<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic NGFW Global Protect 6.2.7 Global Counters Negotiation Error TLS 1.3 MAC-OS in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/ngfw-global-protect-6-2-7-global-counters-negotiation-error-tls/m-p/1222402#M6540</link>
    <description>&lt;P&gt;Hello Livecommunity!&lt;BR /&gt;&lt;BR /&gt;I'm facing an error with the Global Protect Agent&amp;nbsp;&lt;STRONG&gt;6.2.7&lt;/STRONG&gt;&amp;nbsp;when an Apple Mac OS X &lt;STRONG&gt;15.3.1&lt;/STRONG&gt; Sequoia tries to establish an SSL VPN connection with the Global Protect Portal; We see the next error on the DP CLI pcap global counters:&lt;BR /&gt;&lt;BR /&gt;NGFW(active)&amp;gt; show counter global filter packet-filter yes delta yes&lt;BR /&gt;&lt;SPAN&gt;ssl_tls13_connection_error &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;0 error &amp;nbsp; &amp;nbsp; ssl &amp;nbsp; &amp;nbsp; &amp;nbsp; pktproc &amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG dir="ltr"&gt;TLS13: Unrecoverable error in openssl statemachine&lt;BR /&gt;&lt;STRONG&gt;sslv3 alert illegal parameter. Received fatal alert IllegalParameter from client&lt;/STRONG&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG dir="ltr"&gt;&lt;BR /&gt;And these logs where the .193 is the Global Protect Portal IP address and the .170 is the Client public IP address:&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG dir="ltr"&gt;&lt;BR /&gt;NGFW DATA PLANE PCAP LOGS&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DanielSRomero_0-1741003799243.png" style="width: 849px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/66280iC01C672611DC4AB4/image-dimensions/849x295?v=v2" width="849" height="295" role="button" title="DanielSRomero_0-1741003799243.png" alt="DanielSRomero_0-1741003799243.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Also on the NGFW logs there're somes decrypt errors on the traffic and decryptions logs says "&lt;STRONG&gt;sslv3 alert illegal parameter. Received fatal alert Illegal Parameter from client&lt;/STRONG&gt;" When the Mac-OS Client try to negotiate the SSL VPN connection with TLS 1.3.&lt;BR /&gt;&lt;BR /&gt;When the client uses TLS 1.0 the decrypt error says "&lt;STRONG&gt;Client and decrypt profile version mismatch. Supported client version bitmask: 0x08. Supported decrypt profile version bitmask: 0x60. "&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;as below&lt;STRONG&gt;:&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;NGFW DECRYPTION ERRORS TLS 1.0 &amp;amp; TLS 1.3&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DanielSRomero_3-1741004715515.png" style="width: 844px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/66282iB22D4890EB7DEE30/image-dimensions/844x268?v=v2" width="844" height="268" role="button" title="DanielSRomero_3-1741004715515.png" alt="DanielSRomero_3-1741004715515.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG dir="ltr"&gt;&amp;nbsp;&lt;/STRONG&gt;These is a pcap on the Mac-OS device where the &lt;STRONG&gt;.193&lt;/STRONG&gt; is the Global Protect Portal IP address and the &lt;STRONG&gt;.108&lt;/STRONG&gt; is the Client private IP address.&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;MAC-OS DEVICE PCAP GLOBAL PROTECT AGENT CONNECTION&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DanielSRomero_1-1741003799236.png" style="width: 912px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/66279i7B4D428E5836959E/image-dimensions/912x124?v=v2" width="912" height="124" role="button" title="DanielSRomero_1-1741003799236.png" alt="DanielSRomero_1-1741003799236.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG dir="ltr"&gt;&lt;BR /&gt;&lt;/STRONG&gt;The Global Protect Agent on the Mac-OS says "&lt;STRONG dir="ltr"&gt;The network connection is unreachable or the portal is unresponsive. Check the network connection and reconnec&lt;/STRONG&gt;&lt;SPAN&gt;t&lt;/SPAN&gt;"&lt;BR /&gt;&lt;BR /&gt;The openssl version on the Mac-OS is &lt;STRONG&gt;LibreSSL 3.3.6&lt;/STRONG&gt;&lt;BR /&gt;The NGFW PAN-OS version is &lt;STRONG&gt;11.1.5-h1&lt;BR /&gt;&lt;/STRONG&gt;The TLS/SSL Service Profile we allowed connections from TLS 1.2 to TLS 1.3. &lt;STRONG&gt;(We want to avoid TLS 1.0 connections&lt;/STRONG&gt;)&lt;BR /&gt;&lt;BR /&gt;Anyone have an idea how to fix the Global Protect connection with the MAC device or know the meaning of the logs?&lt;BR /&gt;&lt;BR /&gt;Thanks for your time!&lt;/P&gt;</description>
