We have s2s (terminated on FWext) to mng network in customer environment and we can connect to all assets (include both MDSs and CMAs not related to FWext) except both CMAs (from domain where FWext is used in policy).
I tried to debug the issue and I found that the return packet from CMA goes to FWext, but FWext used routing table and send it to some interface not into s2s tunnel.
Because it is not a critical problem for us, I do not want to open SR on it and rather try to find a solution by digging deeper.
So mine question, do you have any idea where to start (I think it will be matther of kernel debug commands but I'm not sure).