NCM webclient URL using FQDN/hostname would redirect to use the IP address thus exposing the IP address.
All supported NCM versions
A CA-signed certificate plays a crucial role when switching Smarts NCM URL from an IP address to a hostname, primarily acting as the structural bridge for browser trust and encryption
The installation of the CA-signed certificate which includes the FQDN in the Subject Alternative Name corrected the redirection behavior.