Have some machines that need to connect to the server side of the IP SEC on port 8288 (web server) but the traffic is going to the server and it seem to not know how to return.
Trace route from the client side lands on the server but when running a trace route from the server side back to the client it cant route… all other traffic is flowing and fine across the site to site.
I suspect your problem is due to what I call “The lazy mans” routing, i.e. NATing, packets are being src NATed one direction and gets to destination and back, but from destination routing is failing.
But as per @sindy, very difficult to say exactly where problem is without more info