Thanks for the clear diagram.
1-You need a policy on SSG 192.168.100.0/24
untrust (eth0/0 if default) to Trust (bgroup0 if default) to allow the inbound traffic
If you have the default nat policy in place on SSG 192.168.100.0/24 than you are done.
If not, you need a static route on SSG 192.168.1.0/24
192.168.100.0/24 next hop eth0/0 interface on SSG 192.168.100.0/24