Just about any policy problem with a ProxySG will require “Trace” information to debug the issue.
For troubleshooting problems with policy files or to monitor evaluation for brief periods of time, use the policy tracing capabilities of the policy language.
There are two types of policy trace in proxySG:
Global Policy Trace (hurts performance when enabled!)
Browse to Console -> Policy -> Policy Option
Within CLI, enter “policy trace all”, to enable, and remember to later enter “policy trace none” to avoid performance impact.
Selective Policy Trace (Less performance impact than global)
Within VPN, use Track -> Set -> New -> trace