You have to have a local domain controller in the same network as the Exchange 2007 server. Connecting to a domain controller on a different subnet via a VPN will prevent certain Directory Services from working such as downloading Offline Address Book (OAB). This domain controller doesn’t need to run DNS — all it needs is have the checkbox for "Global Catalog" checked under AD Sites and Services NTDS settings.