Hi,
sorry that it took so long for us to answer, i had two weeks vacation. Rene and I are facing the issue that we have to allow traffic from our internal VPN solution (not terminating on the gateways) to a third party network, that is directly attached to our internal network (no VPN). This third-party network has a crap-ton of routes, so we want to group them of course.
Now comes the part, that we struggle with: The VPN users can access our internal stuff, that is listed directly in the "internal_spoof" group, but not the systems, that are listed in the third party network group, which is also listed in the internal_spoof group. Gaia routing is fine, our people at the office can access the third party network just fine.
Management and Gateways are on R80.40 with the latest JHF.
Any more questions? All help is much appreciated.
-- Daniel