By default the "Accept connections only from the ePO Server" setting is enabled in the McAfee Agent Policy in ePO 4.5, this is in place for added security. You can simply uncheck this and you should be able to view the log.
As for the VSE policies, do any of them enforce? What are you specifically trying to lock?
With each product and patch release there is a readme which has a "Known Issues" section. As new issues are discovered, we do publish these to the McAfee KB as readme addendums.