in the last week phones stopped being able to be provisioned in Ring Central. They need to get to pp.ringcentral.com:443. Pings to that site from a branch office with Meraki is failing. But pings and
https traffic to other sites works. My first through to troubleshoot tomorrow will be to have a phone
that needs to be provisioned and do a packet capture to see what's going on during that attempted
provisioning. 
 
But it's been some months since I looked at firewall looking. Is it possible to view all conversations allowed through the MX for a time period? I went to Sec & SD WAN/Security Center and selected all dispositions allowed or not. I started to enter the IP address of the provisioning server at RC 199.255.120.237 and the search box suggested I really wanted was remote_ip:199.255.120.237. Ok good enough. I hit enter and the time window is set to an overly generous 2 weeks. But still nothing shows up in the results. Am I searching for these conversations in the wrong place? 
 
Also a snapshot of the conversation is below. It looks like a phone 10.1.61.24 it trying to provision and the RC server is requesting a certificate 1.2TLS. Then the client ends up sending the cert but resending and resending. Any thought what's going on? Invalid certificate?
 

 
Thank you.