v11 Hosts that need to access LIVE

Deployment Guide: Network Architecture and Ports 


After looking at the ports on the table I noticed that the only appliance needing to access LIVE is ESA.


Further looking at the diagram, it does NOT show that ESA can directly access LIVE.


Which of the two is correct and why does the NW server not need to access LIVE? This doesn't make any sense 



Then for NTP ports, none of the core appliances need an open connection to NW server but only to itself.


ArchiverArchiverUDP 123



BrokerUDP 123NTP



ConcentratorUDP 123NTP

So Broker to Broker, Concentrator to Concentrator etc. No Concentrator to NW server. So how would this work exactly?