The outbound LDAP connects from the gateway to the Account Unit LDAP Server are handled by the implied rules by default.
The implicit rule takes effect before the access policy. Therefore, no logs are written and the VPN domains are not applied.
The implied rule does not apply to ports or servers that are not configured in the account unit. The explicit rules take effect and logging / VPN routing is applied.
You can deactivate the implied rule by commenting out the following line in the $FWDIR/lib/implied_rules.def file on the management server.
#define ENABLE_LDAP_SERVER
Please note that explicit rules must then exist for both the internal and external account units.
Oliver