tried tls-version-min 1.0 & tls-version-min 1.2 on both server & client, didn't make any difference.
actually, by able to use DHE-RSA-AES256-GCM-SHA384, it is already using version 1.2, as I read somewhere this cipher is part of the v1.2. Yes, server message also said v1.2 when the connection...