The 911 center's GPS NTP clock fails. Within hours, Workspace ONE Access tokens, TLS certificates on NSX-T Manager, and identity-firewall time windows all skew. Operators propose rewriting IDFW groups. What should the administrator restore?
Select an answer to reveal the explanation.
Short Explanation
Certificates and time-based firewall windows are clocks wearing a badge. When the GPS NTP box dies, every TLS handshake and IDFW schedule starts arguing about what time it is. Restore the physical time source; rewriting groups will not unscrew the clocks.
Full Explanation
TLS validity, SAML or OIDC tokens, Kerberos, and NSX-T time-based identity firewall rules all depend on synchronized time. A failed physical NTP GPS source lets Managers, hosts, and identity systems drift, which looks like certificate, SSO, and IDFW failures. Carbon Black Cloud policy, overlay MTU, and Guest Introspection alone do not correct clock skew. Restore a reachable NTP hierarchy from the physical time source, verify time on NSX-T, vCenter or ESXi, and Workspace ONE Access or directory, then re-test tokens and time-based rules.