Hey Andy,
Sorry for the delayed response and many thanks for your kind offer. I really appreciate it.
Unfortunately, I am not allowed to do so...
May I know which Gaia OS version and take was working for you?
It's really strange behaviour that we can only see clear text on oneway from R81.10 to R81.20 but not the another way around.
In tcpdump on MPLS interface, we can only see echo reply, when do ping from R81.20 --> R81.10:
tcpdump -nnei bond11.14 host 172.31.55.165 and host 10.64.8.117 -s 0

And between R81.20 GWs, there even is no traffic can be seen on MPLS interfaces, except ESP traffic:
We tried several approaches like disable SecureXL, exclude GW's external IP addresses from VPN domain, exclude VPN encryption for MPLS links/IP ranges by modifying crypt.def from SMS, enable manual source IP address of chosen interface from link selection...But still no luck.
Do you perhaps have any other idea?
Many thanks again!
BR,
Andy