NTP Fails to Synchronize with condition Reject
search cancel

NTP Fails to Synchronize with condition Reject

book

Article ID: 415046

calendar_today

Updated On:

Products

VMware vSphere ESXi

Issue/Introduction

ESXi host fails to sync with NTP server.

A packet trace doesn't show any NTP traffic being put on the wire from the ESXi host. 

ntpq -c associations reports a condition of reject:

[root@esxihost:~] ntpq -c associations
ind assid status  conf reach auth condition  last_event cnt
===========================================================
  1 46550  8011   yes    no  none    reject    mobilize  1
 

Environment

ESXi 

Cause

The host is running in an unsupported configuration where multiple vmk adapters are configured on the same subnet and the default gateway is tied to the wrong vmk adapter.

[root@esxihost:~] esxcfg-vmknic -l
  Interface  Port Group/DVPort/Opaque Network        IP Family IP Address                              Netmask                Broadcast          MAC Address         
  vmk0       Management Network                               IPv4         X.X.1.10                                  255.255.255.0        X.X.1.255           xx:xx:xx:xx             
  vmk1       vMotion                                                      IPv4         X.X.1.11                                  255.255.255.0        X.X.1.255           xx:xx:xx:xx               

[root@esxihost:~] esxcfg-route -l

 Network     Netmask        Gateway     Details about the destination                                         Interface  Details about the vmk port
X.X.X.10   255.255.255.0  Local                                                                                                Subnet
X.X.X.11   255.255.255.0  Local                                                                                                Subnet
default     0.0.0.0               XX.XX.1.1                                                                                         vmk1       Port_Group=vMotion --> MTU=1500

Resolution

Change your configuration to have only a single vmk on a subnet, and be sure the default gateway is assigned to the vmk0 interface. 

Once the default gateway is using vmk0 NTP will connect. 

Additional Information

https://knowledge.broadcom.com/external/article?articleId=318546 - Explains that having two vmk adapters on the same subnet is an unsupported configuration with few exceptions. 

Japanese KB: NTP が condition Reject で同期に失敗する