VMware Cloud Director 10.6.1.2
This behavior is caused by the configuration of the Firewall Match setting within the NAT rule options in conjunction with port definition. If a DNAT rule is defined with specific IP addresses but no specific ports (implying "Any"), the rule matches all traffic destined for that IP, regardless of the port.
To workaround the issue, follow Method 1 Resolution from the below KB: