Certificate enrollment for Client to Site VPN over Site to Site VPN Tunnel fails Technical Level
  • Certificate enrollment for C2S over S2S fails
  • Traffic which returns from the Management Server over port 18264 is being forwarded to the actual IP address of the VPN Client machine in *clear* traffic instead of being encrypted and sent as ESP traffic.

Traffic on port 18264 is not being tagged as VPN traffic and is instead sent in "clear" because it is accepted by an implied rule.

