I have a secured network with no outside access of
anykind. I would like to have the DC in this network,
time sync with an ethernet timeserver (Spectracom 9188
NTP Ethernet timeserver) on my other network. I am
planning to do this at the routing level by only allowing
the DC on the secured network access to only the
timeserver, and further restricting it so that only the
NTP protocol can get through the port going either
direction.
While I know nothing is 100% secure, is there anyway that
a virus or malicious code could get through only with the
NTP protocol allowed?

Thanks,
Will