Hi, We have two warm spare sets in our DC's, MX-A and MX-B. They are set as VPN concentrators, as hubs connected to spoke sites and each other. The two DCs have an interconnection, and MX-A and B can reach each other over their Lan IP as well as over their internet NAT IP. When I do packet captures I can see and confirm the A and B site are actually communicating with each other over AutoVPN UDP ports. I can see traffic over the Lan IP adresses and also over the NAT Wan IP addresses (green dotted lines on diagram included). Is there any way to check / confirm which path is actually active? It seems the MX is keeping tunnels up on both paths, but I can't find anything in the dashboard so far to confirm this. I found below online, which makes sense. But is there any way to get insight in to which paths are available and active: "For each MX, the cloud decides whether to use its interface (potentially private) or public IP address to establish a secure VPN tunnel. When possible, an MX’s WAN IP address will be used; this can provide shorter VPN paths between peer MXs (e.g. when multiple VPN peers are connected through MPLS to a primary data center, and from there, out to the Internet)" Thanks, Frank
... View more