Feature Explorer AI AI

×

Subscribe now to get the Latest Updates

Watch a 2-minute overview video

HTTP/2 inspection: SSL proxy support

More Information:

HTTP/2 inspection: SSL proxy support

SSL proxy adds Application-Layer Protocol Negotiation (ALPN)-based HTTP/2 inspection with policy controls for TLS 1.2 and TLS 1.3. During the TLS handshake, the proxy negotiates the HTTP/2 identifier h2 with compliant peers and falls back to HTTP/1.1 when HTTP/2 is disabled or not allowed.

HTTP/2 is disabled by default. You can enable or disable it globally by using the set services ssl proxy global-config http2 on|off command. Disable HTTP/2 selectively per policy using the set security policies from-zone to-zone policy then permit application-services ssl-proxy disable-http2 command.

The SSL proxy enforces protocols by stripping HTTP/3 ALPN, blocks prohibited TLS 1.2 cipher suites, rejects renegotiation, and terminates TLS 1.3 post handshake authentication.

Product / Application Software Introduced Release
vSRX Junos OS 26.2R1
cSRX Junos OS 26.2R1
SRX300 Junos OS 26.2R1
SRX320 Junos OS 26.2R1
SRX340 Junos OS 26.2R1
SRX345 Junos OS 26.2R1
SRX380 Junos OS 26.2R1
SRX1500 Junos OS 26.2R1
SRX1600 Junos OS 26.2R1
SRX2300 Junos OS 26.2R1
SRX4100 Junos OS 26.2R1
SRX4200 Junos OS 26.2R1
SRX4300 Junos OS 26.2R1
SRX4600 Junos OS 26.2R1
SRX5400 Junos OS 26.2R1
SRX5600 Junos OS 26.2R1
SRX5800 Junos OS 26.2R1