You do not need to make BOTH of those changes, only one. It is only recommended to set the HDX's AES encryption setting to "When Available". It is not required, nor is it even recommended to reduce the Lync Server media encryption level.
As long as the HDX is set as I described then it will support either RTP or SRTP media payload requests.
Also make sure that you have purchased the RTV Options Key and are running on at least the 3.1.2 firmware release for a supported Lync 2013 interoperability scenario.
Jeff Schertz | Microsoft Solutions Architect - Polycom | Lync MVP