I was wondering if anyone else has ran into this issue before:
 
We just recently deployed an MX250 pair, along with the deployment of the Umbrella SIG Tunnels for SSL Decrypt among other services. Within this site we are hosting exchange and citrix. The MX holds the 1:1 Nat's. However with the SIG Tunnels active the 1:1 Nat's do not function as intended. We get asymmetric routing. Basically - Traffic comes in fine as expect (Wan1) - However when the server replies the return traffic is being sent out the SIG Tunnel and fails, and user gets page not found. Short from disabling the subnet from the VPN, we are unable to bypass the SIG Tunnels. Disabling isn't an option as this would not allow the subnet to utilize the SSL Decrypt and other policies from SIG.
Thanks in advance.