diff --git a/ntp/files/ntp.conf b/ntp/files/ntp.conf
index df8db2c..8ba076e 100644
--- a/ntp/files/ntp.conf
+++ b/ntp/files/ntp.conf
@@ -70,8 +70,11 @@
 {%- endif %}
 {%- endif %}
 
+# Exchange time with everybody, but don't allow configuration.
+restrict -4 default kod notrap nomodify nopeer noquery
+restrict -6 default kod notrap nomodify nopeer noquery
+
 # Only allow read-only access from localhost
-restrict default noquery nopeer
 restrict 127.0.0.1
 restrict ::1
 
@@ -90,13 +93,8 @@
 {%- for r in server.get('restrict', {}) %}
 restrict {{ r.subnet }} mask {{ r.mask }} {{ r.options|default('nomodify notrap nopeer') }}
 {%- endfor %}
-
-# Exchange time with everybody, but don't allow configuration.
-#restrict -4 default kod notrap nomodify nopeer noquery
-#restrict -6 default kod notrap nomodify nopeer noquery
 {%- endif %}
 
-
 # Location of drift file
 driftfile /var/lib/ntp/ntp.drift
 logfile /var/log/ntp.log
