Cisco SD-WAN NAT Setup

Job ID: 40154206

Budget: ₹1,500 – ₹12,500 INR

I am seeking a Cisco SD-WAN expert to resolve a control plane reachability issue. Currently, my controllers (vManage, vBond, and vSmart) are hosted on prem behind a Unifi Gateway with port forwarding. After changing the vBond IP to a Public IP and implementing port forwarding, the controllers are experiencing the following issues:
Control Plane Flapping: vSmart and vManage are constantly losing connections to the vBond (Logs show "Control No Active vBond" and "OMP Vsmart Down").
Application Failures: vSmart is periodically throwing Error: application communication failure when running CLI commands.
NAT Loopback/Hairpinning: The controllers are in the same subnet (172.16.5.x) but are configured to point to the vBond via its Public IP, causing DTLS/TLS stability issues.
Poor Health Status: vManage reports poor health for vSmart, likely due to a port-offset configuration and certificate/MTU mismatches.


What I need is clear, step-by-step guidance plus hands-on changes so that:
• Each controller establishes stable control and TLS/DTLS connections through the firewall
• All required ports and certificates are properly configured, including any device-local-interface or system-ip tweaks
• Remote WAN Edges can onboard
• A brief document shows the final firewall/NAT rule set and any commands run on the controllers

This is a focused task for someone who already knows Cisco SD-WAN (vManage/vBond/vSmart) and typical NAT traversal pitfalls. Once everything stays up for 24 hours I will consider the job complete.

I have attached the my architecture to this post