Lesson 14 / 25

HTTP/2 and HTTP/3

Enable HTTP/2 and HTTP/3 (QUIC) and understand what they change.

Newer protocols for faster pages

HTTP/2 multiplexes many requests over one TCP connection, compresses headers and removes the need for workarounds like domain sharding. In NGINX it is enabled per server with http2 on; (since version 1.25.1; older versions used listen 443 ssl http2;). Browsers use HTTP/2 only over TLS. HTTP/3 runs HTTP over QUIC, a UDP-based transport that avoids TCP head-of-line blocking, sets up connections faster and handles network changes (Wi-Fi to mobile) better. NGINX supports it since 1.25.0 with listen 443 quic reuseport; alongside the TCP listener, plus an Alt-Svc header telling browsers that HTTP/3 is available, so they upgrade on subsequent requests. Open UDP port 443 in firewalls and security groups. Keep HTTP/1.1 and HTTP/2 enabled for clients and networks that block UDP. HTTP/2 server push is deprecated and was removed from NGINX; use preload hints (Link: rel=preload or 103 Early Hints) instead.

HTTP/1.1, HTTP/2 and HTTP/3 on one server

TCP and UDP listeners share port 443; Alt-Svc advertises HTTP/3.

server {
    listen 443 ssl;                 # TCP: HTTP/1.1 and HTTP/2
    listen 443 quic reuseport;      # UDP: HTTP/3 (reuseport on one server block only)
    http2 on;
    http3 on;
    server_name www.example.com;

    ssl_certificate     /etc/ssl/example/fullchain.pem;
    ssl_certificate_key /etc/ssl/example/privkey.pem;
    ssl_protocols TLSv1.2 TLSv1.3;  # QUIC requires TLS 1.3

    add_header Alt-Svc 'h3=":443"; ma=86400' always;
    root /var/www/example;
}
# remember: allow UDP 443 in the firewall / security group

Lanes on a highway

HTTP/1.1 is a single-lane road where one slow truck holds everyone up. HTTP/2 adds many lanes but still on one road (TCP) that closes entirely if one lane has an accident. HTTP/3 gives each lane its own road surface (QUIC streams), so one accident does not block the others.

Quick check: What extra network change is usually required to serve HTTP/3?

  • Opening TCP port 80
  • Disabling TLS
  • Enabling SSLv3
  • Allowing UDP port 443 through firewalls
Answer

Allowing UDP port 443 through firewalls — HTTP/3 runs over QUIC on UDP, so UDP 443 must be allowed.