Try running the debug again, but this time use the following ping commands.
SSG-140:
ping 192.168.1.1 from bg0
SSG-320:
ping 172.16.10.1 from eth0/0
This will specify the source IP addresses as your internal IPs. Per your configuration, only traffic from/to "192.168.1.0/24" and "172.16.10.0/24" will be permitted through the tunnel. The prior attempt, you were sourcing the traffic from your public IP addresses.