HTTP/3
[!NOTE] HTTP/3 is in beta and needs a valid license. NullWard can serve your services over HTTP/3 (QUIC) as well as HTTP/1.1 and HTTP/2. It can also connect to backends over HTTP/3, directly or through a tunnel. All traffic gets the same WAF and security checks whatever the protocol. Turn on HTTP/3 for visitors Publish the HTTPS port over UDP. HTTP/3 uses the same port as HTTPS, but over UDP. In Docker Compose, add "443:7443/udp" next to "443:7443". Open UDP 443 in your host and cloud firewalls. Raise the host's UDP buffers for full throughput: Add the same settings to /etc/sysctl.d/ to keep them after a reboot. Under Settings > HTTP/3, turn on Enable HTTP/3 and click Save Changes. It takes effect within a second, with no restart. The status panel at the top of the tab shows whether this node's HTTP/3 listener is running and what it advertises. Browsers first connect over HTTP/2, see NullWard's Alt-Svc header, and switch to HTTP/3 on later requests. If you turn HTTP/3 off, NullWard tells browsers to stop using it. Setting Default Purpose Advertised UDP Port 0 (the HTTPS listen port) Set it to the public port when it differs from the port NullWard listens on, for example 443 when Docker maps 443 to 7443. Advertisement Lifetime 86400 s How long browsers remember that HTTP/3 is available. Address Validation Threshold 128 Once this many handshakes are in progress, new clients must first prove their address (QUIC Retry). This protects against spoofed-source floods. Handshakes per IP 32 The most handshakes one address can have in progress at once. Further attempts fall back to HTTP/2. Blocklisted IP addresses are refused before the QUIC handshake. Per service Under the service's TLS Configuration > HTTP/3 (QUIC), choose Inherit global setting, On for this service or Off for this service. HTTP/3 needs TLS 1.3, so the service's maximum TLS version must allow it. WebSockets keep working over HTTP/1.1 and HTTP/2. HTTP/3 to your backends Direct destinations On the service, under General > Destinations, set an https:// destination's Protocol to HTTP/3. The backend must accept HTTP/3 on that port over UDP. NullWard doesn't fall back to TCP if HTTP/3 fails, so use this only for backends that serve HTTP/3. Tunnel destinations Set the upstream group's protocol to h3. For a generic connector, set protocol: h3 in its configuration. For Kubernetes, annotate the Service with nullward.io/protocol=h3 and make sure the Service port accepts UDP. The connector then speaks HTTP/3 to your application. Without a valid license, HTTP/3 destinations are reached over HTTPS on TCP instead.
NullWard documentation