| Solution | - In FortiWeb -> Web Protection -> Protocol -> HTTP, select Create New or Edit an existing entry. (The example in this article is made with Create New).
- In the new window, input a name. Enable HTTP/2 Max Requests and set an action as needed (the default action is Alert), then select OK.
- Check the new HTTP Protocol Constraints were created successfully. The name used here is http2_test.
- Under FortiWeb -> Policy -> Web Protection Profile, edit the corresponding profile.
- Select the newly added profile (http2_test in this example) in HTTP Protocol Constraints and select OK.
To apply it on FortiAppSec Cloud: - Navigate to the desired Application.
- Navigate to Application Name -> Access Rules -> Request Limits, then set 'HTTP/2 Max Requests' to 'ON' and 'Number of HTTP/2 Max Requests' to '1000'.
|