Lesson 14 / 25
HTTP/2 and HTTP/3
Enable HTTP/2 and HTTP/3 (QUIC) and understand what they change.
Newer protocols for faster pages
HTTP/2 multiplexes many requests over one TCP connection, compresses headers and removes the need for workarounds like domain sharding. In NGINX it is enabled per server with http2 on; (since version 1.25.1; older versions used listen 443 ssl http2;). Browsers use HTTP/2 only over TLS. HTTP/3 runs HTTP over QUIC, a UDP-based transport that avoids TCP head-of-line blocking, sets up connections faster and handles network changes (Wi-Fi to mobile) better. NGINX supports it since 1.25.0 with listen 443 quic reuseport; alongside the TCP listener, plus an Alt-Svc header telling browsers that HTTP/3 is available, so they upgrade on subsequent requests. Open UDP port 443 in firewalls and security groups. Keep HTTP/1.1 and HTTP/2 enabled for clients and networks that block UDP. HTTP/2 server push is deprecated and was removed from NGINX; use preload hints (Link: rel=preload or 103 Early Hints) instead.
HTTP/1.1, HTTP/2 and HTTP/3 on one server
TCP and UDP listeners share port 443; Alt-Svc advertises HTTP/3.
server {
listen 443 ssl; # TCP: HTTP/1.1 and HTTP/2
listen 443 quic reuseport; # UDP: HTTP/3 (reuseport on one server block only)
http2 on;
http3 on;
server_name www.example.com;
ssl_certificate /etc/ssl/example/fullchain.pem;
ssl_certificate_key /etc/ssl/example/privkey.pem;
ssl_protocols TLSv1.2 TLSv1.3; # QUIC requires TLS 1.3
add_header Alt-Svc 'h3=":443"; ma=86400' always;
root /var/www/example;
}
# remember: allow UDP 443 in the firewall / security groupLanes on a highway
HTTP/1.1 is a single-lane road where one slow truck holds everyone up. HTTP/2 adds many lanes but still on one road (TCP) that closes entirely if one lane has an accident. HTTP/3 gives each lane its own road surface (QUIC streams), so one accident does not block the others.
Quick check: What extra network change is usually required to serve HTTP/3?
- Opening TCP port 80
- Disabling TLS
- Enabling SSLv3
- Allowing UDP port 443 through firewalls
Answer
Allowing UDP port 443 through firewalls — HTTP/3 runs over QUIC on UDP, so UDP 443 must be allowed.