Ok I have got a little further with this one; I can see from the VIA logs it says it failed to download configuration.
we have 443 / 4500 traffic open to the external IP address of our controller ... I’m wondering if this check / configuration update happens on the inside address? It does the check after the VPN is connected ... I’m wondering if our Windows firewall is still on the public profile and is blocking this request to an “inside” address?