UTM Vulnerable to clickjacking

Hey All,

I have a weird one.

We have 2 UTMs, both running 9.705-3 doing WAF for Exchange Server deployed per the KB -

Everything is working fine, but we are renewing our annual security test including a PenTest
One of these is showing as vulnerable to clickjacking and one is not

I have gone through the config side by side and both look identical, i cant figure it out. 

The links offered up by the PenTest software are:

But i can't find a way to insert these headers. 

If i test with one does load the page (which it shouldn't) and one does not load the page denying the connection (which should be the behaviour) so something isn't set correctly, its just where to change it

Can anyone shove me in the right direction?

