> The secondary zone copied over fine on both DCs
If you look in the zone you should find that it lists lots of private IP addresses (and hasn't a clue about the public IP addressing). Is that correct?
That tends to be why a VPN is required, Trusts have a pre-requisite that you can talk to the other network. The cheapest solution for that tends to be a VPN.
Chris