Hi John Doe,
When you get intermittent auth issues over a forest trust, it usually boils down to selective authentication misconfigurations or Kerberos packet fragmentation. If selective auth is turned on, make sure the users or their groups from the trusted forest actually have the Allowed to Authenticate permission on the target resource's computer object. Also, check the Name Suffix Routing tab under the trust's properties in Active Directory Domains and Trusts to ensure their UPN suffix is active and not excluded.
Since the failure is intermittent, there is a big chance your Kerberos tickets are hitting the MTU limit and getting fragmented over UDP. You can easily force Kerberos to use TCP instead by adding a MaxPacketSize DWORD registry key set to 1 under HKLM\System\CurrentControlSet\Control\Lsa\Kerberos\Parameters on the resource servers. Run nltest /sc_query to check the secure channel health too. If this does the trick, please accept the answer to help others out!
Tracy Le.