Speedfusion config for both ends; AWS fushion hub with device Max BR1 Pro 5G AT&T cellular wan only

I have been searching for an appropriate configuration setting for this setup, but unfortunately, I have not been able to resolve it. There are no other devices involved.
Also, I have other Fushion hubs at AWS working with Peplink devices that use a cable provider’s WAN connection.

From what I have read, cellular carriers such as AT&T utilize Carrier Grade NAT, preventing me from assigning a routable public IP address to the Max BR1 endpoint. The AWS Fushion Hub endpoint does have an addressable public IP. So my Max BR1 endpoint is configured with the Fushion Hub’s remote IP, and the AWS endpoint remote IP is left blank. Both devices have the other devices’ speedfusion ID and shared key configured. The Max BR1 endpoint speedfushion log show’s it trying to connect; however, the AWS speedfushion log is not reporting any activity. Both units show in their respective speedfusion status UI, starting, connecting and then starting again, and this just continues, never getting to the point of establishing/updating routes.

My reading suggests that I need to provide some firewall settings. The AWS Fushion Hub does have firewall settings to allow the two required ports 32015 and 4500. Similar to my other cable carrier working connections.

If this connection is possible, would someone be willing to share the detailed configuration for each endpoint?

Thanks in advance,
Joe

I’ve had to pick alternate ports with some CGNAT providers… either they require IPsec on 4500 expecting NAT-T or they interfere in other ways. So I use port 4501, 4502 etc…

Obviously add the new port to the AWS firewall ruleset. and I use the same port on both sides.

Next up is packet captures… that shows the packets leaving the remote modem, and seeing what arrives at the AWS node. any packets?.. malformed? ICMP errors?.

Perfect, thanks for the insight. I modified the AWS firewall to inbound allow UDP 4507 and TCP 32017. I then changed the fushion hub and the max br1 speed fushion link configuration data ports to custom 4507. Connection established.