I would think (without trying) it should be something like this
set interface tunnel.2 ip x.x.x.x/30
set interface tunnel.2 tunnel encap gre
set interface tunnel.2 tunnel local-if trust dst-ip 220.127.116.11
With 18.104.22.168 the tunnel on the cisco
abd then ofcourse a route to the destination with tunnel.2 as gateway.
I read somewhere in releasenotes the tunnel interface should be in the same zone as the endpoint interface, but can;t remember the details.