the issue has been resolved and was related to the Zero Tier service being enabled on the WAN2 interface of the primary router, the KNOT LTE is a LTE backup router and was connected to WAN2 port of the primary router (non mikrotik).
The primary router had zero tier service enabled on the WAN2 port and looked like zero tier was trying to establish connection to the “cg-nat“ range of the LTE internal isp subnet 10.45.32.120 which the ISP probably recognised as invalid or suspicion traffic and cut the connection off.
That makes sense. Although my first reading was it likely a bug, since KNOT LTE is new.
Verizon in US does drop the connection if it gets any packet that does not match the expected src-address – so this stuff happens. And, ZeroTier probing might try it's own address to get out, and ZL1 is somewhat indifferent to the firewall NAT, so it make it to LTE.