Is this a firewall problem, perhaps? Those packets translate to UDP packets in bsd auth, and if there's some connection tracking going on, it would probably reject a reply packet after 800+ seconds.
If that doesn't prove to be the case, take a look at a tcpdump of the connection, to see whether the REP packet or its ACK is actually being lost. Dustin -- Storage Software Engineer http://www.zmanda.com
