Hi lobstercreed ,
Thanks for your answer, I noted what you are talking about that the firewall pointing out the destination interface as "SSL.root ", but the way the application server located in LAN and there is no DMZ, the firewall has only two interfaces connected to LAN and WAN.
as I mentioned above the traffic is accepted by the firewall when I'm using any VPN application like VPN Express or Urban VPN from my PC and when I disconnect the VPN then I'm not able to connect to my application and got the same message in the firewall logs, also the policy ID that was blocking the traffic id policy ID = 0 which I think this is the global deny policy which blocking any traffic not mentioned in the rules created.
please check the attached picture.
please give me your opinion, I can send you a screenshot of the firewall rules.