Have you reviewed in your firewalls the dropped and rejected traffic?
Surely all rpc dynamic ports are denied from 1024 to 65535.
I had the same problem and I had to add this rule between dc on...