Ohh thanks for detailed response.. Yes we have logged case but the response is slow...
Also I had got the support after few calls, they didn't really say why this is happening.. And we provided the logs but no response from them. But had asked them as well, but your flow makes sense. The VPN appliance resolves it for the client and then send the response but it fails to send in this scenario and hence the Sam policyisnt matching. The support just mentioned to add the hostnames.I had showed them that in psam client event logs, there is few errors related to dns queries and udp etc but they didn't tell anything and mentioned they ll need time to look into logs.