I have an issue with one my my VPN tunnels only allowing one way traffic. its a B2B tunnel for an APN. My APN connected devices are able to communicate to on site resources over the tunnel, but my on site devices can't communicate with the devices on their encryption domain. (r81.20, 3.10)
Checking the logs I found the following :
"dropped by fw_ipsec_encrypt_on_tunnel_instance Reason: No error - tunnel is not yet established;"
This VPN is configured as a Star community, the Encryption settings are all correct and match. It is configured as "One VPN tunnel per Gateway Pair", with VPN routing of "To center or throug hthe center to other satellites..." , and "disable nat inside the vpn community"
We have a few tunnels that probably have poor configurations. Multiple have our encryption domain as 10.0.0.0/8.
My other tunnel are functioning fine. I expect we have a configuration issue that I'm not seeing.
Help is appeciated. Thank you