Here is another thought - If you have some internet-facing web server you can host a page on, implement a "portal" to your SA devices. I've got some code from our SSL VPN regional specialist for a web page which does a rudimentary round-robin assignment to a group of SAs after checking that the device to which the session is to be sent is actually functioning. The assignment is done via a redirect, so there are no load-balancing persistence issues after the assignment is made. I'm looking to perhaps design and implement a portal which would take into account session counts on devices in doing something like this. My environment is pretty complex (15 clusters globally each with 12 IVSs ), and I'm not exactly a great coder, so I'm taking it slow. But the idea is pretty intriuging... Ken
... View more