Symptoms
- NTP or PTP clients do not synchronize across a firewall or between network segments
- WinDiscovery or management tools can see a device locally, but not from other subnets
- Time services work on one side of the network, but fail on the other
Causes
- Incorrect client or server configuration
- Network reachability or routing differences
- Traffic blocked by firewall rules
- Firewall or security policy changes blocking time synchronization traffic (even if the device configuration did not change)
- VLAN, routing, or ACL changes preventing traffic between subnets
- UDP traffic permitted for some hosts but not others due to network policy
Suggested solutions or troubleshooting steps
- Confirm the required ports and protocols are allowed.
NTP uses UDP port 123. Other discovery or management tools may require additional ports. Ensure rules allow traffic in both directions where applicable. - Test reachability from the client network segment.
Verify the client can reach the device IP from the same network path the time traffic will use. A test that works only on the local subnet may not represent cross-network behavior. - Check for recent network security changes.
If the system worked previously and stopped suddenly, review recent firewall, VLAN, or ACL updates. Timing traffic is often blocked unintentionally during security hardening. - Validate client configuration.
Confirm clients are pointed to the correct server IP or hostname and are using the intended protocol (NTP or PTP).
Details
This topic commonly comes up during configuration, verification, or troubleshooting. Understanding what this behavior or setting represents helps distinguish between normal operation and an actual fault.
Article ID: KB-NET-002
KB Version: