It's sounding more and more like a trend micro issue not liking the f5 in the middle.
But you can use tcpdump to see the flows. So things like
tcpdump -nni 0.0:nnnp 'host 192.168.201.37 ' -s0 -vvv
or
tcpdump -nni 0.0:nnnp 'port 8081' -s0 -vvv
Add -w /var/tmp/<filename>.pcap to the dump to capture the output and then you can review it in wireshark.
This should allow you to see the flows, the port 8081 one might look the best at the moment so you can see in and out. Or if you know the client IP add that with a or so 'host 192.168.201.37 or host 10.10.10.1' for example that should then let you see in and out.