(1) Can both of them run in parallel? any downside to using this?
Most people use it in parallel, but ip scanning is mostly used for non-computers.
(2) Active scanning needs DNS setup for untrusted domains to be correct, which im struggling as of now... the way i can get it working is to keep changing the primary & secondary DNS servers to point to correct untrusted domains but is not feasible in the long run (maybe im not doing it correctly?)... i have 5 physically separate domains connected via a VPN link
You can keep one dns server (your current one) and on the dns server create forwarders to the other domains.
(3) How about if i turn off 'Active Scanning' and only use 'IP Range Scanning' for all untrusted domains? will it give the same results?
If the windows firewall is on the computers will never be discovered with ip scanning.