Hello,
I think your approach is WRONG, and let me tell you why 🙂.....
Indeed you have 3 Public IPs on the CKP Cluster - one as VIP and other two on the GWs.
On your set-up, there are several things wrong, as you can't use the stand-by public IP to NAT traffic that would go towards Internet through the primary GW.... or if that traffic will exit, then how you expect to return properly, as the standby appliance will respond to that IP....
So for the NAT, the way you want it, you should wither create a separate NAT pool like xxx.xxx.3.95 - 96 and use that .
Also until you figure out how things should be, do a standard NAT so the clients can get outside and have needed/required access, and play with NAT Pool for a couple of clients that you can play with...
@All others, am I wrong on my logic ?
Thank you,
PS: may I ask how many clients you have in the back that you would consider you require an extra NAT IP, there are some NAT alerts in CKP logs that would point out that you're reaching the limit.