In your case i can believe there could be something going on on your firewall since UAG is a layer7 firewall understanding protocols at the application layer, so maybe the facts that the gateway-va is doing all those redirects could trigger some security feature that needs to be correctly addressed to make it work with Workspace.
In the other case we are talking about a normal NAT/òayer4 firewall that should just forward packets and never messup with protocols at the application level.
Unfortunately i have no experience with UAG and Horizon Workspace to give a specific help.