We are currently using a single NTP server that resides in our DMZ that responds to NTP queries from internal users (it's actually two that are setup with round-robin DNS). However this NTP server does not need to respond to NTP queries from the internet. When I mentioned that it should probably be moved to our internal network segment I had someone in our organization say that it is a Cisco Best Practice to have your NTP server in your DMZ.
I have always had the belief that if a server or service does not need to be accessed from the "Public" side then you do not put it in a DMZ and assign it a public IP address. When I mentioned then I was given a statement that ALL fortune 200 companies do it that way.
Can anyone tell me if Cisco does have a Best Practice for NTP servers and if so can you provide a link to it???
Any suggestions/comments would be greatly appreciated!
Pat G.