I had not configured correct SPNs for AD LDS service account. After registering the SPNs everything works fine.
port 3268 is used by AD to have access to Global Catalog. Port 389 is meant for other LDAP search and has limited acess. Refer to the following url for details
Users browsing this forum: Google [Bot] and 3 guests