<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Decryption: Client and decrypt profile version mismatch in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/decryption-client-and-decrypt-profile-version-mismatch/m-p/577546#M2667</link>
    <description>&lt;P&gt;Hi folks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Have been seeing a lot of "'Client and decrypt profile version mismatch. Supported client version bitmask: 0x08. Supported decrypt profile version bitmask: 0x60. ' errors in the log lately. This article:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/decryption/troubleshoot-and-monitor-decryption/decryption-logs/decryption-log-errors-and-error-indexes" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/decryption/troubleshoot-and-monitor-decryption/decryption-logs/decryption-log-errors-and-error-indexes&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;indicates that the client is trying TLS 1.0, whereas the decryption profile only supports &amp;gt; TLS 1.2. I don't see how this could be since the clients generating these are all fully updated Win10, which should use TLS 1.2 by default. I've checked in the 'Internet Options' control panel item on these clients and TLS 1.2 is in fact selected. I've tried to get packet captures, but these happen at random times to random IP adresses, so it has been difficult. My only thought is that some application is attempting to force a connection using TLS 1.0? Any other thoughts on what it could be?&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;</description>
    <pubDate>Fri, 16 Feb 2024 19:15:25 GMT</pubDate>
    <dc:creator>LCMember40912</dc:creator>
    <dc:date>2024-02-16T19:15:25Z</dc:date>
    <item>
      <title>Decryption: Client and decrypt profile version mismatch</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/decryption-client-and-decrypt-profile-version-mismatch/m-p/577546#M2667</link>
      <description>&lt;P&gt;Hi folks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Have been seeing a lot of "'Client and decrypt profile version mismatch. Supported client version bitmask: 0x08. Supported decrypt profile version bitmask: 0x60. ' errors in the log lately. This article:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/decryption/troubleshoot-and-monitor-decryption/decryption-logs/decryption-log-errors-and-error-indexes" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/decryption/troubleshoot-and-monitor-decryption/decryption-logs/decryption-log-errors-and-error-indexes&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;indicates that the client is trying TLS 1.0, whereas the decryption profile only supports &amp;gt; TLS 1.2. I don't see how this could be since the clients generating these are all fully updated Win10, which should use TLS 1.2 by default. I've checked in the 'Internet Options' control panel item on these clients and TLS 1.2 is in fact selected. I've tried to get packet captures, but these happen at random times to random IP adresses, so it has been difficult. My only thought is that some application is attempting to force a connection using TLS 1.0? Any other thoughts on what it could be?&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 16 Feb 2024 19:15:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/decryption-client-and-decrypt-profile-version-mismatch/m-p/577546#M2667</guid>
      <dc:creator>LCMember40912</dc:creator>
      <dc:date>2024-02-16T19:15:25Z</dc:date>
    </item>
    <item>
      <title>Re: Decryption: Client and decrypt profile version mismatch</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/decryption-client-and-decrypt-profile-version-mismatch/m-p/601920#M3884</link>
      <description>&lt;P&gt;I am having this same problem with a specific site.&amp;nbsp; &lt;A href="http://www.wordstream.com" target="_blank"&gt;www.wordstream.com&lt;/A&gt;&amp;nbsp;it triggers 100% of the time.&amp;nbsp; I've even tried to lower my decryption policy to accept TLSv1.0 and it still fails with a similar error:&amp;nbsp;Client and server version mismatch. Supported client version bitmask: 0x08.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Previous to the downgrade attempt in my decryption profile I had the exact same error as you.&amp;nbsp; I'm wondering if whatever is on the front end of this site is sending some odd requests back.&amp;nbsp; Feel free to test with this site as it fails for me it will hopefully fail for you with the same error.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Oct 2024 15:52:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/decryption-client-and-decrypt-profile-version-mismatch/m-p/601920#M3884</guid>
      <dc:creator>IanLobdell</dc:creator>
      <dc:date>2024-10-16T15:52:05Z</dc:date>
    </item>
    <item>
      <title>Re: Decryption: Client and decrypt profile version mismatch</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/decryption-client-and-decrypt-profile-version-mismatch/m-p/615642#M4921</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Have you had any luck resolving this issue? Running into that exact issue on one of our sites.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Oct 2024 22:41:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/decryption-client-and-decrypt-profile-version-mismatch/m-p/615642#M4921</guid>
      <dc:creator>mariolopez</dc:creator>
      <dc:date>2024-10-29T22:41:13Z</dc:date>
    </item>
    <item>
      <title>Re: Decryption: Client and decrypt profile version mismatch</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/decryption-client-and-decrypt-profile-version-mismatch/m-p/1232591#M6026</link>
      <description>&lt;P&gt;Resurrecting this thread, as I'm having this issue with sites using proper TLS versions. Win10/11 PCs with updated browsers. "SSL Protocol Error" in Edge/Chrome. Not in Firefox. Only when the firewall and our forward trust cert is in the middle....just now poking around with it.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jun 2025 18:11:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/decryption-client-and-decrypt-profile-version-mismatch/m-p/1232591#M6026</guid>
      <dc:creator>moorek</dc:creator>
      <dc:date>2025-06-25T18:11:04Z</dc:date>
    </item>
  </channel>
</rss>

