Scenario
A site-to-site VPN reports healthy, but devices on one subnet cannot communicate while others work.
Recommended Resolution Path
- Compare encryption domains, phase two selectors, and NAT exemption rules on both sides.
- Use packet captures to confirm whether interesting traffic enters the tunnel at all.
- Check for asymmetric routing caused by a newly added subnet or WAN edge change.
- Update tunnel documentation so the missing subnet is not forgotten during the next change window.
Technician Notes
Document what changed, what confirmed the fix, and whether the issue points to a broader standards gap worth addressing for the client.
- Log in to post comments
Subjects