cancel
Showing results for 
Search instead for 
Did you mean: 
Post a Question

New R80.10 ClusterXL gateway cluster VPN NAT issues

I built out a new R80.10 ClusterXL gateway (using previous cluster's policy).  When I attempt to connect to the remote access VPN using the Virtual IP of the cluster, return traffic is sent back via the physical IP address of the gateway, not the virtual IP.  I feel like I just missed a checkbox somewhere, but am not sure where to look.  IPSEC gateway to gateway tunnels work fine.  I have verified that RADIUS authentication is working and properly authenticating.  SSL VPN hangs when authentication is successful (I believe it is because the site is no longer listening on the virtual IP).  If anyone has any suggestions, I would really appreciate it.

1 Reply
Admin
Admin

Re: New R80.10 ClusterXL gateway cluster VPN NAT issues

Might be worth checking this SK: How to prevent ClusterXL / VRRP / IPSO IP Clustering from hiding its own traffic behind Virtual IP a... 

Obviously this is the opposite of what you want, but my thought process is maybe this got configured somehow.

0 Kudos