IMHO, the SNTP compartment should probably...
- not hardcode
pool.ntp.org
- instead, require the user to provide a fallback server (and connection rights)
- use DHCP-provided NTP server information (RFC 2132, section 8.3) as another available server, but that requires some work with the firewall and some way of capturing dynamic connection rights.