Accessing Calico Enterprise Manager UI

I want to access enterprise manager UI with ingress method from documentation.
My cluster is provisioned on vsphere with rancher and it by default installed nginx ingress controller as daemonset. I’ve created ingress resource which points my custom domain to tigera-manager service on port 9443. but problem is I’m getting http 400 error and can’t access ui on that domain. domain points to a nginx loadbalancer which is configured to passthrough ssl/tls.
Any help would be appreciated, thanks in advance.