So as a fix right now, using 3268 is good. You get a much quicker response using the Global Catalog.
Setting the search base DN at the top level of DN=MYORG, DN=NET will stop the search from being restricted to the OU defined.
One other thing you should do is to set the paging value for EEM to true. In the server.xml file located under C:\Program Files\CA\SC\EmbeddedEntitlementsManager\config\server there is a setting:
<paged>false</paged>
Change that to
<paged>true</paged>
and restart the iGateway service.
Because you are using the Multiple Active Directory domain setup, for Process Automation you will also need to set the default AD domain setting once you add the other domains. Don't do this now, but once you add these other domains at a later time, you will have to have this specified
The setting is in the oasisconfig.properties file:
oasis.security.activeDirectory.defaultDomain=
Set this to your main domain as:
oasis.security.activeDirectory.defaultDomain=myorg.net
and restart Process Automation.
If you do for now decide to go with the Basic LDAP setup in EEM, you will have to leave that default domain setting as blank or else you won't be able to log into Process Automation.