In FortiOS SD-WAN, application steering heavily relies on the ISDB application cache for first-packet classification. The exhibits reveal that the destination IP 23.212.248.205 (shown in the FortiAnalyzer log) is absent from the internet-service-app-ctrl-list cache. Therefore, the session's 3-tuple does not match the cache, causing initial packets to bypass rule ID 1 and hit the implicit SD-WAN rule.
Furthermore, once Application Control correctly identifies the "GoToMeeting" payload later in the TCP stream, FortiOS attempts to re-evaluate the routing. However, because Source NAT (SNAT) has already been applied to the session (indicated by the snat entry in the log), FortiGate cannot dynamically refresh the routing to a new interface without breaking the established connection, forcing it to remain on the implicit rule path.