Topology: Internet -- F5(SNAT&DNAT for CP) -- CP(Mobile access VPN/SNX)
The client auditors found that they can not view log(include which user access which host(destination) in one log) while I only found Remote Access log(including which user access which host(destination)). Due to F5 do SNAT for SNX, we can not view different source access which destination according logs. Look at capture I uploaded. So, the client feel it is not acceptable. Does it expected/designed or other issue? It was a tad confusing.