What are the subnet masks and interface configurations for the DMZ?
Are the VIP and "real" addresses here overlapping?
does the DMZ interface overlap with the untrust interface?
For other factors to look at in your monitoring system for the SSG
Bandwidth utilization
CPU stats