We are planning our deplyment strategy for upgrading our two UTM boxes in HA to XG. We have upgraded one to XG and have it configured and ready to test. Since we allow remote access using the SSL VPN service and will need to redeploy user configurations (XG no longer allows admins to download the client certificates en mass for OpenVPN), we are thinking of running both the UTM and XG boxes in tandem.
We think that this could work fine for testing firewall, needing only a change in gateway configurations to switch between them as the active gateway, but we would like to allow users to continue to connect to the UTM while we deploy the updated SSL VPN configurations for XG. In practice, we'd have users connecting to one or the other until we confirm that everyone is connecting to the XG for remote access.
Could this work? A question that has come up is whether, with the UTM as our default gateway, how is the remote access traffic on the XG routed? Would/should it use the XG as the gateway or the UTM?
This thread was automatically locked due to age.