<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic diffternt TLS protocolsbetween client and server  supported in pan ?? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/diffternt-tls-protocolsbetween-client-and-server-supported-in/m-p/341816#M85734</link>
    <description>&lt;P&gt;we have a legacy client which supported only TLS(1.1) &amp;amp; need to connect to server in cloud which works on TLS1.2 only .. So If we do a SSL Decryption in pan firewall does pan will allow tls1.1 between client and pan firewall and tls 1.2 between pan firewall and cloud server ??&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Dinesh&lt;/P&gt;</description>
    <pubDate>Mon, 03 Aug 2020 09:26:43 GMT</pubDate>
    <dc:creator>DineshPal</dc:creator>
    <dc:date>2020-08-03T09:26:43Z</dc:date>
    <item>
      <title>diffternt TLS protocolsbetween client and server  supported in pan ??</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/diffternt-tls-protocolsbetween-client-and-server-supported-in/m-p/341816#M85734</link>
      <description>&lt;P&gt;we have a legacy client which supported only TLS(1.1) &amp;amp; need to connect to server in cloud which works on TLS1.2 only .. So If we do a SSL Decryption in pan firewall does pan will allow tls1.1 between client and pan firewall and tls 1.2 between pan firewall and cloud server ??&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Dinesh&lt;/P&gt;</description>
      <pubDate>Mon, 03 Aug 2020 09:26:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/diffternt-tls-protocolsbetween-client-and-server-supported-in/m-p/341816#M85734</guid>
      <dc:creator>DineshPal</dc:creator>
      <dc:date>2020-08-03T09:26:43Z</dc:date>
    </item>
    <item>
      <title>Re: diffternt TLS protocolsbetween client and server  supported in pan ??</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/diffternt-tls-protocolsbetween-client-and-server-supported-in/m-p/341916#M85748</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/46174"&gt;@DineshPal&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Seems PA has decryption profile under Objects.&lt;/P&gt;
&lt;P&gt;It has option to allow&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Min Protocol Version and Maximum Protocol Version&lt;/P&gt;
&lt;P&gt;There you can specify TLS1.1as Minimum and TLS1.2 as Maximum&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Then it will allow all the connection between TLS1.1 and TLS1.2.&lt;/P&gt;
&lt;P&gt;However if server only supports 1.2 then SSL decryption will not work as Client only supports TLS1.1&lt;/P&gt;
&lt;P&gt;You either need to make change at client or server side&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Aug 2020 00:21:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/diffternt-tls-protocolsbetween-client-and-server-supported-in/m-p/341916#M85748</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2020-08-04T00:21:00Z</dc:date>
    </item>
    <item>
      <title>Re: diffternt TLS protocolsbetween client and server  supported in pan ??</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/diffternt-tls-protocolsbetween-client-and-server-supported-in/m-p/341927#M85751</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/46174"&gt;@DineshPal&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't think if any firewall can change SSL/TLS version of in/out traffic. It can decrypt traffic (if it is enabled) and see what is happening but can't change the versions at client and/or server side. Agreed with &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/75039"&gt;@MP18&lt;/a&gt; Need to make changes at either client or server side to make it work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope it helps!&lt;/P&gt;&lt;P&gt;Mayur&lt;/P&gt;</description>
      <pubDate>Tue, 04 Aug 2020 04:07:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/diffternt-tls-protocolsbetween-client-and-server-supported-in/m-p/341927#M85751</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2020-08-04T04:07:47Z</dc:date>
    </item>
  </channel>
</rss>

