Re: VPn3030 cluster for loadbalance behind firewall
If your vpn concentrator is behind the NAT device and it's using a private IP address then you have to create a static NAT for cluster & two concentrator Ip address because all those IP's should able to reach from outside to effectivly work this load balance setup.
In VPN load balance configuration, you have to use private IP address not the real IP address.
We have configured the outside and inside Interface with official ipv6 adresses, set a default route on outside Interface to our router, we also have definied a rule , which also gets hits, to permit tcp from inside Interface to any6.
In Syslog I also se...