PA dropping packets on their return path


I have a simple L3 setup.

E1/1 connected to a router (default gateway to the internet). IP, untagged Zone VLAN1

E1/2.2 connected to a switch (VLAN 2 tagged). IP (default gateway for the network), Zone VLAN2

I have a default allow all rule, no nat (VLAN2 to VLAN1)

A ping from to doesn't work, so I started troubleshooting.

Monitor shows to, Application "ping" allow

It does not mention any drops.

I did a tcp dump on the internet gateway and I do see request and reply getting in and out. All correct source / destination.

I did a tcp dump on the PA. I see the following in the 4 pcap files:

Receive: Echo request and reply

Transmit: only Echo Request

Firewall: Echo Request and reply

Drop: Echo reply

So, the question which drives me crazy is: Why is the PA dropping the echo reply packets and why is it not telling me that it has done so?

