This is topic Managed switch that can act as an NTP server? in forum Digital Cinema Forum at Film-Tech Forum ARCHIVE.
To visit this topic, use this URL:
https://ft-forum.com/ft/cgi-bin/ubb/ultimatebb.cgi?ubb=get_topic;f=16;t=003276
Posted by Leo Enticknap (Member # 534) on 04-01-2018, 11:28 AM:
I've now hit the same problem at several sites, mainly single screen arthouse type places that don't have a TMS or a connection to the Internet, and therefore no source for the DCP sever to get an NTP sync from. The issue lies dormant for years, until eentually the media block's clock drifts so far that it causes a problem with KDM windows.
At sites where we install a remote access PC, the Windows time service can be used, which solves the problem. But in booths that don't have them, the problem remains.
Looking around the Internet, the only immediately obvious solution is a GPS-based dedicated NTP server, for which you won't get much change out of a grand. I was wondering if anyone knew of any model of managed switch that could provide an NTP time to the devices connected to it? Of course, if the switch itself has no Internet connection, the owner would need to keep checking and correcting its own clock manually, but if they did that often enough for the server to be getting a time from it that was within the DCI budget, this would potentially be a solution. I can't find any model specs online that specifically lists this feature, but wondered if anyone here knew of any models.
Posted by Mark Gulbrandsen (Member # 72) on 04-01-2018, 12:01 PM:
No switches that will do that I am aware of... and you'd still have to have internet or some very stable clock to sync it to. Thats why GPS is so much more effective when you lack anything else. Its actually very easy, and if you search Epay you can do it very reasonably ~$300.00. Get an NTP Clock from Spectracom or similar and hang that on the main switch. I have one six screen site that had no TMS or internet (which is nuts IMHO), and thats what I ended up doing. BTW: If you need absolute GMT time you can get a local clock that receives and locks on to the Atomic clock in the GPS satellites, or you can get one with a plain old crystal refrence clock. I have two Datum GPS receivers here at home that sync up everything to GPS.
Spectracom NTP Clocks
NTP Time Servers
Posted by Steve Guttag (Member # 268) on 04-01-2018, 01:53 PM:
Leo...it isn't enough that there is a clock that the server can sync off of. If that source doesn't show that its time is good, the server should disregard the time.
Furthermore, the NTP logs of the device should let one know what Stratum they are (how far away from the reference) with a Stratum 1 typically a master reference like NIST. So even if you have a PC doing the work via the internet, at best, the PC would identify as Stratum 2.
But if there is no actual reference, then the thing that is using it as a reference will know that it is a non-referenced time.
Note too, most servers rely on their secure clock's precision to keep time for the security manager and what the NTP reference is for is for a show clock, not the secure clock. Most have a means of manually adjusting the secure clock up to +/- 6 minutes a year. Most will reference the secure clock time, absent NTP. The only secure clock that I know that is less than worthless is the CAT745 clock. If it is without power, it will drift fast, rather rapidly. With power, it isn't too bad but who wants to run their projectors 24/7? GDC often isn't right but one can also adjust it but even when right it will start shows about 10 seconds late. And Doremi...who knows when/what shows it starts? It is a mystery up until it does it
Posted by Mark Gulbrandsen (Member # 72) on 04-01-2018, 02:28 PM:
quote: Steve Guttag
GDC often isn't right but one can also adjust it but even when right it will start shows about 10 seconds late.
No issues like that here. They pretty much start right on the button if they get NTP. Almost all the places I service use the TMS scheduler.
Mark
Posted by Scott Norwood (Member # 30) on 04-01-2018, 04:28 PM:
Some Cisco switches (the real IOS-based ones, not the "Cisco Small Business" ones) can be configured to do this. It isn't really a good idea, though, since they generally don't have any sort of internal timekeeping device. You really don't want to see the price on these switches, anyway.
If you don't have Internet access at a particular site, a GPS-based NTP appliance is probably the best option and likely cheaper than the difference between whatever switches you would normally buy and enterprise-grade gear.
Posted by Steve Guttag (Member # 268) on 04-01-2018, 06:20 PM:
Sorry Mark, it isn't opinion (on the GDC time), it's fact. Furthermore, they seem to only sync their clocks AT SHOW START.
