The idea is to ultimately roll out more than just one LDAP server on each domain, so in the event of a failure (Server is down), the subnet doesn't have a seizure (clients would be configured to be aware of multiple LDAP servers– or through a load balancer, just be moved over to an accessible LDAP server).
Additionally, it would be nice to enable updates to take place at the local LDAP server (for example a password change), and have those changes propagate to the other LDAP peers.
For now, concentrate your efforts on VMs in the student.lab network. As you need to do more testing, I can roll you a VM on some other subnets.