Hi guys, I'm trying to use a site to site VPN for the first time and can't seem to find the issue. I have two MX100s both of which have their Internet ports connected to a switch giving them an IP and access to the Internet. Then on their lan ports are either side of the Cisco switches I have plugged in. Upstream is a 3850 and downstream is a cat9300. when I connect these directly with static routing, IPs on the interfaces with no switchports they work fine and all subnets are available and routing. However when I insert the two MX devices in layer 2 passthrough mode the VPN comes up, but there is no connectivity between the 3850 and the 9300. On the 3850(upstream) side I have the local subnets as 0.0.0.0/0 which is a default route and on the 9300(downstream) side there are subnets setup for a /16 as well as the /30 point to point link. Both MX devices are configured as hubs and setup for passthrough or VPN concentrator. Anyone else run into this issue in this scenario?
... View more