I'd start with these ones.
https://learn.microsoft.com/en-us/troubleshoot/windows-server/identity/config-firewall-for-ad-domains-and-trusts#windows-server-2008-and-later-versions
and more are listed here.
https://learn.microsoft.com/en-us/troubleshoot/windows-server/networking/service-overview-and-network-port-requirements
--please don't forget to upvote
and Accept as answer
if the reply is helpful--
Hello KaelYao-MSFT ,
Unfortunately, no one has complete answer and all are pointing Microsoft article that says Any to Any communication is recommended. In the real time this is the hard to achieve, specially in Enterprise with Multi vendor scenario. Every vendor challenge request to open Any to Any communication between domain controllers and Exchange servers.