With help from Sophos level 2 support, we were able to resolve the issue. Using SHA256 encryption was the culprit, so using SHA1 fixed the problem (supposedly a known issue). As I noted previously that an SNAT rule was required/added, it is not required so was also removed.
↧