Hi, Thanks for the help. Unfortunately the actual domains are a bit sensitive so can't post a screenshot. Sorry for delayed reply. I did raise a TAC case and it turns out that there needs to be two "."s in the FQDN.
Won't work (will trigger the error not a valid FQDN):
not-workingdomain.com (only one .)
anything.com (only one .)
Will work:
workingdomain.co.nz (two .) <- this one is misleading, for this case, but it works!
vpn.not-workingdomain.com (two .)
The hint is on page 41 of the Identity Awareness admin guide where it says it has to be "ID.mycompany.com".
Cheers,
Andrew