Finally figure it out and it's a dumb one...my IPTABLES firewall was blocking the traffic. Changed the ruled to allow port 2055 inbound and nfcapd works just fine.
Learned an important lesson: tcpdump is the first thing that network traffic hits, before IPTABLES. Just because you can see traffic with tcpdump doesn't mean it is getting past your firewall.