I had a jtac case opened, they eventually pin pointed to the problem after getting tier2 support.
For anyone else having the same type of zones/vr like I do.
You must have in your static nat rule specified the proper routing instance of default!
If you specify any other routing instance including the vr it wont work!
If you specify no routing instance it will not work!
Of course each case varies, so in other cases you may need the routing instance your-vr-router;
in my case it was like so
rule test-rule {
match {
destination-address 208.184.x.x/32;
}
then {
static-nat {
prefix {
10.1.20.216/32;
routing-instance default;
}
}
}
}
Hope it helps someone in the future.