Hi
Here below is the debug flow basic. I have also attached a little more detailed config experpt.
1.1.1.2 external ip
2.2.2.2 SSG firewall
****** 472511.0: <Untrust/ethernet0/0> packet received [82]******
ipid = 28685(700d), @0384c310
packet passed sanity check.
flow_decap_vector IPv4 process
ethernet0/0:1.1.1.2/2398->2.2.2.2/20409,17<Root>
no session found
flow_first_sanity_check: in <ethernet0/0>, out <N/A>
[ Dest] 95.route 1.1.1.2->2.2.2.1, to ethernet0/0
self check, not for us
chose interface ethernet0/0 as incoming nat if.
flow_first_routing: in <ethernet0/0>, out <N/A>
search route to (ethernet0/0, 1.1.1.2->10.238.135.227) in vr trust-vr for vsd-0/flag-0/ifp-null
no route to (1.1.1.2->10.238.135.227) in vr trust-vr/0
packet dropped, no route
****** 472513.0: <Untrust/ethernet0/0> packet received [82]******
ipid = 29032(7168), @03826b10
packet passed sanity check.
flow_decap_vector IPv4 process
ethernet0/0:1.1.1.2/2398->2.2.2.2/20409,17<Root>
no session found
flow_first_sanity_check: in <ethernet0/0>, out <N/A>
[ Dest] 95.route 1.1.1.2->2.2.2.1, to ethernet0/0
self check, not for us
chose interface ethernet0/0 as incoming nat if.
flow_first_routing: in <ethernet0/0>, out <N/A>
search route to (ethernet0/0, 1.1.1.2->10.238.135.227) in vr trust-vr for vsd-0/flag-0/ifp-null
no route to (1.1.1.2->10.238.135.227) in vr trust-vr/0
packet dropped, no route
****** 472519.0: <Untrust/ethernet0/0> packet received [82]******
ipid = 29812(7474), @03878b10
packet passed sanity check.
flow_decap_vector IPv4 process
ethernet0/0:1.1.1.2/2398->2.2.2.2/20409,17<Root>
no session found
flow_first_sanity_check: in <ethernet0/0>, out <N/A>
[ Dest] 95.route 1.1.1.2->2.2.2.1, to ethernet0/0
self check, not for us
chose interface ethernet0/0 as incoming nat if.
flow_first_routing: in <ethernet0/0>, out <N/A>
search route to (ethernet0/0, 1.1.1.2->10.238.135.227) in vr trust-vr for vsd-0/flag-0/ifp-null
no route to (1.1.1.2->10.238.135.227) in vr trust-vr/0
packet dropped, no route