Do you have any firewalls in between the edges and cores? The fact that your connections are not seeing any peers and some blacklisting may show that something is blocking autodiscovery, possibly due to the TCP options during the syn/syn-ack.
Another thing to look at is if you are intercepting on all of your WAN egress points? Possibly some asynchronise routes where you are not doing interception? Doing traceroutes from the client and server side will assist in tracking something like that down.
The command in 4.0 is "sh tfo auto-discovery list". Another good on is to do "edge-fe1#sh tfo auto-discovery blacklist" to see if you are getting a lot of hits on connections that are getting dumped by firewalls or other deep packet inspection technology.
Dan