@viragomann
You are absolutely correct ... we had a reply-to issue.
The issue was cause by there not being a default gateway set on the Tier-2 interface, so it wasn't spotted as a WAN interface, so reply-to wasn't enabled.
Heaven only knows how long it had been that way, but now its set, everything works as advertised.
Thanks again for your time and effort ... much appreciated.
May the force be with you.
ChIP.