Hello,
For a period of time, the solution proposed by @dcaporetto worked also for me, but starting with one month ago I start having problems with Anydesk clients. After investigation, the following solution work for my PA:
Imported into my PA the AnyNet Root CA certificate and marked as Trusted Root CA (a big thank you to @dcaporetto for the certificate)
Create a service object for TCP 80 and 6568
Create a custom URL list for:
anynet%20relay/
anynet%20relay:80/
anynet%20relay:6568/
anynet relay:6568/
anynet relay:80/
anynet relay/
Create a decryption profile with "Block sessions with expired certificates" and "Block sessions with untrusted issuers" checked on No Decryption tab
Create a decryption policy with action of NO-DECRYPT using custom URL categories and services configured above as match criteria and action of NO-DECRYPT
... View more