pool.ntp.org iburst</code>
</div>
<div class="line number8 index7 alt1">
<code class="xhtml plain">server 1.centos.pool.ntp.org iburst</code>
</div>
<div class="line number9 index8 alt2">
<code class="xhtml plain">server 2.centos.ntp.org iburst</code>
</div>
<div class="line number10 index9 alt1">
<code class="xhtml plain">server 3.centos.pool.ntp.org iburst</code>
</div>
<div class="line number11 index10 alt2">
<code class="xhtml plain">includefile /etc/ntp/crypto/pw</code>
</div>
<div class="line number12 index11 alt1">
<code class="xhtml plain">keys /etc/ntp/keys</code>
</div>
<div class="line number13 index12 alt2">
<code class="xhtml plain">disable monitor</code>
</div>
</div>
</td>
</tr></tbody></table>
</div>
</div>
<div class="codetool" id="codetool">
<div class="code_n">
<textarea></textarea>
</div>
</div>
</div>
<p>
<span><strong>四.启动NTP服务和防火墙</strong></span></p>
<p>
systemctl start ntpd<br>
systemctl enable ntpd<br>
iptables -A INPUT -p UDP -i eno16777736 -s 192.168.1.0/24 --dport 123 -j ACCEPT<br>
setsebool -P ntp_disable_trans 1#SELinux设置<br>
vi /etc/sysconfig/ntpd#允许BIOS与系统时间同步,添加下面一行。<br>
SYNC_HWCLOCK=yes</p>
<p>
<span><strong>五.检测NTP</strong></span></p>
<p>
<strong>1.检测NTP服务是否运行</strong></p>
<div class="jb51code">
<div>
<div class="syntaxhighlighterxhtml" id="highlighter_871916">
<div class="toolbar">
<span>?</span>
</div>
<table border="0" cellpadding="0" cellspacing="0"><tbody><tr>
<td class="gutter">
<div class="line number1 index0 alt2">
1</div>
<div class="line number2 index1 alt1">
2</div>
<div class="line number3 index2 alt2">
3</div>
<div class="line number4 index3 alt1">
4</div>
<div class="line number5 index4 alt2">
5</div>
<div class="line number6 index5 alt1">
6</div>
<div class="line number7 index6 alt2">
7</div>
</td>
<td class="code">
<div class="container">
<div class="line number1 index0 alt2">
<code class="xhtml plain"># netstat -tlunp | grep ntp</code>
</div>
<div class="line number2 index1 alt1">
<code class="xhtml plain">udp 0 0 192.168.1.101:123 0.0.0.0:* 2563/ntpd </code>
</div>
<div class="line number3 index2 alt2">
<code class="xhtml plain">udp 0 0 127.0.0.1:123 0.0.0.0:* 2563/ntpd </code>
</div>
<div class="line number4 index3 alt1">
<code class="xhtml plain">udp 0 0 0.0.0.0:123 0.0.0.0:* 2563/ntpd </code>
</div>
<div class="line number5 index4 alt2">
<code class="xhtml plain">udp6 0 0 fe80::20c:29ff:fe7b:123 :::* 2563/ntpd </code>
</div>
<div class="line number6 index5 alt1">
<code class="xhtml plain">udp6 0 0 ::1:123 :::* 2563/ntpd </code>
</div>
<div class="line number7 index6 alt2">
<code class="xhtml plain">udp6 0 0 :::123 :::* 2563/ntpd </code>
</div>
</div>
</td>
</tr></tbody></table>
</div>
</div>
<div class="codetool" id="codetool">
<div class="code_n">
<textarea></textarea>
</div>
</div>
</div>
<p>
<strong>2.查看ntp服务器有无和上层ntp连通</strong></p>
<div class="jb51code">
<div>
<div class="syntaxhighlighterxhtml" id="highlighter_166722">
<div class="toolbar">
<span>?</span>
</div>
<table border="0" cellpadding="0" cellspacing="0"><tbody><tr>
<td class="gutter">
<div class="line number1 index0 alt2">
1</div>
<div class="line number2 index1 alt1">
2</div>
<div class="line number3 index2 alt2">
3</div>
<div class="line number4 index3 alt1">
4</div>
</td>
<td class="code">
<div class="container">
<div class="line number1 index0 alt2">
<code class="xhtml plain"># ntpstat</code>
</div>
<div class="line number2 index1 alt1">
<code class="xhtml plain">synchronised to NTP server (120.25.108.11) at stratum 3</code>
</div>
<div class="line number3 index2 alt2">
<code class="xhtml spaces"> </code><code class="xhtml plain">time correct to within 99 ms</code>
</div>
<div class="line number4 index3 alt1">
