Some VPN clients are not able to connect to Security Gateway.
Cause
Kernel table "ccc_sessions" (for Endpoint Connect clients) on Security Gateway fills up very rapidly (refer to output of "fw tab -t ccc_sessions -s" command), not allowing these VPN clients to connect to Security Gateway.