That would be a good idea if your DNS servers are not behind an IPsec
connection. In my case, branches contact HQ via IPsec for HQ local
domain resources like an intranet. They need access to the internet if
the IPsec goes down for some reason. So yo...