The url below is very detailed about how to setup a VPN with Overlapping Subnets. In that doc it states that you'll need to create the following Static route: page 9
Network > Routing > Destination > New trust-vr: Enter the following, then click OK.
IP Address/Netmask: 0.0.0.0/0 Next Hop: Gateway Interface: ethernet0/3 Gateway IP Address: 220.127.116.11
This route uses IP 18.104.22.168 as the Gateway, but in the Diagram on page 6 the Gateway should be 22.214.171.124. is this an over site or is this this something that needs to be done while configuring the Tunnel? In the initial configuration of the Firewall there would already be a cleanup route for 126.96.36.199.