<code class="xhtml spaces"> </code><code class="xhtml plain">polling server every 64 s</code>
</div>
</div>
</td>
</tr></tbody></table>
</div>
</div>
<div class="codetool" id="codetool">
<div class="code_n">
<textarea></textarea>
</div>
</div>
</div>
<p>
<strong>3.查看ntp服务器与上层ntp的状态</strong></p>
<div class="jb51code">
<div>
<div class="syntaxhighlighterxhtml" id="highlighter_582001">
<div class="toolbar">
<span>?</span>
</div>
<table border="0" cellpadding="0" cellspacing="0"><tbody><tr>
<td class="gutter">
<div class="line number1 index0 alt2">
1</div>
<div class="line number2 index1 alt1">
2</div>
<div class="line number3 index2 alt2">
3</div>
<div class="line number4 index3 alt1">
4</div>
<div class="line number5 index4 alt2">
5</div>
<div class="line number6 index5 alt1">
6</div>
<div class="line number7 index6 alt2">
7</div>
<div class="line number8 index7 alt1">
8</div>
<div class="line number9 index8 alt2">
9</div>
<div class="line number10 index9 alt1">
10</div>
<div class="line number11 index10 alt2">
11</div>
<div class="line number12 index11 alt1">
12</div>
<div class="line number13 index12 alt2">
13</div>
<div class="line number14 index13 alt1">
14</div>
<div class="line number15 index14 alt2">
15</div>
</td>
<td class="code">
<div class="container">
<div class="line number1 index0 alt2">
<code class="xhtml plain"># ntpq -p</code>
</div>
<div class="line number2 index1 alt1">
<code class="xhtml spaces"> </code><code class="xhtml plain">remote refid st t when poll reach delay offset jitter</code>
</div>
<div class="line number3 index2 alt2">
<code class="xhtml plain">==============================================================================</code>
</div>
<div class="line number4 index3 alt1">
<code class="xhtml spaces"> </code><code class="xhtml plain">news.neu.edu.cn .INIT. 16 u - 64 0 0.000 0.000 0.000</code>
</div>
<div class="line number5 index4 alt2">
<code class="xhtml plain">x202.118.1.130 202.118.1.47 2 u 7 64 377 153.659 9.605 19.941</code>
</div>
<div class="line number6 index5 alt1">
<code class="xhtml plain">*time4.aliyun.co 10.137.38.86 2 u 10 64 377 39.666 -47.661 15.944</code>
</div>
<div class="line number7 index6 alt2">
<code class="xhtml plain">remote - 本机和上层ntp的ip或主机名,“+”表示优先,“*”表示次优先</code>
</div>
<div class="line number8 index7 alt1">
<code class="xhtml plain">refid - 参考上一层ntp主机地址</code>
</div>
<div class="line number9 index8 alt2">
<code class="xhtml plain">st - stratum阶层</code>
</div>
<div class="line number10 index9 alt1">
<code class="xhtml plain">when - 多少秒前曾经同步过时间</code>
</div>
<div class="line number11 index10 alt2">
<code class="xhtml plain">poll - 下次更新在多少秒后</code>
</div>
<div class="line number12 index11 alt1">
<code class="xhtml plain">reach - 已经向上层ntp服务器要求更新的次数</code>
</div>
<div class="line number13 index12 alt2">
<code class="xhtml plain">delay - 网络延迟</code>
</div>
<div class="line number14 index13 alt1">
<code class="xhtml plain">offset - 时间补偿</code>
</div>
<div class="line number15 index14 alt2">
<code class="xhtml plain">jitter - 系统时间与bios时间差</code>
</div>
</div>
</td>
</tr></tbody></table>
</div>
</div>
<div class="codetool" id="codetool">
<div class="code_n">
<textarea></textarea>
</div>
</div>
</div>
<p>
<span><strong>六.配置时间同步客户机</strong></span></p>
<p>
<strong>1.执行ntpdate命令:</strong></p>
<p>
ntpdate 192.168.1.101 #192.168.1.101为ntp服务器IP地址</p>
<p>
<strong>2.写入BIOS</strong></p>
<p>
hclock -w</p>
<p>
<strong>3.crond服务</strong></p>
<p>
vi /etc/crontab<br>
30 8 * * * root /usr/sbin/ntpdate 192.168.1.101; /sbin/hwclock -w</p>
<p>
<strong>4.重启crond服务</strong></p>
<p>
service crond restart</p>
<p>
以上就是小编为大家带来的linux配置ntp服务器的方法全部内容了,希望大家多多支持~</p>
頁:
[1]