We have a mail gateway running in a DMZ, which is a relay for our internal mail server holding all the mail. We have come accross the need to use DNS from the DMZ to resolve names of internal services (such as the internal mail server, etc.).
Should we allow DNS queries from the DMZ to LAN? This would result in a serious breach in case some of the DMZ servers were compromised. On the other hand, not allowing the DNS queries makes us much less flexible.
I came accross the concept of a split-brain DNS, which is, I assume, what would solve the problem, but I do not quite understand how it can be accomplished in a Windows AD integrated environment.