I disagree on other DCs syncing externally
Nope every DC that is not the PDC emulator should be set to NT5DS as well as every Member Server
http://technet.microsoft.com/en-us/library/cc786897(WS.10).aspx
http://technet.microsoft.com/en-us/library/cc758905(WS.10).aspx