Multiple FusionHubs behind a single ipv4

Hi,

we want to operate multiple fusionhubs behind a single ipv4 address. if we only put port 4500 on port 4501 we will not get a tunnel to run.

Am I right in the assumption that the port 4500 is a UDP tunnel?
What does TCP port 2222 and 32015 do? Where could we change the ports 32015 and 2222 on the router side?
Do we really need the webports, or can we shield the web interface behind a VPN?

Similar request Change Port Fusion Hub Listens