I've set up a site to site VPN to an ASA at a branch location, but the remote site also needs local/private DNS. I can't get the remote LAN to use DNS servers behind the VPN, because there's no network redundancy and if the VPN dies, the site has no DNS. On IOS you can set up DNS server with split DNS and send queries to different servers based on regular expressions (view lists, name lists). But since ASA can't act as a DNS server, the functionality is simply missing. The ASA serves DHCP for the local LAN.
Can DNS inspection on ASA be configured to match certain queries?
If that was possible, I could redirect queries for internal domains to internal DNS server. There is alwas the option to simply set up a local DNS server, but the remote office (in Asia, the HQ is in the UK) only has clients/desktops, so I'd rather try all possible options on the ASA first.