SSL proxy adds Application-Layer Protocol Negotiation (ALPN)-based HTTP/2 inspection with policy controls for TLS 1.2 and TLS 1.3. During the TLS handshake, the proxy negotiates the HTTP/2 identifier h2 with compliant peers and falls back to HTTP/1.1 when HTTP/2 is disabled or not allowed.
HTTP/2 is disabled by default. You can enable or disable it globally by using the set services ssl proxy global-config http2 on|off command. Disable HTTP/2 selectively per policy using the set security policies from-zone
The SSL proxy enforces protocols by stripping HTTP/3 ALPN, blocks prohibited TLS 1.2 cipher suites, rejects renegotiation, and terminates TLS 1.3 post handshake authentication.
| Product / Application | Software | Introduced Release |
|---|---|---|
| vSRX | Junos OS | 26.2R1 |
| cSRX | Junos OS | 26.2R1 |
| SRX300 | Junos OS | 26.2R1 |
| SRX320 | Junos OS | 26.2R1 |
| SRX340 | Junos OS | 26.2R1 |
| SRX345 | Junos OS | 26.2R1 |
| SRX380 | Junos OS | 26.2R1 |
| SRX1500 | Junos OS | 26.2R1 |
| SRX1600 | Junos OS | 26.2R1 |
| SRX2300 | Junos OS | 26.2R1 |
| SRX4100 | Junos OS | 26.2R1 |
| SRX4200 | Junos OS | 26.2R1 |
| SRX4300 | Junos OS | 26.2R1 |
| SRX4600 | Junos OS | 26.2R1 |
| SRX5400 | Junos OS | 26.2R1 |
| SRX5600 | Junos OS | 26.2R1 |
| SRX5800 | Junos OS | 26.2R1 |