If you are using the hostname in your connection rather than IP, you need to declare it in hosts.yaml file on your VA’s. Since nc command works for IP and port on the VA, connectivity isn’t a problem I suppose. if hostname is used, it is failing to resolve to the IP causing time out error.
Thanks Uday, I am now trying only with ip. And all in plain text (ad 389 and iqs 5050). I am setting up a VA from scratch right now, to see if there is some problem there, although tenant says connection is fine.