Clock synchronisation. Quietly critical: TLS certificate validation, authentication tokens, scheduled jobs and log correlation all break when a clock drifts far enough, and NTP is what keeps machines within milliseconds of each other. It is one of the few protocols almost every device on a network speaks without anyone configuring it.
Older NTP servers responded to a monlist command with a huge reply, making them potent DDoS amplifiers. Keep NTP current and do not answer queries from the internet unless you intend to run a public server.
Open 123 is fine on a time server. Elsewhere, verify your NTP daemon is current and not answering queries from outside, since older versions are powerful amplification tools.
The port scanner will tell you whether 123 is reachable on a host you control. Checking from outside your own network matters: a port can be open on the machine and still be blocked at the firewall, and it is the view from the internet that decides whether anyone else can reach it.
Only scan hosts you own or have permission to test.