Did you ever find a solution to this problem? I have the same issue with a StrongSwan, although a simpler setup without NAT. I'm using an external IP as my peer IP, so no loopback. Ping works both ways, although not for every packet size. E.g. From the firewall (inside interface) size=1080 works but not 1085, size=282 works but not 283 !? Traffic is flowing from local site, but no reply is ever received. I did a packet capture on the tunnel interface, and see the three-way handshake, but when our host does a http GET, I see no reply. Very odd. We're running PANOS 7.0.14 and we have numerous other VPN's up and running, but only this one with Strongswan.
... View more