1: Strange that I don;t see any packet for 192.168.99.109 at least I should see the packet getting decrypted on the device. Please set the filters as below:
set ff src-ip 172.31.99.63 dst-ip 192.168.135.1.
set ff src-ip 192.168.135.1. dst-ip 172.31.99.63
set ff src-ip 172.31.99.63 dst-ip 192.168.99.109
set ff src-ip 192.168.99.109 dst-ip 172.31.99.63
use 'unset ff' multiple times till the time old filters are not removed.
2: output of 'get route ip 192.168.99.109"
3: What is the the proxy ip/ split tunneling configured on the NCP client?
Thanks,
Vikas