What is the safest way to allow internet access to the time?

I am trying to set up a firewall (Cisco ASA, but I don't think that matters) to allow an internal time server out to the internet to synch its clock. The issue is this time server is also a DC/DNS server. At the moment, the firewall is blocking all outside access anywhere except for a VPN connection to a specific server at a different office. We cannot use that link to synch the time though.

I'm thinking of using pool.ntp.org. However in order to do that, I would have to allow DNS. Since the time pool is a moving target, I can't allow just by IP, correct? But if I allow DNS that means other devices could get internet name resolution, even if they aren't allowed any sort of external access. Is there any risk in that? Or perhaps there is a better way to do this?
Brian B Topic Advisor, Independant Technology Professional Asked:
Brian B Author Commented:
The concern is that IPs could change, so I'm going to use a different time source. So it sounds like I can't do this as I really wanted, but the information provided was helpful, thanks.
noci Software Engineer Commented:
If you narrow down somewhat...
the pool is too large, but there are also regional pools, or country based pools.
Near NTP servers are prefered above one on the opposite of the Globe.

Check out this site for the rules of engagement.

From there you can zoom in on continent etc. etc.

If you select country based then most probably there are only one or two available.
Brian B Author Commented:
Yes, but will those IPs change?
David Johnson, CD, MVP Owner Commented:
then you cannot use a pool you have to use a specific server
nslookup server 0.north-america.pool.ntp.org will give you 4 ip addresses that you can use.
> server 0.north-america.pool.ntp.org
Default Server:  0.north-america.pool.ntp.org


