Hello,
I checked "Log packets that are handled by this rule" on each IPsec VTI interface TCP rule with dst port 179. In packet capture I see packets to port 179 on each IPsec VTI interface but I do not see them in the firewall log...
Theyre probably matched by a rule further up in the ruleset. Check Floating and extend the Automatic Generated Rules.
Not all traffic is logged in the FW logs, only connection establishment.
So if there's already session/state for that traffic, no FW logs will be generated.