Hi,
I now have the trial vMX's setup and running on Alibaba Cloud and part of my Org. However, I'm struggling to get the basic setup working.
My current setup is:
The end goal is this topology:
As a side note, I would prefer to keep the London <> Hong Kong Office AutoVPN as it is as latency is good at 210ms. I would prefer to avoid the scenario below, where these sites are both spokes to the HK vMX as this increases latency between these sites.
...would like to avoid this setup, if possible
Anyway, back to my point, in the vMX's > Security & SD-WAN > Site-to-Site VPN, it says about adding routes to the upstream router.
I presume this means the Alibaba Cloud VPC. Here, I have created static routes for 192.168.110.0/24 (which is the network the HK Office MX64 is in), next hop = ECS instance (HK vMX)
However, with this in place, if I go to the HK Office MX > Appliance Status > Tools > Ping the internal IP of the HK vMX, I get no reply (100% loss).
When looking at Organization > VPN Status, I see all sites connected. On the HK vMX, if I run a packet capture on the site-to-site VPN I get nothing at all🤨
What am I missing? Thanks in advance.