Hi Gokul,
Thanks for your advice.
Do i need to NAT the Untrust port? Or the port which facing the VPN tunnel (trust zone)?
My config: port 0 (un-trust) and bgroup 0 (trust).
I've enable the policy - untrust (side B) to trust (LAN to server) which changed the action indicator color from green to blue