Some more logs which may be more helpfull:
Cannot obtain tunnel from Policy? Any Ideas?
This is from Traffic between Trust and Untrust Zones:
Sep 16 11:50:53 OfficeFW01 clear-log[7926]: logfile cleared
Sep 16 11:50:55 11:50:54.1465871:CID-0:RT:<192.168.30.15/132->192.168.1.222/1;1> matched filter MatchTrafficIN:
Sep 16 11:50:55 11:50:54.1465871:CID-0:RT:packet [60] ipid = 383, @423c6640
Sep 16 11:50:55 11:50:54.1465871:CID-0:RT:---- flow_process_pkt: (thd 2): flow_ctxt type 1, common flag 0x0, mbuf 0x423c6400, rtbl_idx = 0
Sep 16 11:50:55 11:50:54.1465871:CID-0:RT: in_ifp <junos-self:.local..0>
Sep 16 11:50:55 11:50:54.1465974:CID-0:RT:flow_process_pkt_exception: setting rtt in lpak to 531580a8
Sep 16 11:50:55 11:50:54.1465974:CID-0:RT:pkt out of tunnel.Proceed normally
Sep 16 11:50:55 11:50:54.1465974:CID-0:RT: vlan.1:192.168.30.15->192.168.1.222, icmp, (8/0)
Sep 16 11:50:55 11:50:54.1465974:CID-0:RT: find flow: table 0x493482b0, hash 55308(0xffff), sa 192.168.30.15, da 192.168.1.222, sp 132, dp 1, proto 1, tok 7
Sep 16 11:50:55 11:50:54.1465974:CID-0:RT: no session found, start first path. in_tunnel - 1291609452, from_cp_flag - 0
Sep 16 11:50:55 11:50:54.1465974:CID-0:RT: flow_first_create_session
Sep 16 11:50:55 11:50:54.1465974:CID-0:RT: flow_first_in_dst_nat: in <vlan.1>, out <N/A> dst_adr 192.168.1.222, sp 132, dp 1
Sep 16 11:50:55 11:50:54.1465974:CID-0:RT: chose interface N/A as incoming nat if.
Sep 16 11:50:55 11:50:54.1465974:CID-0:RT:flow_first_rule_dst_xlate: DST no-xlate: 0.0.0.0(0) to 192.168.1.222(1)
Sep 16 11:50:55 11:50:54.1465974:CID-0:RT:flow_first_routing: call flow_route_lookup(): src_ip 192.168.30.15, x_dst_ip 192.168.1.222, in ifp vlan.1, out ifp N/A sp 132, dp 1, ip_proto 1, tos 0
Sep 16 11:50:55 11:50:54.1465974:CID-0:RT:Doing DESTINATION addr route-lookup
Sep 16 11:50:55 11:50:54.1465974:CID-0:RT: routed (x_dst_ip 192.168.1.222) from untrust (vlan.1 in 0) to vlan.0, Next-hop: 192.168.1.222
Sep 16 11:50:55 11:50:54.1465974:CID-0:RT: policy search from zone untrust-> zone trust (0x0,0x840001,0x1)
Sep 16 11:50:55 11:50:54.1466254:CID-0:RT: app 0, timeout 60s, curr ageout 60s
Sep 16 11:50:55 11:50:54.1466254:CID-0:RT:flow_first_src_xlate: nat_src_xlated: False, nat_src_xlate_failed: False
Sep 16 11:50:55 11:50:54.1466254:CID-0:RT:flow_first_src_xlate: src nat returns status: 0, rule/pool id: 0/0, pst_nat: False.
Sep 16 11:50:55 11:50:54.1466254:CID-0:RT: dip id = 0/0, 192.168.30.15/132->192.168.30.15/132
Sep 16 11:50:55 11:50:54.1466254:CID-0:RT: get_nsp_tunnel - Tunnel not found. if vlan.0, nexthop ip 0xc0a801de, policy id 10
Sep 16 11:50:55 11:50:54.1466254:CID-0:RT: packet dropped, cannot obtain tunnel from policy
Sep 16 11:50:55 11:50:54.1466384:CID-0:RT:cannot obtain tunnel from policy
Sep 16 11:50:55 11:50:54.1466715:CID-0:RT: flow find session returns error.
