STIGUI
V-284928CAT II — Medium severitySV-284928r1212129_rule

The Cisco SNA appliance must be configured to use HTTP/2 at a minimum.

Rule version CSNA-ND-000870 · STIG v1 · 2026-07-08

Discussion

HTTP/2, like HTTPS, enhances security compared to HTTP/1.x by minimizing the risk of header-based attacks (e.g., header injection and manipulation).

Websites that fully use HTTP/2 are inherently protected and defend against smuggling attacks. HTTP/2 provides the method for specifying the length of a request, which removes any potential for ambiguity that can be leveraged by an attacker.

This is applicable to all web architectures such as load balancing/proxy use cases. - The front-end and back-end servers should both be configured to use HTTP/2. - HTTP/2 must be used for communications between web servers. - Browser vendors have agreed to only support HTTP/2 only in HTTPS mode; thus, TLS must be configured to meet this requirement. TLS configuration is out of scope for this requirement.

Check

Verify HTTP/1.x downgrading is disabled.

Navigate to Sysadmin Console >> Network >> HTTP Version >> Select >> Yes to Warning >> OK.

If the message displayed states "There are no changes to HTTP/2 settings.", then HTTP/1.x has been disabled.

If the HTTP/1.x downgrading is enabled, this is a finding.

Fix

Configure the Cisco SNA Appliance to use HTTP/2.

Navigate to Sysadmin Console >> Network >> HTTP Version >> Select >> Yes to Warning >> OK.

Identifiers

Group ID
V-284928
Group title
SRG-APP-000516-NDM-000317
Rule ID
SV-284928r1212129_rule
Check ID
C-89498r1205550_chk
Fix ID
F-89403r1205551_fix