If you are connected to your client-to-site VPN and having issues logging in to your Avaya soft phone agent, make sure that your forwarding rule is set to 'No SNAT' for connection type and that the 'bi-directional' box is check marked. The Avaya agent will actually create its own connection back to the client in order to complete the login process instead of simply replying to the initial connection by the client. If the forwarding rule is not bi-directional, or if a separate rule is not made to allow traffic back, then the login may fail.
Additional Info: none