Hey @Brandon_Wertz , thank you again, took off some time today to try this out, as I was very curious.
Here are the screenshots if you would still be interested in landing me some more insights :
Below are the results of a ping from branch fw 172.28.89.252 to a natted host behind main fw, 172.28.89.248
Logs from Main FW (172.28.89.254). As you can see the ping arrives well through the tunnel.
And below the wireshark results on the natted host 172.28.89.248, with the infamous no response found icmp packets even with ECMP enabled on both sides quite unfortunately :
For completeness sake here are the related routes left in my VR configuration on Main FW ... technically you can disregard the last 2 routes, they are remainings from previous tests, only the first one really matters in this.
And VR on the branch FW looks like this:
As a side note the packet wouldn't reach branch FW without the last explicit route ... Strange.
Both sites have ECMP enabled on their VR like so :
Any suggestion ? 😇
... View more