Hi @Avinash Yadav ,
this is a good approach to secure critical service like domain controllers.
The two impact you can occurred:
- If the IP of domain controller is used as DNS resolver on client computer, client can be impacted to navigate on internet, because the local DNS server ( domain controller in your case) need to forward DNS request to external DNS server.
- If you don't have a WSUS server ,and the domain controllers download update from Microsoft download site, windows update can be impacted
Please don't forget to mark helpful answer as accepted