I never tried this but, if I where in your shoes, I'd pull a copy of Wireshark, instruct it to use the SSL dissector on TCP 636 and have a look at a packet dump: if you're looking at an SSL failure, ...
I found the following information in the Microsoft website regadring replication over the firewall which asked me to configure the firewall to permit the following, ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results