1. Check the policy between internal and ISP2, there is no rule to filter 40.x.x.69;
2. There are two primary route and stand-by route. If ISP1 link is down, the route via ISP2 will be effective.
ip route-static 0.0.0.0 0.0.0.0 41.x.x.65
ip route-static 0.0.0.0 0.0.0.0 39.x.x.49 preference 100
3. Shutdown the link between USG2200 and ISP1, and then trace the route from USG2200 to serve 40.x.x.69, the result is as below:
The trace log shows that the packets arrvied ISP1, which indicates that the route between ISP1 and ISP2 has no problem.
4. Checking configuration on USG2200, found abnormal configuration for 40.x.x.69:
firewall mac-binding 41.x.x.69 0006-xxxx-fc97
Because of the MAC binding on USG2200, and 0006-xxxx-fc97 is MAC address of ISP1 router. If packets reply from server to USG2200 via ISP2, the MAC address will be changed by ISP2. And the packets will be dropped on USG2200 because the MAC address which has been changed by ISP2 router cannot match the MAC binding on USG2200
5. Confirm with customer that the MAC biding configured before, but it's not updated when network is changed.