Hello Daniel SHEN
As you have confirmed that there is a firewall in between it is possible that you have not opened up all the necessary ports which are listed here: https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/dd772723(v=ws.10)?redirectedfrom=MSDN#communication-to-domain-controllers
You will note one of those ports is 9389 which is the AD DS Web Services port. Note for the RPC ports you may want to scope that down.
Hope this helps