The smart solution of the DNS Firewall does not block anything except custom DNS but now allows to force use it by "Forward all traffic to port 53 to user-configured DNS endpoint." That's clever since some apps tried contact 8.8.8.8/8.8.4.4 on their own.
Its called RethinkDNS and not RethinkNTP. So you cannot cover any application layer protocols. But how about Idea of doing similar traffic forwarding by firewall for this type of traffic? "Forward all traffic to port 123 to (user-configured/default) NTP endpoint."
From: celzero/rethink-app#310
From: celzero/rethink-app#310