Ensure the client side also uses the initial destination connection ID for decryption purposes instead of the one from the current long header packet. PCAP from local WiFi hotspot.