You should create a separate site. This would localize the authentication traffic. Even with high bandwidth and low latency, there is no reason to have users/devices in the production site authenticate randomly against domain controllers residing in the DR site
If the above response helps answer your question, remember to "Accept Answer" so that others in the community facing similar issues can easily find the solution. Your contribution is highly appreciated.
hth
Marcin