We experience inconsistent user experience when using the internal network or on-network, there are times that we can access the site or not and no logs are captured. We are using AD users' identities only that shared information with roaming client. Roaming is working when off-network and hits the policy and has logs. All users are domain-joined. When in on-network we have tunnels going to umbrella. What could be the possible solution in on-network that should hit the same policy as when off-network? We also tried using DNS forwarder but the status is unable to resolve. Could the routing to the tunnels be the issue?