You're right. I totaly forgot about this. That's why I wrongly identified it as a TLSv1 request. 😬
We were able to find the reason for the issue.
The site is excluded from HTTPS inspection on all our firewalls. But the rule doesn't match anymore on one firewall since last week.
The last exception logs reportet log
We've created a new rule for the bypass below the non-working rule to solve the issue.
Now we're trying to identify why the global rule is not matching on one firewall.
The last matching log entries for that firewall show an error:
"The probe detected that this destination cannot be inspected and its identity cannot be verified due to a TLS alert (TLS alert: protocol_version)"
After about 20 of this errors no more HTTP inspection logs where generated for this firewall and website.