Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

2 WAN-Links (use primary one, and only if failover the second) - Problem with DNAT on failover Interface

Hello,

we have an question because in the past we have problems with DNAT when configuring our two WAN-links as active/passive.

As a workaround we configured the two interfaces as active/active, but now the problem is the second link (which is limited by used data - mobile access) will used in round-robin. 

What we need is:

All devices should use WAN1 (fixed 5Gbits Access to ISP) for traffic to the internet. Only when WAN1 is down the devices behind XGS (and the XGS itself for traffic to Central) can use WAN2 (mobile data) for an "emergency" option.  

What we see in the past is:

When we configured WAN1 as active and WAN2 as passive -> DNATs from Internet which pointing on WAN1 works perfect.
But DNATs from Internet which poiting on WAN2 are not reachable -> i think the incoming traffic will be ok, but XG uses in same tcp-connection WAN1 for outbound traffic back to the customer. 

Anyone has an solution for these?