When troubleshooting SD-WAN connectivity issues using the "VPN Test" option from Remote diagnostics, customers might get the error "Branch-to-Branch VPN is disabled. Please enable it before running this test."
The "VPN test" feature aims to identify reachability issues from the source edge to peer edges that are supposed to be reachable through VCMP tunnels in the Overlay. This test will send ICMP packets from the source edge to peer edges in the SD-WAN overlay, according to the configuration in the Cloud VPN section. The source IP and destination IP addresses used to reach peer edges will be automatically selected by the source edge depending on the available destination routes in the Overlay and the source edge own available interfaces
If the edge from where the test is ran has only "Branch to HUB" enabled under Cloud VPN, the edge will use its static (already built) VCMP tunnels towards the configured HUB/s to send the pings
If the edge has also "Dynamic Branch to Branch" enabled, it will build the dynamic paths (dynamic VCMP tunnels) to the peer spokes at that moment in order to send the pings to the destinations
This test is complex, thus is important to understand how the feature works and be aware of all possible issues that might generate this error while attempting to run it
1. Cloud VPN is not enabled in the Segment selected for the test
2. The Edge cannot select a valid IP as the Source IP to initiate the tunnel requests.
3. The edge is not able to build VCMP tunnels to the Gateways (VCGs), thus, not getting the control plane information and routes from Overlay peers as expected from the Cloud VPN configuration. Check if there is an issue with the ISP or firewall preventing the edge to successfully build VCMP tunnels in UDP port 2426