DNS with overlay network

Hi,

I want to set up an overlay network for specific servers in my network but am struggling over dns service. The dns server (backend is samba4) has an up and running overlay network interface which is listening on port 53. dns queries from within that dns server over the overlay interface is working well but when I request that dns overlay ip from another client I get the error ** server can't find example.com: REFUSED What am I missing? Testing with univention-firewall disabled does not work either.

Kind regards,
Christian