To be honest edmund085 bind should be split into forward and reverse nodes and without doubt the internal IP shouldn't need to be hid.
I have setup a few versions of vanilla samba4 from sernet and have a personal choice for the internal DNS of samba rather than bind. (full blown bind9 to complicated for this simple mind, just wish the internal could have more forwarders)
Its just a doddle to set up and you can use RSAT tools.
I get different results with Zentyal and vanilla samba4 and yeah something is not right but exactly what I am not sure.
Its a bug and shouldn't be that way externally. I don't know the exact details with this fault haven't had a look but something is amiss with the dns generally.