This KB provides detailed guidance on troubleshooting connectivity issues between two hosts within a Hub and Spoke SD-WAN topology. Specifically, the troubleshooting focuses on scenarios where the connection traverses an overlay tunnel between two SRX devices managed by Mist. While the KB is tailored for the PC-A to PC-B topology, many of the troubleshooting steps can be applied to similar scenarios involving other host pairs connected via overlay tunnels in Hub and Spoke architectures.
To troubleshoot connectivity issues and validate how the SRX is handling traffic, it's essential to conduct tests. In this scenario, we initiated a Ping from PC-A to PC-B to assess the behavior.
As the issue primarily concerns traffic initiated from PC-A (the spoke side), we began by inspecting this device. Using the >show security flow sessions with appropriate filters (such as source-prefix and protocol ICMP), we identified that the device was selecting the wrong Application Policy from Mist perspective or Security Policy if we see it from the SRX perspective. This resulted in the traffic being steered through the incorrect outbound interface.
Upon discovering this discrepancy, we adjusted the intended Application Policy to ensure alignment with the source of the traffic. With the correction implemented, connectivity was restored, and traffic between PC-A and PC-B resumed normal operation.
Additionally, when encountering similar issues, it is advisable to inspect security flow sessions for the traffic. This helps verify whether the traffic matches the parameters configured on the Mist Cloud, providing further insights into the issue.