Try all the following from Member 1 while it is active.
As mentioned earlier you'll need to use tcpdump -e to verify the inbound destination MAC address is correct when Member 1 is active.
If you have verified that, next step is to verify that the traffic is reaching the Firewall Worker (INSPECT) with fw monitor -F, in particular the "i" capture point. If packets are showing up in tcpdump but not reaching "i" you have some kind of inbound layer 2 networking problem like ARP.
If the traffic is reaching "i", next step is to run fw ctl zdebug drop which will display all traffic dropped by INSPECT/SecureXL in real time and the reason.
If the traffic is not being dropped, use fw monitor to verify the traffic is reaching "i" then "I". You should next see that packet enter "o" but if it doesn't, you have a layer 3 routing problem in Gaia.
In fw monitor -F assuming the packet reaches "o" it should next go through "O". If it goes through "O" but does not appear in a tcpdump on the egress interface or actually get transmitted to the network, you have an outbound layer 2 networking problem, such as the inability to form an IP-MAC mapping for the next-hop router or destination.
Gateway Performance Optimization R81.20 Course
now available at maxpowerfirewalls.com