The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

HTTP2 traffic inspection

Prev Next

Introduction

IPS supports HTTP2 inspection for the following scenarios:

  • HTTP2 Prior Knowledge

  • HTTP2 over TLS

Note

HTTP2 upgrade (h2c) scenario is not supported.

When you install/upgrade the Manager, by default, HTTP2 traffic inspection is not enabled.

Enable HTTP2 traffic inspection from the Manager

You can enable HTTP2 traffic inspection at both Global and Devices level in the Manager.

To enable HTTP2 traffic inspection at Global level, go to Devices → <Admin Domain Name> → Global → IPS Device Settings → Advanced Device Settings and select Enable HTTP2 Traffic.

Advanced Device Settings at Global level
Advanced Device Settings at Global level


To enable HTTP2 traffic inspection at Devices level, go to Devices → <Admin Domain Name> → Devices → <Device Name> → Setup → Advanced → Advanced Device Settings and select Enable HTTP2 Traffic.

Advanced Device Settings at Device level
Advanced Device Settings at Device level


Note

By default, Enable HTTP2 Traffic is disabled.

After enabling the HTTP2 traffic inspection from Devices tab, follow the below steps:

  1. Go to Policy → <Admin Domain Name> → Intrusion Prevention → Policy Types → Inspection Options.

  2. Navigate to Inspection Options tab and click Traffic Inspection tab.

  3. Configure HTTP Response Traffic Scanning based on your requirement.

  4. Go to HTTP2 section, configure HTTP2 Traffic Scanning and HTTP2 Server Push Traffic Scanning based on your requirement.

  5. Click Save.

Notes:

  • The Sensor requires a reboot when you enable or disable HTTP2 Traffic Scanning. You can check the Sensor reboot status from Device Manager or status CLI.

  • HTTP2 Traffic Scanning can be enabled only when HTTP Response Traffic Scanning is enabled.

  • HTTP2 Server Push Traffic Scanning can be enabled only when HTTP2 Traffic Scanning is enabled.

  • HTTP2 traffic inspection requires a sigset with HTTP2 features.

  • Only NS9600, NS9500, NS7600, NS7500, and NS3600 Sensors support HTTP2 traffic inspection.

  • From 11.1.5.122, HTTP2 traffic inspection with TLS and proxy-based SSL decryption is supported.

  • HTTP2 performance numbers align with HTTP 1.1 for supported Sensor models.

Inspection Options: Traffic Inspection
Inspection Options: Traffic Inspection


HTTP2 Protocol settings

You can configure the HTTP2 protocol settings for any required Sensor from Devices → <Admin Domain Name> → Devices → <Device Name> → Setup → Advanced → Protocol Settings. Go to HTTP2 section, and configure the following:

Parameters

Description

Flow Allocation %

Set the maximum HTTP2 flows as a percentage of total supported flows. Flow allocation differs for each Sensor model. For NS3600, NS7500, NS7600, NS9500 and NS9600 Sensors the min and max flow allocation are as follows:

  • NS3600 and NS7500 - It can range from 1% to 5%.

  • NS7600, NS9500 and NS9600 - It can range from 1% to 10%.

After configuring, click Update to apply the changes.

Note

The Sensor requires a reboot after updating the flow allocation.

Include decoded packets in attack packet log

While inspecting HTTP2 traffic, the Sensor decodes the HTTP2 packets/frames into HTTP requests/responses. By enabling this, the Manager will include decoded HTTP requests/responses along with HTTP2 packets/frames in the attack packet log.

After configuring, click Update to apply the changes.

Slowloris Attack Configuration

Allows you to configure the values for the following parameters:

  • Slow Post Timeout - Set the value between 5 and 30.

  • Slow Post Threshold Frame Size - Set the value between 1 and 100.

  • Slow Post Minimum Number of Streams - Set the value between 50 and 100.

  • Slow Post Min Number of Tiny Frames - Set the value between 1 and 10.

  • Slow Read Timeout - Set the value between 30 and 300.

  • Slow Read Window Size - Set the value between 1 and 100.

  • Slow Read Minimum Number of Streams - Set the value between 50 and 100.

Note

Users are recommended to modify these configurations only in consultation with Trellix support team.

HTTP2 Protocol Settings
HTTP2 Protocol Settings


Alert enhancements for HTTP2

The following new alert fields are included in Layer 7 data:

  • HTTP2_STREAM_ID

  • HTTP2_SETTINGS_ENABLE_PUSH

  • HTTP2/3_HTTP_VERSION

You can customize the alert fields from Devices → <Admin Domain Name> → Devices → <Device Name> → Setup → Advanced → L7 Data Collection.

Note

HTTP2/3 HTTP VERSION is always enabled.

Layer 7 Data Collection
Layer 7 Data Collection


Filter HTTP2 alerts

You can filter HTTP2 alerts through the Attack Log or Reports page in the Manager.

Attack Log

To focus on attacks detected on HTTP2 traffic, you can apply the filter in the Attack Log. To apply the filter, select Filters from Layer 7 Data column drop-down and in the search field, enter HTTP2/3 HTTP VERSION: HTTP2.

Layer 7 Data: Filter value
Layer 7 Data: Filter value


Alerts for attacks detected on HTTP2 traffic
Alerts for attacks detected on HTTP2 traffic


For a particular alert, you can differentiate the HTTP2 alerts by verifying the Protocol data in Summary tab of Details panel in Attack Log page.

Summary tab
Summary tab


You can also verify the HTTP2 alerts through the Layer 7 section in Details tab of Details panel in Attack Log page.

Details tab
Details tab


Reports

You can follow the below steps to create HTTP2 reports:

  1. Go to Analysis → <Admin Domain Name> → Event Reporting → Custom Reports.

  2. In the Custom Reports page, select New.

  3. Select the type of data as Alert Data and click Next.

  4. Specify the required display and click Next.

  5. Specify the required fields and click Next.

  6. Select Protocol and set the property value to be equal to HTTP2 and click Next.

  7. Configure the Date Options and Report Format.

  8. Click Run.

Supported features with HTTP2

In this release, IPS supports following HTTP2 attack categories:

  • Attack content in a single HTTP2 stream

  • Attack content across multiple HTTP2 stream

  • HTTP2 protocol compliance attacks

  • HTTP2 DoS attacks

Unsupported features with HTTP2

In this release, the following features are not supported over HTTP2 connections:

  • Malware scanning

  • URL Reputation

  • Application Identification

  • SSL (Known Key, Agent)

  • Mandate Authentication/HTTP Redirection

  • Layer 7 Distributed DoS

  • Trellix Snort Rules

  • Botnet detection over HTTP

  • Connection limiting

  • X-Forwarded-For Header Parsing (XFF)

  • Decompression (Gzip, Deflate) and Decoding (Chunk, HTML)

  • Shell Code Detection

  • Firewall

  • File Reputation

  • Web Security

  • IPS Quarantine