So Fencing is just making a private instance of your public network.
Based on the screen capture, your picture the networking path looks kinda like this:
[VM on vApp Network]-[10.0.0.2]--------[vShield Edge with NAT Enabled]-[10.0.0.4 DNAT to 10.0.0.2]----- ? Then it would to to the default gateway defined for the network.
Is the 10.0.0.x network a Direct, Routed, or Isolated Org vDC Network?
You should just need to ensure that you can actually ping through. Can you provision any other VM on the same Org vDC network and do a ping test?
Is the vShield Edge on the same ESXi host as the VM with IP 10.0.0.2? If not, can you vMotion them to the same phyiscal host (no other changes) and see if the connection starts to work again?