What IPs do I need to whitelist to use the NTP Pool?

the set of IP-addresses returned by our authoritative DNS-servers changes every few minutes so the load will be evenly distributed as good as possible among all volunteered time server resources.

It’s not possible to white-list all the IPs, you have to allow the traffic by port number.

Stateful firewalls are capable of regarding the reply package as ‘related’ traffic. Therefore, you only need to allow outbound traffic to UDP destination port 123 and all ‘related’ inbound traffic. So, there is no need at all to allow incoming connections.

An alternative is to setup a server in your “DMZ” (or outside the firewall) and run an ntp server there. Then your internal systems can synchronize time from your own trusted server at that IP address.

Some firewall systems or gateway boxes also have NTP functionality built-in that your internal systems might be able to use.