Firewall UDP 123 checklist when NTP clients will not sync

Many “timing failures” are network policy, not GNSS. Verify UDP 123 and ACLs before swapping antennas.

Between client and server, confirm UDP 123 is allowed (client requests and server replies) via packet capture or firewall logs.

Segment the path: same L2 switch first, then cross-VLAN ACLs, then whether only a management VRF may reach the timing port.

If the server NTP source allowlist is on, clients not listed often time out or never sync.

Confirm the server is LOCKed and serving NTP on the Web UI; warm-up policy may briefly advertise Stratum 2.

Only after the network path is clean, read offset with chrony/ntpd. If still wrong, check switch load and client stacks before blaming the GNSS antenna.

Guides · Contact