- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- Re: ‘TLS alert: protocol_version’ after QUIC block...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
‘TLS alert: protocol_version’ after QUIC blocking and connecting via https
‘TLS alert: protocol_version’ after QUIC blocking and connecting via https
Good afternoon
Can you please tell me if HTTPS inspection will work correctly when the connection is already via TCP 443?
We have QUIC blocked. User has Bypass configured in https inspection. In logs we see reject QUIC and then Bypass log with Alert. And we see the error: ‘The probe detected that this destination cannot be inspected and its identity cannot be verified due to a TLS alert (TLS alert: protocol_version)’.
What can this be related to?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
We have the same log entries.
Which firewall version?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
HTTPS Inspection only supports up to TLS 1.2 unless you're on R81+ and USFW is enabled: https://support.checkpoint.com/results/sk/sk167052
If the remote site requires TLS 1.3 (or above), then I could see this error popping up.
In any case, please provide a full log card (redacting sensitive details.
