Rancher Server/Agent Private VPC Error

When launching Rancher Server (1.3) in an AWS private VPC with NAT gateway, the infrastructure stacks all come up red and no containers are downloaded.
Containers can be pulled and run from the terminal on the same server without issue.
Adding an agent stops with an error after ‘Starting websocket pings’.
Tried adding the local DNS server from resolv.conf to /etc/docker/daemon.json to no avail.
Closest issue found was ELB not allowing websockets traffic, but there is no ELB and the server has internet access.
Any additional configuration required?