📖 ~1 min read

Table of contents
  1. Symptom & Impact
  2. Environment & Reproduction
  3. Root Cause Analysis
  4. Quick Triage
  5. Step-by-Step Diagnosis
  6. Solution – Primary Fix
  7. Solution – Alternative Approaches
  8. Verification & Acceptance Criteria
  9. Rollback Plan
  10. Prevention & Hardening
  11. Related Errors & Cross-Refs
  12. References & Further Reading

Symptom & Impact

System clock drifts, causing TLS failures, log skew, and scheduled job misfires.

Environment & Reproduction

Ubuntu 24.04 servers in restricted networks where outbound UDP 123 is filtered.

Root Cause Analysis

chronyd cannot reach configured sources, so stratum never converges to synchronized state.

Quick Triage

Check chrony tracking and source reachability counters immediately.

chronyc tracking; chronyc sources -v

Step-by-Step Diagnosis

Inspect firewall policy and packet path while probing NTP servers from host.

sudo ufw status numbered; sudo tcpdump -ni any udp port 123 -c 20
Illustrative mockup for ubuntu-24-04-lts — chrony_firewall_problem
chrony sources unreachable due to blocked NTP traffic — Illustrative mockup — Progressive Robot

Solution – Primary Fix

Allow UDP 123 to approved NTP servers and restart chrony service.

Still having issues? Our IT Solutions & Services team can diagnose and resolve this for you. Get in touch for a free consultation.

sudo ufw allow out 123/udp && sudo systemctl restart chrony
Illustrative mockup for ubuntu-24-04-lts — chrony_firewall_fix_success
NTP allowed and chrony synchronized — Illustrative mockup — Progressive Robot

Solution – Alternative Approaches

Use internal enterprise NTP relay and restrict direct internet time egress.

Verification & Acceptance Criteria

chronyc tracking reports synchronized and offset remains within operational tolerance.

Rollback Plan

Remove temporary firewall changes and rebind to internal time source if required.

Prevention & Hardening

Monitor time offset and enforce consistent NTP policy across server fleets.

Related to certificate validity errors and Kerberos auth failures from clock skew.

Related tutorial: View the step-by-step tutorial for Ubuntu 24.04 LTS.

View all Ubuntu 24.04 LTS tutorials on the Tutorials Hub →

Browse all common problems & solutions on the Tutorials Hub.

References & Further Reading

chrony documentation and Ubuntu time synchronization best practices.

Need Expert Help?

If you cannot resolve this yourself, our team offers hands-on Server Management, Managed IT Services, and flexible Support Plans. Contact us today — we respond within one business day.