IPA added ipa-replica-conncheck to check the firewall settings between replicas. It should be a part of the replica preparation/installation section.
This is run automatically by ipa-replica-install. It is certainly executable by an average admin but this usage would not be typical. A man page for it exists.
This probably shouldn't be doc'ed in the official docs.