    <pubDate>Mon, 03 Mar 2025 12:31:59 GMT</pubDate>
    <dc:creator>DanielS.Romero</dc:creator>
    <dc:date>2025-03-03T12:31:59Z</dc:date>
    <item>
      <title>NGFW Global Protect 6.2.7 Global Counters Negotiation Error TLS 1.3 MAC-OS</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/ngfw-global-protect-6-2-7-global-counters-negotiation-error-tls/m-p/1222402#M6540</link>
      <description>&lt;P&gt;Hello Livecommunity!&lt;BR /&gt;&lt;BR /&gt;I'm facing an error with the Global Protect Agent&amp;nbsp;&lt;STRONG&gt;6.2.7&lt;/STRONG&gt;&amp;nbsp;when an Apple Mac OS X &lt;STRONG&gt;15.3.1&lt;/STRONG&gt; Sequoia tries to establish an SSL VPN connection with the Global Protect Portal; We see the next error on the DP CLI pcap global counters:&lt;BR /&gt;&lt;BR /&gt;NGFW(active)&amp;gt; show counter global filter packet-filter yes delta yes&lt;BR /&gt;&lt;SPAN&gt;ssl_tls13_connection_error &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;0 error &amp;nbsp; &amp;nbsp; ssl &amp;nbsp; &amp;nbsp; &amp;nbsp; pktproc &amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG dir="ltr"&gt;TLS13: Unrecoverable error in openssl statemachine&lt;BR /&gt;&lt;STRONG&gt;sslv3 alert illegal parameter. Received fatal alert IllegalParameter from client&lt;/STRONG&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG dir="ltr"&gt;&lt;BR /&gt;And these logs where the .193 is the Global Protect Portal IP address and the .170 is the Client public IP address:&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG dir="ltr"&gt;&lt;BR /&gt;NGFW DATA PLANE PCAP LOGS&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DanielSRomero_0-1741003799243.png" style="width: 849px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/66280iC01C672611DC4AB4/image-dimensions/849x295?v=v2" width="849" height="295" role="button" title="DanielSRomero_0-1741003799243.png" alt="DanielSRomero_0-1741003799243.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Also on the NGFW logs there're somes decrypt errors on the traffic and decryptions logs says "&lt;STRONG&gt;sslv3 alert illegal parameter. Received fatal alert Illegal Parameter from client&lt;/STRONG&gt;" When the Mac-OS Client try to negotiate the SSL VPN connection with TLS 1.3.&lt;BR /&gt;&lt;BR /&gt;When the client uses TLS 1.0 the decrypt error says "&lt;STRONG&gt;Client and decrypt profile version mismatch. Supported client version bitmask: 0x08. Supported decrypt profile version bitmask: 0x60. "&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;as below&lt;STRONG&gt;:&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;NGFW DECRYPTION ERRORS TLS 1.0 &amp;amp; TLS 1.3&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DanielSRomero_3-1741004715515.png" style="width: 844px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/66282iB22D4890EB7DEE30/image-dimensions/844x268?v=v2" width="844" height="268" role="button" title="DanielSRomero_3-1741004715515.png" alt="DanielSRomero_3-1741004715515.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG dir="ltr"&gt;&amp;nbsp;&lt;/STRONG&gt;These is a pcap on the Mac-OS device where the &lt;STRONG&gt;.193&lt;/STRONG&gt; is the Global Protect Portal IP address and the &lt;STRONG&gt;.108&lt;/STRONG&gt; is the Client private IP address.