Sep 16 11:50:55 11:50:54.1466715:CID-0:RT:flow_process_pkt_exception: Freeing lpak 3fcec9e8 associated with mbuf 0x423c6400
Sep 16 11:50:55 11:50:54.1466737:CID-0:RT: ----- flow_process_pkt rc 0x7 (fp rc 0)
This is betwen DEG Zone and Untrust Zone:
Sep 16 12:01:32 12:01:31.1263543:CID-0:RT:packet [60] ipid = 557, @423e7dc0
Sep 16 12:01:32 12:01:31.1263543:CID-0:RT:---- flow_process_pkt: (thd 2): flow_ctxt type 1, common flag 0x0, mbuf 0x423e7b80, rtbl_idx = 0
Sep 16 12:01:32 12:01:31.1263543:CID-0:RT: in_ifp <junos-self:.local..0>
Sep 16 12:01:32 12:01:31.1263543:CID-0:RT:flow_process_pkt_exception: setting rtt in lpak to 531580a8
Sep 16 12:01:32 12:01:31.1263543:CID-0:RT:pkt out of tunnel.Proceed normally
Sep 16 12:01:32 12:01:31.1263543:CID-0:RT: vlan.1:192.168.30.15->192.168.220.10, icmp, (8/0)
Sep 16 12:01:32 12:01:31.1263543:CID-0:RT: find flow: table 0x493482b0, hash 7312(0xffff), sa 192.168.30.15, da 192.168.220.10, sp 140, dp 1, proto 1, tok 7
Sep 16 12:01:32 12:01:31.1263543:CID-0:RT: no session found, start first path. in_tunnel - 1291609452, from_cp_flag - 0
Sep 16 12:01:32 12:01:31.1263753:CID-0:RT: flow_first_create_session
Sep 16 12:01:32 12:01:31.1263753:CID-0:RT: flow_first_in_dst_nat: in <vlan.1>, out <N/A> dst_adr 192.168.220.10, sp 140, dp 1
Sep 16 12:01:32 12:01:31.1263753:CID-0:RT: chose interface N/A as incoming nat if.
Sep 16 12:01:32 12:01:31.1263753:CID-0:RT:flow_first_rule_dst_xlate: DST no-xlate: 0.0.0.0(0) to 192.168.220.10(1)
Sep 16 12:01:32 12:01:31.1263753:CID-0:RT:flow_first_routing: call flow_route_lookup(): src_ip 192.168.30.15, x_dst_ip 192.168.220.10, in ifp vlan.1, out ifp N/A sp 140, dp 1, ip_proto 1, tos 0
Sep 16 12:01:32 12:01:31.1263753:CID-0:RT:Doing DESTINATION addr route-lookup
Sep 16 12:01:32 12:01:31.1263753:CID-0:RT: routed (x_dst_ip 192.168.220.10) from untrust (vlan.1 in 0) to vlan.2, Next-hop: 192.168.2.1
Sep 16 12:01:32 12:01:31.1263753:CID-0:RT: policy search from zone untrust-> zone DEG (0x0,0x8c0001,0x1)
Sep 16 12:01:32 12:01:31.1263753:CID-0:RT: app 0, timeout 60s, curr ageout 60s
Sep 16 12:01:32 12:01:31.1263753:CID-0:RT:flow_first_src_xlate: nat_src_xlated: False, nat_src_xlate_failed: False
Sep 16 12:01:32 12:01:31.1263753:CID-0:RT:flow_first_src_xlate: src nat returns status: 0, rule/pool id: 0/0, pst_nat: False.
Sep 16 12:01:32 12:01:31.1263753:CID-0:RT: dip id = 0/0, 192.168.30.15/140->192.168.30.15/140
Sep 16 12:01:32 12:01:31.1263753:CID-0:RT: choose interface vlan.2 as outgoing phy if
Sep 16 12:01:32 12:01:31.1263753:CID-0:RT:is_loop_pak: No loop: on ifp: vlan.2, addr: 192.168.220.10, rtt_idx:0
Sep 16 12:01:32 12:01:31.1263753:CID-0:RT:jsf sess interest check. regd plugins 18
Sep 16 12:01:32 12:01:31.1263753:CID-0:RT: Allocating plugin info block for 18 plugin(s) from OL