Just in case someone else runs into this, when your troubleshooting disable this in the firewall IP Source Address spoofing protection change to LOG if you have a dup subnet that worked in the past, the MX might think it's spoofing a subnet on the MX.
... View more