Hi stuman,
When you transfer larger files, do you think the sessions hit their idle timeout?
Why don't you start by sharing the configuration for the interfaces involved on the 240, the ones we transit on the 345s, the security zones each interface belongs to (with their respective security related services/protocols enabled), the security policies this traffic context transits?
A 'show interfaces | display set' should cover the interface snippet from both the SRXs, just point out which interfaces we need to be focusing on.
A 'show security zones| display set' should cover the zone related information, again display the zones from both the SRXs.
A 'show security policy from-zone <source-zone> to-zone <destination-zone> | display set' should cover policies belonging to the zone transit, point out the ideal policy this should be hitting on both SRXs please?
Cheers
Pooja
Please Mark My Solution Accepted if it Helped, Kudos are Appreciated too!!!