Hi @Matie ,
Welcome to the community.
If I understood correctly the topology, traffic is coming via VLAN10 and should be routed, via VAL23, towards the ISP router.
I would start the troubleshooting looking at the routing table and the traffic flow (while generating traffic):
get router info routing-table all
diagnose debug flow filter addr x.x.x.x <---where x.x.x.x is the source of the traffic
diagnose debug flow trace start 10
diagnose debug enable
Looking at the policy that should allow the traffic, we can see that, at some point, there was some traffic that matched it.