Had to delete and add peering again, aadds-vnet uses remote gateway of peer. AADDS is exposed according to nmap. Joined synology to domain, works fine.
LDAP from premises to AADS
Reputation points
aadds-vnet hosts the directory servers on
There is an option to add a firewall - but creating one doesn't include aadds-vnet
The goal is an IPsec VPN from premises LAN to aadds-vnet, to allow LDAP query from a Synology Diskstation, or to add an on premises Windows member server.
The reverse, in a sense, of AD Connect.