This thread was automatically locked due to age.
Hi, P M, and welcome to the UTM Community!
If you haven't added the LAN to 'Local Networks' in the SSL VPN Profile, you shouldn't need that DNAT. Which IPs are being reached, where are they and what test reveals them as reachable? If it's a ping, what happens if you test after de-selecting 'Firewall forwards pings' on the 'ICMP' tab of 'Firewall'?
Cheers - Bob
The other "trick" is Web Filtering - I bet you have "VPN Pool (SSL)" in 'Allowed Networks' there. You might be interested in a document I maintain that I make available to members of the UTM Community, "Configure HTTP Proxy for a Network of Guests." If you would like me to send you this document, PM me your email address. I also maintain a version auf Deutsch initially translated by fellow member hallowach when he and I did a major revision in 2013.
Cheers - Bob