Domain Controller Time Server Port
Le tableau suivant liste les scores attribués par le service de temps windows à chaque type de contrôleur de domaine.
Domain controller time server port. For more information about the dynamic port range change in windows server 2012 and windows server 2012 r2 see. Both udp and tcp port 135 are required for communication between domain controllers and clients to domain controllers. The domain controller then returns the required information in the form of a 64 bit value that has been authenticated with the session key from the net logon service.
This is the new dynamic port range for rpc connections. Udp port 389 for ldap network port is used to handle normal authentication queries from client computers. On the server that net time identified nettimeserver primary domain controller right click on your powershell icon and choose run as administrator.
Tcp port range 1025 5000 if your network has any server 2003 r2 or older domain controllers. If the returned ntp packet is not signed with the computer s session key or is signed incorrectly the time is rejected. Instead when a computer requests the time from a domain controller in the domain hierarchy the windows time service requires that the time be authenticated.
Tcp port range 49152 65535 if your network has any server 2008 or newer domain controllers. This command doesn t do the sync it just displays how much time your server is off. If an authoritative time server that is configured to use an announceflag value of 0x5 does not synchronize with an upstream time server a client server may not correctly synchronize with the authoritative time server when the time synchronization between the authoritative time server and the upstream time server resumes.
This is the default dynamic range for rpc connections. Windows time assigns each domain controller that is queried a score based on the reliability and location of the domain controller. All such authentication failures are logged in.
The following table lists the scores assigned by windows time to each type of domain controller. Run the following command to only check how much time your server is off from the global time authority. How to check your domain controller time against a global time provider.