Hi @amirimran Thank you for providing the screenshot. I think there are a few things to consider. Firstly, if you see the route as "Branch to Branch" or "Branch to Backhaul" on the spoke side "Flo...
See more...
Hi @amirimran Thank you for providing the screenshot. I think there are a few things to consider. Firstly, if you see the route as "Branch to Branch" or "Branch to Backhaul" on the spoke side "Flows" tab, it is completely expected if 1. There is a business rule using just the "Application Name" and not the IP address in the destination IP field and 2. A business rule under the above indicating the destination as "Internet" and backhauling traffic to the Hub. Reason is that VCE takes a few packets from the flows to read and identify the application name from the flow which involves a bit of time. During this process, as the application name for that flow is not yet determined, VCE sends the traffic out using the next best business rule. So for a few flows, seeing "Branch to Backhaul" is expected since it's backhauling the traffic to the Hub, and for many more flows "Brach to Branch" should be seen since the subsequent flows start hitting the policy that has just the application name. With respect to the Link Name not reflecting for a few flows, it's expected since for the flows that are being load-shared, it does not reflect the Interface or Link Name as it sends the traffic out of multiple links. Coming to the original query on why you are unable to access the application - 1. Please check if it's expected that the public route i.e., in the Flow dump that you shared, the route towards 52.123.128.14 is expected to be learnt from a remote branch. If not, please stop advertising it at the source VCE. If it's expected to be learnt from the remote branch, then you can take captures on the LAN side of both VCEs to check if the packets that are actually sent are reaching the other side. 2. Try configuring the business rule with IP address and play with it sending "Direct"/"Multipath"/"Backhaul" and observe the results. If you feel that VCE is dropping the traffic, please feel free to engage support and take it forward as this would have confidential data of your customer which they might not want to be discussed in this forum.