is it possible to install ipa-dns-install on a remote host that is only
connect via vpn?

I mean this i my current network structure:

Host (Internet)                                               Intranet
VPN Access Provider  tun   <  -  > tun             FreeIPA Server dc01

when i now try to ipa-dns-install with the ip from the client ip of the tun
device of the FreeIPA Server i always get an error that the ip is not on my
device. Is there an easy way of having the DNS of the FreeIPA Server on an
Internet Machine? I mean it will work if i replicate the whole ipa-server
but that is somehow a little bit of an overkill.
