<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is there any command to modify tls response version for ssl decryption forward proxy in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-any-command-to-modify-tls-response-version-for-ssl/m-p/245271#M69919</link>
    <description>&lt;P&gt;@Retired Member,&lt;/P&gt;&lt;P&gt;No. The firewall is going to respond to the client however the website is configured, so TSL1.0 won't magically be upgraded to TLS1.2. If the website is a requirement the client will need to re-enable TLS1.0 on their browser.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;FYI: TLS1.0 shouldn't be in use anymore, and best practice would be that its excluded from your Decryption Profile altogether.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 08 Jan 2019 20:44:46 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2019-01-08T20:44:46Z</dc:date>
    <item>
      <title>Is there any command to modify tls response version for ssl decryption forward proxy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-any-command-to-modify-tls-response-version-for-ssl/m-p/245037#M69879</link>
      <description>&lt;P&gt;When a client's browser disabled TLS1.0 and connect to a website which is only support TLS1.0.&lt;/P&gt;&lt;P&gt;Is there any way to let PA firewall&amp;nbsp; response TLS1.0 to user?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Because before we replaced our customer's firewall, their firewall was CheckPoint CP5800.&lt;/P&gt;&lt;P&gt;In same situation CP5800 responsed TLS1.2 to clients, so they browse the website works fine, but now they couldn't connect to that site anymore.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anybody know the workaround?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many, thanks.&lt;/P&gt;&lt;P&gt;Harold&lt;/P&gt;</description>
      <pubDate>Mon, 07 Jan 2019 04:10:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-there-any-command-to-modify-tls-response-version-for-ssl/m-p/245037#M69879</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2019-01-07T04:10:35Z</dc:date>
    </item>
    <item>
      <title>Re: Is there any command to modify tls response version for ssl decryption forward proxy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-any-command-to-modify-tls-response-version-for-ssl/m-p/245271#M69919</link>
      <description>&lt;P&gt;@Retired Member,&lt;/P&gt;&lt;P&gt;No. The firewall is going to respond to the client however the website is configured, so TSL1.0 won't magically be upgraded to TLS1.2. If the website is a requirement the client will need to re-enable TLS1.0 on their browser.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;FYI: TLS1.0 shouldn't be in use anymore, and best practice would be that its excluded from your Decryption Profile altogether.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Jan 2019 20:44:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-there-any-command-to-modify-tls-response-version-for-ssl/m-p/245271#M69919</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-01-08T20:44:46Z</dc:date>
    </item>
  </channel>
</rss>

