panorama uses ssl on a non standard port, the application is also dependent on ssl (this means ssl needs to be allowed also)
there could have been a condition where, because there is app-default configured and also a very short security policy, appid was a little too fast and tagged panorama traffic as ssl on a non-default port and rejected it
if this persists you should reach out to TAC to have the AppID verified, but this will probably solve itself once you have a slightly larger security policy
... View more