VMware NSX
This is expected behavior when trying to apply both a DNAT and an SNAT NSX rule to the same stateful traffic flow in default NSX.
There are two known workarounds for this NAT-based workflow, detailed below;
Workaround
See KB NAT not working on NSX Tier0 router with or without IPSec VPN involved which details a workaround that prevents the above T1 and T0 hairpin for scenarios where both SNAT and DNAT are needed.