You fw doesn't know how to get to the destination address as it is on both sides of the firewall. You would need to be in non-routed mode for the layout you depict. I would recommend taking the 192.168.x.X network off the router, switch and firewall....