You may wish to try port 3268 (Global Catalog) instead of 389(limited/Local). This will alow the LDAP to query the whole of AD.
Refer to the following threads:
GRC 10 LDAP query issue at the root node
Also refer to this link Global Catalog and LDAP Searches