Hi,
First, the filter is set for a different IP, while you are trying to reach 10.20.5.7. The filter will nto capture this traffic.
As per your previous post, isn't the server IP 10.10.10.7.
Also, the debug should be run on the Site-A firewall, which would be the SSG-20:
<<<<<<<<<<<<<<<<<At Site A, the SSG box can reached the server since it is in the same subnet:
ssg20-wlan-> trace-route 10.10.10.7 from bgroup0>>>>>>>>>>>>>>>>