Query on Replica Node got Invalid credentials

I install a UCS 5.0 as my AD Domain Controller ( Primary Directory Node ).
And I install another two UCS 5.0 as Replica Directory Node & Backup Directory Node.

Use ldapsearch query Primary Node / Replica Node / Backup Node to LDAP ( port 7636 ) all works.
( ldapsearch -x -H ldaps://FQDN:7636 -b “dc=foo,dc=bar” -D “uid=Administrator,cn=users,dc=foo,dc=bar” -W )

But, query SAMBA-LDAP ( port 636 ) not all works, when I query to Replica Node / Backup Node got “ldap_bind: Invalid credentials (49)” .
( ldapsearch -x -H ldaps://FQDN:636 -b “dc=foo,dc=bar” -D “cn=Administrator,cn=users,dc=foo,dc=bar” -W )

How can i solve this problem?