Argh, stupid forum lost my long response.
I can ping DNA-170 from SVR-FILE-RCH and vice versa.
Both DNA-170 and SVR-FILE-RCH have their Windows firewalls turned off. The Vyatta firewall doesn't have anything in it that seems obvious and the configuration hasn't changed (except for two added, then removed NAT rules) since December of 2018.
I have ran a dcdiag from SVR-FILE-RCH (dc1) and added it to the v3 OneDrive folder.
SVR-EXCH-RCH is being difficult, so I may not ever get anything out of it. That's probably why it was powered off.
DNA-170 is where I had been making all of my changes on for the three years I've been here. I'm pretty sure previous to this fiasco, it was a fully functional DC. I won't swear to it, however.
DNA-170 and SVR-FILE-RCH have nearly the same user and group configuration. The only differences that seem obvious to be would be things done in the past week or so, which is how long Azure AD Connect hasn't been able to sync passwords.