HTTP configurations
Setting global HTTP parameters
-
Default HTTP profile
-
Global HTTP command
Default HTTP profile
-
Not all HTTP parameters can be configured through the default HTTP profile. Some settings are performed by using the global HTTP command (see the following section).
-
The default profile does not have to be explicitly bound to a service or virtual server.
-
Using the command line interface, at the command prompt enter:
set ns httpProfile nshttp_default_profile … -
On the GUI, navigate to System > Profiles, click HTTP Profiles and update nshttp_default_profile.
Global HTTP command
-
Using the command line interface, at the command prompt enter:
set ns httpParam … -
On the GUI, navigate to System > Settings, click Change HTTP parameters and update the required HTTP parameters.
set ns httpParam [-ignoreConnectCodingScheme ( ENABLED | DISABLED )]
set ns httpParam -ignoreConnectCodingScheme ENABLED
Configure HTTP profile to drop TRACE or TRACK invalid requests
set ns httpProfile <profile name> [-markTraceReqInval ENABLED | DISABLED ]
set ns httpProfile profile1 -markTraceReqInval ENABLED
Configure HTTP profile for a service group
add serviceGroup <serviceGroupName>@ <serviceType> [-cacheType <cacheType>] [-td <positive_integer>] [-maxClient <positive_integer>] [-maxReq <positive_integer>] [-cacheable ( YES | NO )] [-cip ( ENABLED | DISABLED ) [<cipHeader>]] [-usip ( YES | NO )] [-pathMonitor ( YES | NO )] [-pathMonitorIndv ( YES | NO )] [-useproxyport ( YES | NO )] [-healthMonitor ( YES | NO )] [-sp ( ON | OFF )] [-rtspSessionidRemap ( ON | OFF )] [-cltTimeout <secs>] [-svrTimeout <secs>] [-CKA ( YES | NO )] [-TCPB ( YES | NO )] [-CMP ( YES | NO )] [-maxBandwidth
<positive_integer>] [-monThreshold <positive_integer>] [-state ENABLED DISABLED )][-downStateFlush ( ENABLED | DISABLED )] [-tcpProfileName <string>] [-httpProfileName <string>] [-comment <string>] [-appflowLog ( ENABLED | DISABLED )] [-netProfile <string>] [-autoScale <autoScale> -memberPort <port> [-autoDisablegraceful ( YES | NO )] [-autoDisabledelay <secs>] ] [-monConnectionClose ( RESET | FIN )]
add serviceGroup Service-Group-1 HTTP -maxClient 0 -maxReq 0 -cip ENABLED -usip NO -useproxyport YES -cltTimeout 200 -svrTimeout 300 -CKA NO -TCPB NO -CMP NO -httpProfileName profile1
Configure the HTTP profile using the NetScaler GUI
-
Sign into NetScaler appliance and navigate to Configuration > System > Profiles.
-
In the HTTP Profiles tab page, click Add.
-
In the Create HTTP Profile page, select Mark TRACE Requests as Invalid option.
-
Click Create.
Setting service or virtual server specific HTTP parameters
To specify service or virtual server level HTTP configurations by using the command line interface
-
Configure the HTTP profile.
set ns httpProfile <profile-name>... -
Bind the HTTP profile to the service or virtual server.To bind the HTTP profile to the service:
set service <name> .....
> set service service1 -httpProfileName profile1
set lb vserver <name> .....
> set lb vserver lbvserver1 -httpProfileName profile1
To specify service or virtual server level HTTP configurations by using the GUI
-
Configure the HTTP profile.Navigate to System > Profiles > HTTP Profiles, and create the HTTP profile.
-
Bind the HTTP profile to the service or virtual server.Navigate to Traffic Management > Load Balancing > Services/Virtual Servers, and create the HTTP profile, which must be bound to the service/virtual server.
Built-in HTTP profiles
| Built-in profile | Description |
|---|---|
| nshttp_default_profile | Represents the default global HTTP settings on the appliance. |
| nshttp_default_strict_validation | Settings for deployments that require strict validation of HTTP requests and responses. |
Sample HTTP configurations
-
HTTP band statistics
-
WebSocket connections
HTTP band statistics
> set protocol httpBand reqBandSize 300 respBandSize 2048
Done
> show protocol httpband -type REQUEST
WebSocket connections
> set ns httpProfile http_profile1 -webSocket ENABLED
Done
> set lb vserver lbvserver1 -httpProfileName profile1
Done
Configure the NetScaler appliance to delete or pass the upgrade header to the back-end server
-
If the passProtocolUpgrade parameter is enabled, then the upgrade header is passed to the back-end server. The server accepts the upgrade request and notifies it in its response.
-
If the parameter is disabled, then the upgrade header is deleted and the remaining request is sent to the back-end server.
-
nshttp_default_profile - enabled by default
-
nshttp_default_strict_validation - disabled by default
-
nshttp_default_internal_apps - disabled by default
-
nshttp_default_http_quic_profile - enabled by default
Set the passProtocolUpgrade parameter by using the CLI
set ns httpProfile <name> [-passProtocolUpgrade ( ENABLED | DISABLED )]
set ns httpProfile profile1 -passProtocolUpgrade ENABLED
Set the passProtocolUpgrade parameter by using the GUI
-
Navigate to System > Profiles > HTTP Profiles.
-
Create or edit an HTTP profile.
-
Select Pass Protocol Upgrade.
Configure HTTP profile to validate host headers
-
The length of the host header that is the IP address or the DNS name portion of the host header is not more than 255 characters.
-
The port number, if specified, is not more than 5 characters because the maximum port number is 65535.
Validate HTTP host headers using the NetScaler CLI
set ns httpprofile <name> -hostHeaderValidation (ENABLED | DISABLED)
set ns httpProfile http_profile1 -hostHeaderValidation ENABLED
Validate HTTP host headers using the NetScaler GUI
-
Navigate to System > Profiles > HTTP Profiles.
-
Create or edit an HTTP profile.
-
In the Configure HTTP Profile page, select Host header validation.
Configure HTTP profile to validate duplicate HTTP headers
maxDuplicateHeaderFields parameter in the HTTP profile to set the maximum limit for duplicate headers. This value can be configured using the NetScaler CLI or GUI.
Validate duplicate HTTP headers using the NetScaler CLI
set ns httpprofile <name> -maxDuplicateHeaderFields <value>
set ns httpprofile http_profile1 -maxDuplicateHeaderFields 5
Validate duplicate HTTP headers using the NetScaler GUI
-
Navigate to System > Profiles > HTTP Profiles.
-
Create or edit an HTTP profile.
-
In the Configure HTTP Profile page, enter a value in the Max Duplicate Header Fields.