<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: General TLS protocol  Error in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/general-tls-protocol-error/m-p/617673#M122015</link>
    <description>&lt;P&gt;Thank will look into that&lt;/P&gt;</description>
    <pubDate>Thu, 14 Nov 2024 09:34:54 GMT</pubDate>
    <dc:creator>Salathiwe</dc:creator>
    <dc:date>2024-11-14T09:34:54Z</dc:date>
    <item>
      <title>General TLS protocol  Error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/general-tls-protocol-error/m-p/590483#M117627</link>
      <description>&lt;P&gt;We have forward proxy (ssl decryption configured)&lt;/P&gt;
&lt;P&gt;We are having intermittent access to some webpages users have to reload the page to gain access.&lt;BR /&gt;We are seeing General TLS Error on the decryption logs under Error.&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 171px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/60540i74E7B5EB2F03EC7B/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What Iv found out about the error is that&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;TABLE class="table colsep rowsep  table-striped"&gt;
&lt;TBODY class="tbody"&gt;
&lt;TR class="row"&gt;
&lt;TD class="entry relcol"&gt;
&lt;DIV&gt;
&lt;DIV class="p"&gt;
&lt;DIV&gt;This message indicates that an error doesn't meet the criteria for any of the aforementioned protocol errors&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;</description>
      <pubDate>Wed, 26 Jun 2024 13:50:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/general-tls-protocol-error/m-p/590483#M117627</guid>
      <dc:creator>Salathiwe</dc:creator>
      <dc:date>2024-06-26T13:50:06Z</dc:date>
    </item>
    <item>
      <title>Re: General TLS protocol  Error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/general-tls-protocol-error/m-p/590542#M117639</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/206322"&gt;@Salathiwe&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Unfortunately that particular error message doesn't give you much to go off of from a troubleshooting aspect. The best step forward is taking a PCAP and look through to validate that everything looks good from the logs as far as what the server is exchanging and what the firewall itself actually supports.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jun 2024 23:33:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/general-tls-protocol-error/m-p/590542#M117639</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2024-06-26T23:33:52Z</dc:date>
    </item>
    <item>
      <title>Re: General TLS protocol  Error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/general-tls-protocol-error/m-p/617200#M121994</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/206322"&gt;@Salathiwe&lt;/a&gt;&amp;nbsp;Normally&amp;nbsp;this means that Server only supports TLS1.3&lt;/P&gt;
&lt;P&gt;This is what i have seen so far. Make sure on Firewall Decryption Profile - TLS version - TLS1.3 is selected.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Tue, 12 Nov 2024 16:19:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/general-tls-protocol-error/m-p/617200#M121994</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2024-11-12T16:19:12Z</dc:date>
    </item>
    <item>
      <title>Re: General TLS protocol  Error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/general-tls-protocol-error/m-p/617673#M122015</link>
      <description>&lt;P&gt;Thank will look into that&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2024 09:34:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/general-tls-protocol-error/m-p/617673#M122015</guid>
      <dc:creator>Salathiwe</dc:creator>
      <dc:date>2024-11-14T09:34:54Z</dc:date>
    </item>
    <item>
      <title>Re: General TLS protocol  Error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/general-tls-protocol-error/m-p/627649#M122099</link>
      <description>&lt;P&gt;In addition, when debugging SSL decrypt problems I also recommend running SSLLabs "Test Your Server" on the endpoint server.&amp;nbsp; I have come across quite a few TLS/1.2 and 1.3 capable public servers that deliberately choose weak encryption algorithms for TLS/1.2 (server side prefers weak ciphers before strong). After successful TLS/1.2 negotiation the server then tries to upgrade the connection to HTTP/2.0, which explicitly forbids weak ciphers, causing the TLS/1.2 to abort. When doing a TLS/1.3 connection everything works fine as 1.3 requires strong ciphers to start. So the server is actually causing the problem, not the PaloAlto.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Nov 2024 16:49:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/general-tls-protocol-error/m-p/627649#M122099</guid>
      <dc:creator>Adrian_Jensen</dc:creator>
      <dc:date>2024-11-19T16:49:01Z</dc:date>
    </item>
  </channel>
</rss>

