Can't filter firewall policy based on user group
Hello everybody,
I have a firewall policy regarding an IPSEC tunnel.

This policy is saying that all the addresses that belong to ipsec_range can reach the internal destinations.
This policy, if I connect, is working fine:

I can reach on of  my VMs:

 
Everything is all right.
What's the problem?
The user that has connected to the tunnel, belongs to a group:
 
Let's suppose I  want to say:
I want to filter the source not only by ip address, but also by user group.

the same user has an address in ipsec_range and also belongs to IPSEC_USER.
Everything should be okay, right?
No! I can't reach my VM anymore. What am I doing wrong?

 
