gRPC with the responder policy
-
Enable the responder feature on the appliance.
-
Configure the responder action to generate a custom response, redirect a request to a different webpage, or reset a connection.
-
Configure the responder policy for determining the gRPC requests (traffic) on which an action has to be taken.
-
Bind the responder policy to the load balancing virtual server to examine if the traffic matches the policy expression.
-
By using a responder policy, you can perform the following based on the gRPC status code.
Configure gRPC call termination with the responder policy by using the CLI
-
Enable the responder feature
-
Add a responder action
-
Add a responder policy and associate responder action
-
Bind the responder policy to load balancing virtual server
Enable the responder feature
enable ns responder
Add the responder action
add responder action <name> <type>
add responder action grpc-act respondwith "HTTP/1.1 200 OK\r\nServer: NS-Responder\r\nContent-Type:application/grpc\r\ngrpc-status: 12\r\ngrpc-message: Not Implemented\r\n\r\n" + "Method: " + HTTP.REQ.URL+ "is not implemented."
Adding responder policy
add responder policy <name> <expression> <action> [<undefaction>]-appFlowaction <actionName> Example:
add responder policy grpc-resp-pol1 HTTP.REQ.URL.NE(“/helloworld.Greeter/SayHello”) grpc-act
Bind responder policy to load balancing virtual server
bind responder global <policyName> <priority> [<gotoPriorityExpression> [-type <type>] [-invoke (<labelType> <labelName>)]
bind lb vserver lb-grpc svc-grpc -policyName grpc-resp-pol1 –priority 100
Policy expressions for matching gRPC protocol buffer fields
-
gRPC protocol buffer field access. The arbitrary gRPC API call matches the message field number with the new policy expressions. In a PI configuration, the matches are done using only the 'field numbers' and 'API path'.
-
gRPC header filtering. The "HttpProfile" parameters for gRPC is used to adjust the default behavior of gRPC parsing (including gRPC policy expressions). The following parameters are applicable to gRPC policy expressions:
-
gRPCLengthDelimitation. It is enabled by default and expects the protocol buffers to be presented with a length delimited message.
-
gRPCHoldLimit. The default value is 131072. It is the maximum protocol buffer message size in bytes. It is also the maximum string length and the maximum 'byte' field length as well.
-
Configure gRPC advance policy expressions by using the CLI
set ns httpProfile <name> -http2 ( ENABLED | DISABLED ) -gRPCLengthDelimitation ( ENABLED | DISABLED ) -gRPCHoldLimit <int>
set ns httpProfile http2gRPC -http2 ENABLED -gRPCLengthDelimitation ENABLED -gRPCHoldLimit 131072
Configure gRPC header filtering parameters by using the GUI
-
Navigate to System > Profiles and click HTTP Profiles.
-
On the Create HTTP Profile page, scroll down to HTTP/3 section, select gRPC Length Delimitation.

http.req.body(1000).grpc.message(5).message(4).int32(3).eq(2)
-
message
-
double
-
float
-
int32
-
int64
-
uint32
-
uint64
-
sint64
-
sint32
-
fixed32
-
fixed64
-
sfixed32
-
sfixed64
-
bool
-
string
-
enum
-
bytes
API path matching
http.req.header(":path").eq("acme.inventory.v1/ListBooks")