When allowing outbound DNS queries from a DMZ, if the DMZ is configured via DMZ access-list to allow queries to go to a specific IP Address (ISP DNS Server),
Does an inbound rule need to be applied on the outside interface, or is the connection stateful for both udp and tcp?