
1. Ping from 10.20.12.11 to 10.22.225.28, and check firewall session on the USG6650, there is no session table.
2. Ping from 10.12.11.1 to 10.22.225.28, and check firewall session on the USG6650, there is the right session table and pass.
3. traffic count on the firewall, find out that when Ping from 10.20.12.11 to 10.225.28, the destination port is 68.

Upgrade the software to V500R001C30SPC600 and install patch V500R001SPH001.