Re: IP NAT Pool NOT applied on SPLAT Cluster when SC is NGX The problem has been identified and solved! The cause of the problem was not the cluster, but on the cluster we had the only SecuRemote rule which had nested user groups. Fact is: If you compile the policy on a R55 SmartCenter, a SecuRemote rule containing nested user groups works, whereas if you compile the same policy on an NGX SmartCenter, the rule does not work when installed on the R55 gateway, regardless whether it is a cluster or not. The user's can authenticate, but the first access rule gets dropped on the cleanup rule!!! The workaround is to add additional rules and de-nesting the user groups. You might consider that when upgrading to NGX SmartCenter Cheers |