Posted by Leo Enticknap (Member # 534) on 04-01-2018, 11:56 PM:
quote: Scott Norwood
If you don't have Internet access at a particular site, a GPS-based NTP appliance is probably the best option and likely cheaper than the difference between whatever switches you would normally buy and enterprise-grade gear.
Many thanks, Scott (and everyone) - that is the conclusion I was heading towards after reading yours, Mark's and Steve's replies. So it looks like the solution is high three figures (in hardware cost) rather than low three figures, but at least I know what I have to offer the next time I come up against this situation.
Steve - I'd guess that Stratum 2 is allowable for DCI purposes, because we regularly install remote access PCs running Windows, that sit in the booth to enable us to Teamviewer in as a first line support mechanism for operational problems. Typically, the screen servers get their NTP sync from the TMS, and the TMS gets its from the remote access PC's Windows time service. This arrangement works, as long as the remote access PC doesn't lose its Internet connection for any significant length of time.
quote: Steve Guttag
he only secure clock that I know that is less than worthless is the CAT745 clock. If it is without power, it will drift fast, rather rapidly.
Amen to that. This bit me in the rear somewhat spectacularly recently, when the DSL200 TMS in an 11-plex I look after crapped out (RAID controller card died). Their normal operating routine was to shut down the individual screen servers (DSS220/cat745) overnight, and has been since they were installed several years ago: so for the last few years, those IMBs have spent around 12 hours out of every 24 without power, and their clocks being maintained on battery power. If a screen server receives a valid NTP time from 192.168.241.2 (the TMS, on the theatre network) on bootup, all is good. But if it can't, it falls back to using the cat745's secure clock. They had all drifted forward around two hours by the time the TMS went down. So, when that happened in the middle of one night, the first they knew they had a problem was when the next day's shows started about two hours before they should have done, because the cat745 clocks were now being used for scheduling purposes as well. Uh oh...
Posted by Steve Guttag (Member # 268) on 04-02-2018, 06:48 AM:
The server doesn't care if it is stratum 2. What it does care about is how many hops there are to the NTP source. I think it is something like 15 hops. You can be on stratum 6 (or higher), but you can't be 16 hops away to get to stratum 6. Generally, it is easier to get to a local NTP server so it is preferred.
Posted by Mark Gulbrandsen (Member # 72) on 04-02-2018, 11:38 AM:
quote: Steve Guttag
Sorry Mark, it isn't opinion (on the GDC time), it's fact. Furthermore, they seem to only sync their clocks AT SHOW START.
Steve...
Must be an east coast thing. I don't see that happen out here.
Mark
Posted by Steve Guttag (Member # 268) on 04-02-2018, 01:13 PM:
You just don't pay attention.
Posted by Mark Gulbrandsen (Member # 72) on 04-02-2018, 06:10 PM:
Actually I check on on my customers quite often.
Posted by Gary Benn (Member # 7858) on 04-24-2018, 04:59 AM:
Why not just set the clock manually every 3 or 6 months. It' can't be drifting that much! We've never had NTP on our Doremi servers. Never drifts by more than 30 seconds in a year.
Posted by Carsten Kurz (Member # 5396) on 04-24-2018, 05:07 AM:
There are some secure clocks (specifically the Dolby CAT745) drifting way more than that. Yeah, you could simply make it the managers duty to go around every server weekly or monthly to adjust times. But, sooner or later, they freak out at you.
- Carsten
Posted by Gary Benn (Member # 7858) on 04-24-2018, 05:22 AM:
What a great advert for Dolby!
Posted by Carsten Kurz (Member # 5396) on 04-24-2018, 05:51 AM:
Well, as it seems, the CAT745 has not been designed by Dolby ;-)
But Dolby show clock and secure clock time reference issues were in fact notorious for a long time, it has only improved lately.
That said - a collegue recently reported issues with their ATMOS installation dropping out of ATMOS regularly for unknown reasons. After analyzing the log files, the techs found out that the CP850 clock deviated more than 23 hours.
