HTTP/2 DoS mitigation
Configure the maximum limit for HTTP/2 frames to mitigate DoS attacks by using the command-line interface
set ns httpprofile <profile_name> -http2MaxEmptyFramesPerMin <positive_integer> -http2MaxPingFramesPerMin <positive_integer> -http2MaxSettingsFramesPerMin <positive_integer> -http2MaxResetFramesPerMin <positive_integer> -http2MaxRxResetFramesPerMin <positive_integer> -http2SmallWndTimeout <integer>
set ns httpprofile profile1 -http2MaxEmptyFramesPerMin 20 -http2MaxPingFramesPerMin 20 -http2MaxSettingsFramesPerMin 20 -http2MaxResetFramesPerMin 20 -http2MaxRxResetFramesPerMin 100 -http2SmallWndTimeout 30
Configure the maximum limit for frames received in an HTTP/2 connection by using the NetScaler GUI
-
On the navigation pane, expand System and then click Profiles.
-
On the Profile page, select the HTTP Profiles tab.
-
In the HTTP Profiles tab page, click Add.
-
In the Configure HTTP Profile page, set the following parameters.
-
http2MaxPingFramesPerMin: Set the maximum PING frames received per connection in a minute. If the number of PING frames exceeds the configured limit, NetScaler drops packets on the connection.
-
http2MaxSettingsFramesPerMin: Set the maximum SETTINGS frames received per connection in a minute. If the number of SETTINGS frames exceeds the configured limit, NetScaler drops packets on the connection.
-
http2MaxResetFramesPerMin: Set the maximum RESET frames sent per connection in a minute. If the number of RESET frames exceeds the configured limit, NetScaler drops packets on the connection.
-
http2MaxEmptyFramesPerMin: Set the maximum empty frames sent per connection in a minute. If the number of empty frames exceeds the configured limit, NetScaler drops packets on the connection.
-
http2MaxRxResetFramesPerMin: Set the maximum RESET frames received per connection in a minute. If the number of RESET frames exceeds the configured limit, NetScaler drops packets on the connection.
-
http2SmallWndTimeout: Set the timeout, in seconds, for which an HTTP/2 stream can remain stalled at a zero or a small flow-control window before NetScaler silently closes the connection. The stall timer resets when the client acknowledges a meaningful amount of data, so genuinely slow clients are not affected. Set the value to 0 to disable this check.
-
-
Click OK and Close.HTTP/2 DoS mitigation GUI configuration