So the consultant from the Inks company phoned again, and needs a little help. Seems that the HP JetDirect printing to some of their sites has broken, since the transition to the new network.
A bit of a look, and some disabling and re-enabling some functions later, and we get back to everything working for a site connected via an IPSec VPN link, with no overall changes.. but now it works.
For the other site, we have an issue that might have been a TCP MSS size problem (connections starts, but fails to transfer data). Fudged the Juniper WX devices with a lower MSS size for accelerated traffic but no dice. It did appear as if the hard disk was busy, so took the traffic out of NSC (the disk based compression engine), again no dice. Disabled TCP acceleration, and everything’s hunky-dory..

The only part of the network which had Junipers at both ends was the other providers connections between the data centers. I’m still certain that they fudge the MTU on their network, even though the changes to MSS should have worked around this. Still another case to open with JTAC. At least we have full traces and diag files for this one.