I have a single forest, 3 DC Windows 2003 AD domain. I would have thought
that all DCs are essentially time references, with the PDC role holder being
primary for the domain. However running "dcdiag /s:nameofdc" brings up a
warning on the non-PDC role DCs that the DC is not advertising as a time
server. All other advertsing tests pass.
This is confirmed using a packet sniffer. Clients are sending udp port 123
time queries to the non-PDC role DCs, but getting no response back.
Has anyone seen this issue and know how to correct it?
....Ticking away, the moments that make up a dull (Sun)day...
|