Cluster of 4800 8GB running R80.30 Take 155 distributed.
No issues running VPN with all kind of Windows PC (Windows client, SSL Extender), but as soon as Mac's stepped in they were unable to launch SNX (would pop up then immediately disconnect) and the VPN client would fail at the site creation. No drops seen in FW logs from the public IP of the client to the public IP of the cluster.
No issues with the same users on the PC systems. After investigation it turned out that cipher_util was used to allow only TLS 1.2 ciphers on primary gateway, but not yet on secondary. Doing a failover solved the issue and Mac OS can now use the client or SNX.
I quickly had a look and don't see this limitation in the release notes or the known limitations, but it works and for now that's all we ask of the system.
So it's a n FYI in case you would suddenly need to support MAC VPN on your TLS 1.2-only MOB and wonder why nothing is working.