If you feel the DNS proxy on Astaro is more solid than the one you're using internally (e.g., Bind), you could benefit from using the proxy; people on the 'net will not have direct access to the ports of your so-so DNS Server to play with. Any malformed DNS requests will (hopefully) be sanitized by Astaro's DNS proxy.
The advantage of not using the proxy is it removes another thing to maintain/go wrong.
If you feel the DNS proxy on Astaro is more solid than the one you're using internally (e.g., Bind), you could benefit from using the proxy; people on the 'net will not have direct access to the ports of your so-so DNS Server to play with. Any malformed DNS requests will (hopefully) be sanitized by Astaro's DNS proxy.
The advantage of not using the proxy is it removes another thing to maintain/go wrong.
If you use the proxy, you wouldn't use NAT at all. The internal DNS server would use the proxy as its forwarder DNS server, authoritative for all else outside your domain.