If this gateway is using Identity Awareness blade and Identity Sharing feature is active, the main ip address is used for the sharing connection (pdpd <-> pepd). If you hit this problem, you can circumvent this by setting the ip address used for these IA sharing connection manually by filling gateways field ia_control_connections_ip with (gui)dbedit. See sk60701 for that.
You should also check the various portal settings (admin, mobile access, user check, identity awareness, etc.) and their certificates.