Verizon LTE Extender: "ERROR: Fail to get certificate form CMP server" over Starlink

I have a situation where I need to facilitate a Verizon LTE Extender over a Starlink connection (with a Ubiquiti ER-X router between Starlink and the LAN), but due to Starlink having CG-NAT (Carrier Grade NAT) and not having a way to NAT things across due to sharing a single IP with multiple customer premise devices, Verizon’s range extender just doesn’t work. From what I understand with the errors from the device LCD + device logs:

  • On the device LCD: “Server Error 5A” and then
  • In the device’s web admin panel logs:
    Get certificate form CMP server...
    ERROR: Fail to get certificate form CMP server
    • (Yes, “Get certificate from CMP server…” is misspelled with “form” vs “from” on the device itself, but I figured I’d include it to help your SEO findability. Lol.)

It appears that I need to forward ports 50, 53, 80, 123, 500, and 4500. 80 might be questionable, but I want to play it safe and assume that this is the case from what I’ve been reading.

It would be nice to just slap the Verizon LTE Extender onto a “DMZ” and be done with it…

How would your service be used to facilitate such a scenario where all TCP/IP traffic from a LAN device could be able to negotiate such an apparent VPN certificate for Verizon’s network to work with its device?

Unfortunately, this needs traditional port forwarding, since Verizon needs direct access to the modem on multiple ports, is not going to work, since it is Verizon that needs to access the network and not you.

Some further information. Remote.It does work in many other Starlink use cases where you are accessing devices which are directly on the LAN.
