which would solve the problem in a more holistic way, as the IKE-SA between client and GW would be maintained even when the client changes its IP address or it would move the traffic over a different interface. So with mobIKE configured, the VPN disconnect and re-connect mechanism could maintain the same IKE-SA during soft-lock with the loadbalancer being able to route the traffic to the correct GW. -> According to Chi mobIKE is already implemented but not activated as a feature in 10.1 but this could be done for 10.2. Secusmart could then use mobIKE in its VPN extension.