The interface you connect to should have host-inbound-traffic system-service ssh enabled. If you pass through another zone to reach this interface you should have a policy to allow you to reach the destination ip. Ssh should be enabled as a system service. That's all I can think of.
Screenie. Juniper Ambassador, Instructor,JNCIP If this worked for you please flag my post as an "Accepted Solution" so others can benefit. A kudo would be cool if you think I earned it.