@Kake, Thanks for posting in Q&A. Based as I know, the Azure AD Connect server needs DNS resolution for both intranet and internet. The DNS server must be able to resolve names both to your on-premises Active Directory and the Azure AD endpoints. It also requires network connectivity to all configured domains and to the root domain of all configured forest. If you have firewalls on your intranet and you need to open ports between the Azure AD Connect servers and your domain controllers. Here is a link with more details for your reference:
Hope the above information can help.
If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.