Option B does not seems to work :-(
My current minimum plan is to force cluster members to send syslogs to syslog server with its real IP addreses (further on, I would like to have NTP working on both members, etc).
I tried you recommendation without success:
- It is impossible to add cluster into "Source" field of NAT rule
- Adding 2 rules with cluster members in orginal_packet:source and syslog server in orginal_packet:destination and keeping all the rest field as "Original" haven't resolved problem too - syslogs are still appearing on syslog server with cluster address.
Bart