The trouble is, in most cinemas, no one wants the equipment to have any internet connections at all for security reasons. Most DCI servers run on stable Linux operating systems, but these are not patched regularly, neither do they run virus protection software. So, no one want's them to be exposed. But the easiest way to have a common time is to dial into an outside NTP server. If you don't want that, you need to setup your own internal time server.
The problem is, time servers are usually built to supply very accurate time, and yre built in low quantities for high profile applications, thus are very expensive. Where as in a cinema, the supplied time does not need to be overly accurate ( down to a few seconds would do). But there is no market for cheap, low cost, decently inaccurate time servers.
It is very easy to build your own time server from a cheap GPS receiver, but these need an external wire run for the antenna on a roof. Radio controlled clocks are another option. Seems a prominent solution is to have a dedicated PC running all the time, relaying external NTP.
- Carsten
Posted by Mark Gulbrandsen (Member # 72) on 04-25-2018, 10:26 PM:
quote: Carsten Kurz
The trouble is, in most cinemas, no one wants the equipment to have any internet connections at all for security reasons.
Don't your multiplex cinemas have a Windoez based TMS? If so they already have the time server and connection wires that are needed. The fact that the servers run on Linux is irrelevant. The Linux based device is just wanting a standard protocol time signal which the Windoez based TMS can easily put out. All but two of my customers have a TMS or a booth computer that is connected to the net and used for remote access by the theater owner in many cases to do scheduling and content transfer without having to go to the actual work place. If the TMS is net connected via a VPN then it is quite safe from hackers.
Mark
Posted by Marcel Birgelen (Member # 6801) on 04-26-2018, 01:48 AM:
Usually, it should not be a problem to open a network for NTP clients to the Internet without causing any security issues, as long as you know what you're doing. So, instead of having a local NTP server that could run haywire, I'd rather let those machines connect to a public NTP pool. We're talking about simple show scheduling applications, so we don't need time that's accurate to the nanosecond anyway. The chance of a whole pool failing is pretty neglectable. Also, if the Internet connection fails, I can reasonably assume it will sufficiently annoy the day to day operations, somebody will eventually manage to repair it.
But we're a bunch of engineers, aren't we? If we need an NTP server, we build one ourselves.
It's a rather old guide, but the basics are still sound. So, if you're stuck at a location without a stable Internet connection, this kind of device is a good alternative to the "professional" stratum 1 servers, which easily sell for a few thousand dollars.
Posted by Carsten Kurz (Member # 5396) on 04-26-2018, 05:05 AM:
With a TMS, no problem. There are many sites, of course, without a TMS. I know many sites that do not even have a general purpose computer connected to the projection system, projectors/servers are operated fully manual. Some of them still need a decent accurate time.
I myself have no problem to allow NTP on a standard router. But some people do.
- Carsten
Posted by Mark Gulbrandsen (Member # 72) on 04-26-2018, 10:04 AM:
quote: Carsten Kurz
I myself have no problem to allow NTP on a standard router. But some people do.
Those people probably have no buisness running a theater then... Why on earth would they worry about NTP? Thats just silly...
Mark
Posted by Marcel Birgelen (Member # 6801) on 04-26-2018, 11:50 AM:
Well, NTP isn't entirely without issues. It's a pretty old protocol and you should be sure not to open up your network to random NTP traffic from unknown sources.
NTP has been used in amplification DDoS attacks and if you've got an NTP server on your network that's vulnerable and is reachable over the Internet, it can lead to serious impact, both on your internet connectivity and on your local network. Also, some ISPs might actually cut or severely limit your Internet connection in such a situation, because you're essentially participating in a "zombie network".
Also, some NTP implementations are notoriously hard to configure as a client-only device and they'll run as an NTP server for the public as a "bonus".
So, nothing wrong with allowing NTP from inside to outside your network, but make sure the other side around is closed or else stuff might just someday start to fall apart.
Posted by Mark Gulbrandsen (Member # 72) on 04-26-2018, 07:44 PM:
It works just fine for me. All but several customers are using it and everyones servers are on time except the several that are not getting it. A certain brand of server may have to have very specific settings in order for it to work, this is true of GDC. But they supply the complete set up schemeyou need to use.
Mark
Powered by Infopop Corporation
UBB.classicTM
6.3.1.2