902 and 903 are not required externally, only from vCD cell to ESXi. TCP 443 to the console proxy address is needed.
If you are not on 5.1.2, can you upgrade to vCloud Director 5.1.2?
Also, check timestamps of the servers involved (cell, ESXi, client, etc) and that the certificates for the console proxy are identical (if you have multiple cells, it should be the same on each of them).