dkjones21 On the F5 that is active in the HA pair I would run the following tcpdump.
tcpdump -nni 0.0:nnp host <destination_IP> and port <destination_port>
Once the traffic leaves the F5 and goes directly to the Palo Alto I would perform a capture on it to ensure your traffic is indeed making it for the specific destination in question. If another gateway sits between you and the Palo Alto I would run a capture on it as well to validate the traffic is moving on its way to the Palo Alto. You are essentially doing this to ensure that each device in the path is passing the communication on correctly to the destination so you can figure out what is dropping it.