<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Global Protect Mac-OS Received fatal alert IllegalParameter from client in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/global-protect-mac-os-received-fatal-alert-illegalparameter-from/m-p/1240621#M6409</link>
    <description>&lt;P&gt;Hello Livecommunity!&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;As an update, our client created a ticket with MAC support, as the operating system is attempting to use the insecure TLS 1.0 instead of TLS 1.2 or TLS 1.3. As soon as I have any progress on MAC parsing, I'll post it in this knowledge base.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Best regards,&lt;/P&gt;</description>
    <pubDate>Fri, 24 Oct 2025 05:02:50 GMT</pubDate>
    <dc:creator>DanielS.Romero</dc:creator>
    <dc:date>2025-10-24T05:02:50Z</dc:date>
    <item>
      <title>Global Protect Mac-OS Received fatal alert IllegalParameter from client</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/global-protect-mac-os-received-fatal-alert-illegalparameter-from/m-p/1222228#M5626</link>
      <description>&lt;P&gt;Hello team,&lt;BR /&gt;&lt;BR /&gt;I have an issue with the Global Protect 6.2.7 app running on an Apple Mac OS X Sequoia15.3.1 in the SSL negotiation process,&lt;BR /&gt;&lt;BR /&gt;The error on the Global Protect say "&lt;STRONG&gt;The network connection is unreachable or the portal is unresponsive. Check the network connection and reconnect.&lt;/STRONG&gt;"&lt;BR /&gt;&lt;BR /&gt;On the NGFW logs see somes decrypt errors on the traffic and decryptions logs says "&lt;STRONG&gt;sslv3 alert illegal parameter. Received fatal alert IllegalParameter from client&lt;/STRONG&gt;" When the Mac-OS Client try to negotiate the SSL connection with TLS 1.3.&lt;BR /&gt;&lt;BR /&gt;When the client uses TLS 1.0 the decrypt error says "&lt;STRONG&gt;Client and decrypt profile version mismatch. Supported client version bitmask: 0x08. Supported decrypt profile version bitmask: 0x60. " &lt;/STRONG&gt;as below&lt;STRONG&gt;:&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;NGFW DECRYPTION ERRORS TLS 1.0 &amp;amp; TLS 1.3&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DanielSRomero_0-1740714068271.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/66233iABA90AF48371F41D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="DanielSRomero_0-1740714068271.png" alt="DanielSRomero_0-1740714068271.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;I import the Global Protect certificate on the Mac OS and the issues still there.&lt;BR /&gt;&lt;BR /&gt;I verify the TLS/SSL Service Profile configured to the Global Protect and I see that it only allowed connections from TLS 1.2 and higher, however why the Global Protect SSL connection fail even with TLS 1.3 negotiation?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;NGFW GLOBAL PROTECT SSL/TLS SERVICE PROFILE&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DanielSRomero_1-1740714215213.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/66234i865EC30664AFDD35/image-size/medium?v=v2&amp;amp;px=400" role="button" title="DanielSRomero_1-1740714215213.png" alt="DanielSRomero_1-1740714215213.png" /&gt;&lt;/span&gt;&lt;BR /&gt;I configured a pcap to try to find extra information about the issue, and I see that the TCP 3-way is completed between the NGFW Global Protect and the Client Global Protect App, however some times the mac-os try to negotiate with the TLS 1.0 or TLS 1.3 and the NGFW sends a TCP RST to finish the session.&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;NGFW GLOBAL PROTECT TLS1.0 NEGOTIATION&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DanielSRomero_2-1740714813788.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/66235iAB05D14F2D51C216/image-size/medium?v=v2&amp;amp;px=400" role="button" title="DanielSRomero_2-1740714813788.png" alt="DanielSRomero_2-1740714813788.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;FROM NGFW GLOBAL PROTECT TLS1.0 NEGOTIATION ERROR&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DanielSRomero_3-1740714853802.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/66236i209826B217326912/image-size/medium?v=v2&amp;amp;px=400" role="button" title="DanielSRomero_3-1740714853802.png" alt="DanielSRomero_3-1740714853802.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;NGFW GLOBAL PROTECT TLS1.3 NEGOTIATION (AT THE END THE NGFW SENDS A TCP RST TO THE GLOBAL PROTECT CLIENT APP)&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DanielSRomero_4-1740714987441.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/66237i19BCC0F88BD6701A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="DanielSRomero_4-1740714987441.png" alt="DanielSRomero_4-1740714987441.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Someone else have the same issue and know how to fix it?&lt;BR /&gt;&lt;BR /&gt;I appreciate your time and help,&lt;BR /&gt;&lt;BR /&gt;Best Regards,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Feb 2025 04:01:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/global-protect-mac-os-received-fatal-alert-illegalparameter-from/m-p/1222228#M5626</guid>
      <dc:creator>DanielS.Romero</dc:creator>
      <dc:date>2025-02-28T04:01:33Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect Mac-OS Received fatal alert IllegalParameter from client</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/global-protect-mac-os-received-fatal-alert-illegalparameter-from/m-p/1240621#M6409</link>
      <description>&lt;P&gt;Hello Livecommunity!&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;As an update, our client created a ticket with MAC support, as the operating system is attempting to use the insecure TLS 1.0 instead of TLS 1.2 or TLS 1.3. As soon as I have any progress on MAC parsing, I'll post it in this knowledge base.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Best regards,&lt;/P&gt;</description>
      <pubDate>Fri, 24 Oct 2025 05:02:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/global-protect-mac-os-received-fatal-alert-illegalparameter-from/m-p/1240621#M6409</guid>
      <dc:creator>DanielS.Romero</dc:creator>
      <dc:date>2025-10-24T05:02:50Z</dc:date>
    </item>
  </channel>
</rss>

