At one point an organization had several AD DC servers, since then some were terminated, but the other remaining ADs were not properly notified of that termination. So, it's more often than not, that in direct queries to the AD/LDAP returns the same type of referral (Referred this request) to another server that is off and in these situations the LDAP client tries to communicate with an inactive IP and awaits for a tiemout.
In this situation the manual changes to be implemented in the IPBrick server are:
/etc/libnss-ldap.conf
/etc/pam_ldap.conf