Hello Jimp,
This is a fresh build for a new office, so there aren't many FW rules as yet. The IPsec S/S channel is essentially a copy of the Office3 stable IPsec S/S link, so nothing really exciting to see there.
VLAN3 has no specific host/port allow rules
Block rules to other VLANS/interfaces.
Allow all rule for internet.
VLAN3 is on LAGG0 along with 2 other VLANs (LAGG0 is 2x10GbE interfaces).
After stuffing around for another hour or so I gave up and rebuilt the unit from scratch last night.
I don't know what is going on but everything works fine this time around… I've compared the config.xml files and they are identical.
The problem is fixed but the issue is unresolved, guess we will never know.