I have the same problem like described in:
#14707 – Google webmaster tool error 403 on Sitemap
When I set main-disable.php google can read my xml-Sitemap.
When I activate main.php again, google says there's a 403 error.
So it definetly is caused by Admin Tools as far as I understand.
I did this as you said here:
First go to Admin Tools, Web Application Firewall, Configure WAF. Make sure "Log security exceptions" is set to Yes; if it's not, set it to Yes and click on Save. Now try reproducing your issue. Immediately after that, please go to Admin Tools, Web Application Firewall, Security Exceptions Log and go to the last page. The last log entry should have the date and time of when the issue occurred. Please copy the Reason and Target URL here so that I can help you.
With activated Admin Tools I reproduce the error, but only in in google search console it shows me again the error 403. But when I check again in Security Exceptions Log, there is no entry in the log about it.
So I first indexed the site with disabled admin tools in google search console, but now activated admin tools again.
How can I try further?
Maybe you can help me.