If blocked by default, you will need to whitelist the following smallstep domains in order for the hosts and bastion hosts to renew certificates with your SAAS CA:
api.smallstep.com
ssh.<your_team>.ca.smallstep.com
additionally if you are running the smallstep host quickstart to register servers you will need to whitelist: