Quote from: ednt on February 05, 2021, 01:21:54 PM
Ok, the ports where automatically enabled. (519,520)
In our case it was a problem of the NAT outbound rules:
This firewall should not use the VIP address when the destination is in the same net.
So invert destination and use as destination net the net of the rule.
As I am browsing the logs and comparing the configs I think our setup might have the same issue. Sadly I do not understand your solution with the NAT outbound rules. At least the last sentence makes no sense for me.