We have an internal site-to-site VPN that we've been running for years now where our firewalls send traffic through another firewall just fine. However, after the JHF, the remote firewall is now stating this traffic should be encrypted when the firewall is sending from an IP not in the VPN Domain. See diagram below:
[VPNDomainNetA] --- [FWA]TX --- [LANA] --- [PrivateWAN] --- [LANB] --- [FWB] --- [VPNDomainNetB] --- RX[ServerB]
So FWA is sending (TX) from its LANA interface to ServerB (RX).
Why is FWB now considering this something that should be encrypted post hotfix? Obviously we can't add FWA LANA's IP to the VPN Domain as that would break all kinds of other stuff. Having to follow sk86582 (as TAC suggested) seems a bit ridiculous. Firewall interfaces not in the VPN Domain networks shouldn't be considered in the VPN Domain network.