IPSec Traffic Being Discarded
The IPSec SA is up. The show vpn flow command shows 0 decap packets. The IPSec session in the session table shows discard-flow.
The IPSec packets coming into the PAN device were not ingressing the same interface where the IPSec tunnel was terminated, but instead entering on another interface and being routed to the tunnel. As a result, the IPSec session was in a discard-flow state and dropping all packets coming in on the VPN.
The tunnel was moved to terminate directly on the ingress interface. The IPSec tunnel started seeing decap packet counters incrementing in the show vpn flow command ouput and traffic through the VPN worked fine.