Thank you - although I missed your reply before solving it. "VPN address 192.168.126" was a typo - it was supposed to be 192.168.92.126. Looking again at this, I think we had the pool addresses in the same subnet as the external cluster interface not the internal interface. We have separate narrow VLANs for the connections from our BigIron router to the MAG, so the interfaces are not seeing our entire network. In any case, we changed to a bigger address pool like 192.168.79/24 and added a static route to the internal interface. This now seems to be working as expected
... View more