
I made some progress, but I am still unable to do what I need.
I said that ldapsearch correctly returns the record related to myself from both servers, but one of them, namely that configured with ACL's, also returns some other lines like this:

# refldap://ext.domain.net/CN=Configuration,DC=ext,DC=domain,DC=net

I use simple bind and these lines are returned because my servers answer on port 389.
Querying the Global Catalog on port 3268 removes those lines (and authentication works fine), but GC does not return an attribute I need, i.e. the employeeID. So when the records synchronize I will get problems.
I did not find a way to avoid referrals to appear in the answer.

Did anyone face and solve this problem?
