If SSL traffic matches an SSL Forward Proxy or SSL Inbound Inspection
Decryption policy rule, the firewall prevents negotiation with PQC, hybrid PQC, and
other unsupported algorithms. Specifically, the firewall removes these algorithms
from the ClientHello, forcing the client to negotiate with classical algorithms.
(For a list of supported cipher suites, see
PAN-OS 11.1 Decryption Cipher Suites.)
This enables continuous decryption and threat identification through deep packet
inspection. If the client strictly negotiates PQC or hybrid PQC algorithms, the
firewall drops the session. In the Decryption log for the dropped session, the error
message states that the "client only supports post-quantum algorithms.” To see
details of successful or unsuccessful TLS handshakes in the Decryption logs, enable
both options in your Decryption policy rules.