&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;MAC-OS DEVICE PCAP GLOBAL PROTECT AGENT CONNECTION&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DanielSRomero_1-1741003799236.png" style="width: 912px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/66279i7B4D428E5836959E/image-dimensions/912x124?v=v2" width="912" height="124" role="button" title="DanielSRomero_1-1741003799236.png" alt="DanielSRomero_1-1741003799236.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG dir="ltr"&gt;&lt;BR /&gt;&lt;/STRONG&gt;The Global Protect Agent on the Mac-OS says "&lt;STRONG dir="ltr"&gt;The network connection is unreachable or the portal is unresponsive. Check the network connection and reconnec&lt;/STRONG&gt;&lt;SPAN&gt;t&lt;/SPAN&gt;"&lt;BR /&gt;&lt;BR /&gt;The openssl version on the Mac-OS is &lt;STRONG&gt;LibreSSL 3.3.6&lt;/STRONG&gt;&lt;BR /&gt;The NGFW PAN-OS version is &lt;STRONG&gt;11.1.5-h1&lt;BR /&gt;&lt;/STRONG&gt;The TLS/SSL Service Profile we allowed connections from TLS 1.2 to TLS 1.3. &lt;STRONG&gt;(We want to avoid TLS 1.0 connections&lt;/STRONG&gt;)&lt;BR /&gt;&lt;BR /&gt;Anyone have an idea how to fix the Global Protect connection with the MAC device or know the meaning of the logs?&lt;BR /&gt;&lt;BR /&gt;Thanks for your time!&lt;/P&gt;</description>
      <pubDate>Mon, 03 Mar 2025 12:31:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/ngfw-global-protect-6-2-7-global-counters-negotiation-error-tls/m-p/1222402#M6540</guid>
      <dc:creator>DanielS.Romero</dc:creator>
      <dc:date>2025-03-03T12:31:59Z</dc:date>
    </item>
    <item>
      <title>Re: NGFW Global Protect 6.2.7 Global Counters Negotiation Error TLS 1.3 MAC-OS</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/ngfw-global-protect-6-2-7-global-counters-negotiation-error-tls/m-p/1226729#M6686</link>
      <description>&lt;P&gt;Did you ever find a solution to this? I am receiving the exact same problem now&lt;/P&gt;</description>
      <pubDate>Wed, 16 Apr 2025 16:43:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/ngfw-global-protect-6-2-7-global-counters-negotiation-error-tls/m-p/1226729#M6686</guid>
      <dc:creator>Josh_Levine</dc:creator>
      <dc:date>2025-04-16T16:43:43Z</dc:date>
    </item>
    <item>
      <title>Re: NGFW Global Protect 6.2.7 Global Counters Negotiation Error TLS 1.3 MAC-OS</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/ngfw-global-protect-6-2-7-global-counters-negotiation-error-tls/m-p/1226731#M6687</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/186939"&gt;@Josh_Levine&lt;/a&gt;&amp;nbsp;We open a TAC case and this is the results on a tshoot call:&lt;BR /&gt;&lt;BR /&gt;"Summary:&lt;BR /&gt;=========&lt;BR /&gt;-Joined the call and you replicated the issue.&lt;BR /&gt;-Found the decrypt error as "Client and decrypt profile version mismatch. Supported client version bitmask: 0x08. Supported decrypt profile version bitmask: 0x60." .&lt;BR /&gt;-Run the command 'debug data plane show ssl-decrypt bitmask-version 0x08' to check the supported version of the client and the supported version is TLSv1.0.&lt;BR /&gt;-Run the command 'debug data plane show ssl-decrypt bitmask-version 0x06' to check the supported version of the decrypt profile and the supported versions were SSL2.0 and SSL 3.0.&lt;BR /&gt;-Checked the traffic logs to confirm the rule it is hitting and checked the policy.&lt;BR /&gt;-We observed the traffic is coming from two different zones. The rule is changing for the zone.&lt;BR /&gt;-However, there is the decrypt error for only one zone.&lt;BR /&gt;-Informed you the same and we created the separate decryption profile for the testing purpose. It didn't work.&lt;BR /&gt;-I informed the only solution is to edit the decryption profile since we cannot update the client.