Description
I had trouble establishing a forest trust between the "on-premise" AD and the managed AD.
After some investigation I noticed that the security group created for the directory controller was allowing dns and kerberos traffic only for 10.16.0.0/16 range.
After allowing UPD and TCP traffic for 0.0.0.0/0 the trust relationship process worked