If you capture on the LAN side of the MX you should see the packets coming from a client in your MX network towards your MX (source MAC address client, dest MAC address Meraki MX). However on the WAN side you could only see ESP packets leaving your WAN IP towards the WAN IP of the SRX. Looking inside the site 2 site VPN is definitely possible with AutoVPN but I'm not exactly sure with IPsec VPN if this works. Should test it out 😉 In the logging you should make sure you have a CHILD_SA with all the necessary traffic selectors active before you can see traffic actually passing. The little green dot in the VPN status page is NOT enough. The last thing that could be wrong is if you have any IPsec VPN firewall rules on the VPN page.
... View more