This website uses cookies essential to its operation, for analytics, and for personalized content. By continuing to browse this site, you acknowledge the use of cookies. For details on cookie usage on our site, read our Privacy Policy
I had the same issue on my passive firewall, active firewall does not have issues. Come to find out I had SSL Decryption policies that was preventing the traffic since the CA that Palo Alto is using for 'apitrusted.paloaltonetworks.com' is not a trusted CA (weird). I wasn't decrypting the traffic, just validating certificates. I downloaded the CA cert and imported and marked as "trusted ca". Things seem to be working now. LOG: show log decryption dst in 35.238.43.180 2021/10/28 04:44:20 ssl Trust 48978 [INTERNAL-IP] [RULE-NAME] allow Untrust 443 35.238.43.180 TLS1.2 ECDHE AES_256_GCM SHA384 No Decrypt apitrusted.paloaltonetworks.com Palo Alto Networks Inc.-SJC-Ser Untrusted issuer CA
... View more