Okay, i try to be more specific.
Cisco Concentrator sends a AS_REQ to the Windows DC (KDC).
The User has many attributes which don't fit into one UDP Segment (the AS_REPLY).
Now Cisco Concentrator should switch over to TCP. But this does not happen.
May there is a solution in setting the SEC_WINNT_AUTH_IDENTITY_ONLY falg in the Request.