&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Kindly refer the below documents for decryption error:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000HB8bCAG&amp;amp;lang=en_US%E2%80%A9&amp;amp;refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000HB8bCAG&amp;amp;lang=en_US%E2%80%A9&amp;amp;refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-admin/decryption/troubleshoot-and-monitor-decryption/decryption-troubleshooting-workflow-examples/troubleshoot-unsupported-cipher-suites" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-admin/decryption/troubleshoot-and-monitor-decryption/decryption-troubleshooting-workflow-examples/troubleshoot-unsupported-cipher-suites&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;If there is anything else I could help you with, please don't hesitate to reach us. We will be happy to assist you."&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;According to the results we need to contact the MAC support to try fix this connectivity issue.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;As a workaround, we modified the SSL/TLS service profile to support up to TLS 1.2, and the connection worked!&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;This was my previous SSL/TLS service profile configuration:&lt;/P&gt;
&lt;DIV id="tinyMceEditor_9318ca02ecf0f9DanielSRomero_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&lt;STRONG&gt;SSL/TLS SERVICE PROFILE CONFIGURATION&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DanielSRomero_1-1763776362289.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/69902i74D5A88086AEADFE/image-size/medium?v=v2&amp;amp;px=400" role="button" title="DanielSRomero_1-1763776362289.png" alt="DanielSRomero_1-1763776362289.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Hope this could be useful,&lt;BR /&gt;&lt;BR /&gt;Best Regards,&lt;BR /&gt;&lt;BR /&gt;Daniel Romero&lt;BR /&gt;PANW Partner&lt;BR /&gt;Senior Network/Security Engineer&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 22 Nov 2025 01:54:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/ngfw-global-protect-6-2-7-global-counters-negotiation-error-tls/m-p/1226731#M6687</guid>
      <dc:creator>DanielS.Romero</dc:creator>
      <dc:date>2025-11-22T01:54:48Z</dc:date>
    </item>
    <item>
      <title>Re: NGFW Global Protect 6.2.7 Global Counters Negotiation Error TLS 1.3 MAC-OS</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/ngfw-global-protect-6-2-7-global-counters-negotiation-error-tls/m-p/1229293#M6782</link>
      <description>&lt;P&gt;Having the same issue with my Mac users.&lt;/P&gt;</description>
      <pubDate>Fri, 16 May 2025 17:57:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/ngfw-global-protect-6-2-7-global-counters-negotiation-error-tls/m-p/1229293#M6782</guid>
      <dc:creator>sbarba</dc:creator>
      <dc:date>2025-05-16T17:57:29Z</dc:date>
    </item>
    <item>
      <title>Re: NGFW Global Protect 6.2.7 Global Counters Negotiation Error TLS 1.3 MAC-OS</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/ngfw-global-protect-6-2-7-global-counters-negotiation-error-tls/m-p/1242412#M7139</link>
      <description>&lt;P&gt;Hello &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/282556"&gt;@sbarba&lt;/a&gt;&amp;nbsp;,&lt;BR /&gt;&lt;BR /&gt;Could you please check the alternative solutions and confirm if they work for you?&lt;BR /&gt;&lt;BR /&gt;Best Regards,&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Daniel Romero&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;PANW Partner&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Senior Network/Security Engineer&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 22 Nov 2025 01:57:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/ngfw-global-protect-6-2-7-global-counters-negotiation-error-tls/m-p/1242412#M7139</guid>
      <dc:creator>DanielS.Romero</dc:creator>
      <dc:date>2025-11-22T01:57:18Z</dc:date>
    </item>
  </channel>
</rss>

