Does the 2nd point mean you can't ever connect? Have you tried adding a new server registration, if this fails then you're not going to be able to replicate when the details are not correct.
Has the server ever conneted ok?
Can the other domain be linked to your VPN as an alternative and then use the internal IP address for replication?