Route-based IPsec VPN sessions established between two Tier-0 VRFs show a "Success" status, but data traffic fails to pass between the Virtual Tunnel Interfaces (VTIs).
get ipsecvpn tunnel stats

get ipsecvpn sad summary | find <remote_ip>get logical-router interface <uuid> | find IPsecThis is a known limitation. Inter-VRF ingress for IPsec VPN is not supported in these versions. For the NSX datapath to correctly process and decrypt IPsec traffic, the packets must ingress the Edge Node via a physical uplink interface.
Adjust the network topology to avoid IPsec ingress via Inter-VRF port.
For supported versions (9.1 and higher), verify if the configuration adheres to standard uplink requirements. For further assistance, contact support: Contact Broadcom Support.
For defects and enhancements, subscribe to this article (reference: Subscribe to a Broadcom knowledge article by article or product) to be updated on fix status.