On the SSG the zone selection for firewall policy match is based on the routing table. So the policy untrust to trust is selected because the route to the destination address is to an interface in your trust zone and not your DMZ zone.
On the SSG the zone selection for firewall policy match is based on the routing table. So the policy untrust to trust is selected because the route to the destination address is to an interface in your trust zone and not your DMZ zone.