That's fine.
you need to place IP addresses into the field by WebUI section.
when you do that SYNC from Check Point device towards local IP address of your locally-hosted NTP server that sync does not leave your network,
when you do that SYNC from Check Point device towards external IP address ie. 195.66.241.10 - that is an external public (well known and with good reliability) NTP server - that traffic is leaving your local network towards an Internet host. Either way you need to create Access Rules for that purpose allowing udp/123 port through. How you're going to do that? I think this is a matter of creating respective Rules in your Smart Dashboard and allow traffic as a principle.
In the mean time please do think about allowing that NTP sync to all "network devices" not only CP host (your FW). Local hosts like PC usually sync-ntp (time w32t) against their DC (domain controller) so no need to allow "hosts" to sync via Internet or locally to your NTP server. IT is now a matter ... can you deploy that yourself?
hope it helps.
J.
Jerry