1. Confirm that the ACL configuration is correct and the express port forwarding is disabled.
2. Debug the USG2110. The debugging result shows that the data is not encapsulated with a tab, so the firewall discards the data.
Handling Procedure: The intranet IP addresses of the firewalls on both ends of the tunnel can be pinged through after the IP address is encapsulated with VLAN. The problem is solved after the subinterface of the USG2110 is encapsulated with VLAN.