if your only resolver to the internet is a client (firewall that runs resolv.conf containing only external nameservers); your internal dns can/cannot use a forwarders directive to the firewall to resolve external hostnames? the answer is no; or is there is some other way? rf