Hi davejr ,
As i understood , You cannot ping some subnets ( not directly connected to the firewall ) from your new PCI Zone which is at your new virtual router PCI-VR
1.1.1.X (e0/0) (e0/1) 2.2.2.X
Subnet1....layer3 Router.............................PCI-VR............Trust-VR.........................layer3 Router........Subnet2
For Subnet1 to be able to ping Subnet2 , you need 2 routes + 1 policy :
Route on PCI-VR :
set vrouter "PCI-vr"
set route Subnet2/24 vrouter "trust-vr" ( if you want to reach Subnet2 your next hop is Trust-VR)
Route on Trsut-VR:
set vrouter "trust-vr"
set route Subnet2/24 interface ethernet0/1 gateway 2.2.2.2 ( if you want to reach Subnet2 your next hop is e0/1 )
For Subnet2 to be able to ping Subnet1 , you need 2 routes + 1 policy :
Route on Trsut-VR:
set vrouter "trust-vr"
set route Subnet1/24 vrouter "PCI-vr" ( if you want to reach Subnet1 your next hop is PCI-VR)
Route on PCI-VR:
set vrouter "PCI-vr"
set route Subnet1/24 interface ethernet0/0 gateway 1.1.1.1 ( if you want to reach Subnet1 your next hop is e0/0 )
If this still could not help you , please post your configuration + specifying from which IP you are not able to ping which ip
************** Click on the button saying " Accept as Solution" if My Post solved your problem **************