# Main Settings | v3

import Tag from '~/components/webkit/Tag.vue'
import DocButton from '~/components/webkit/DocButton.vue';

import Apiv4Rollout from '~/includes/snippets/apiv4Rollout/en/snippet.mdx'

<Apiv4Rollout />

:::caution[important]
You're viewing an earlier version of this documentation. If your account has already been migrated, see the updated [Application main settings reference](/en/documentation/products/build/edge-application/main-settings/).
:::


With [Application](/en/documentation/products/build/edge-application/), you can choose your application's delivery protocol and ports. You can also ensure the security of the HTTPS connection between the application and its users with TLS ciphers.

---

## Delivery Protocols

- **HTTP**: delivers your application using only the HTTP protocol.
- **HTTP & HTTPS**: delivers your application using both the HTTP and HTTPS protocols.

:::note
If you choose to deliver your application through HTTP & HTTPS, you must associate a [digital certificate](/en/documentation/products/secure/firewall/certificate-manager/) to your domain.
:::

### HTTP/3 support

If you choose to deliver your application through **HTTP & HTTPS**, you can enable **HTTP/3 support**. Based on the QUIC protocol standard, HTTP/3 provides faster load times and lower latency when compared to previous versions.

When you enable HTTP/3 support, your applications can utilize this protocol version in compatible browsers only through *HTTP port 80* and *HTTPS port 443*.

Upon a user's first request to an application with HTTP/3, the handshake and first response will be conducted using TCP and HTTP/1.1 or HTTP/2. The response from this exchange will assign a value to the [Alt-Svc header](https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Alt-Svc) that indicates that the latest version of the protocol is available to the browser. If the browser supports HTTP/3, the QUIC protocol and HTTP/3 will be used, unless the cached response misses or expires.

---

## Ports

Azion offers a simultaneous multiport solution, which means you can customize through which HTTP and HTTPS ports your application will be delivered to. You must choose *at least one port* for each protocol, but you can select from all available ports for delivery.

:::note
If you enable [HTTP/3 support](#http3-support), multiport configuration will be overwritten to the default ports 80 for HTTP and 443 for HTTPS. Simultaneous multiport isn't available for applications with HTTP/3 support.
:::

### Available ports

| HTTP Port    | HTTPS Port    |
|--------------|---------------|
| 80 (default)  | 443 (default)  |
| 8008         | 8443          |
| 8080         | 9440          |
| 8880         | 9441          |
|              | 9442          |
|              | 9443          |
|              | 7777          |
|              | 8888          |
|              | 9553          |
|              | 9653          |
|              | 8035          |
|              | 8090          |

:::note
All ports listed above are open at the infrastructure level across all of Azion's data centers for all customers. This is required by the simultaneous multiport architecture. However, **your application only responds on the ports you explicitly configure**. Requests arriving on ports not selected for your application are not routed to your origin and do not expose your application's content.

If a pentest or port scan reports multiple open ports on an Azion IP address, this reflects the shared infrastructure behavior — not a misconfiguration of your application.
:::

---

## Minimum TLS version

The **Transport Layer Security (TLS)** protocol allows you to encrypt web traffic. The following TLS versions can be used with applications:

- TLS 1.0 (*deprecated*)
- TLS 1.1 (*deprecated*)
- TLS 1.2
- TLS 1.3 (Default)

You can choose the minimum version of TLS that'll be supported by your application. By choosing recent versions of the protocol, older devices or browsers might not be able to access the application.

Azion blocks TLS Renegotiation and TLS Resumption by default. If you want to customize this setup, [contact the Sales team](https://www.azion.com/en/contact/).

:::note
A TLS scan performed against an Azion data center IP or domain returns the TLS versions accepted at the **infrastructure level** — not the minimum TLS version configured for your application. Azion's shared infrastructure accepts TLS 1.0, 1.1, 1.2, and 1.3 at the network layer.

The minimum TLS version you configure is enforced at the **application layer**: your application will reject any connection that uses a TLS version lower than the one you set. For example, if you configure TLS 1.2 as the minimum, connections using TLS 1.0 or 1.1 will be refused when targeting your domain, even if the infrastructure layer accepts them.

You can verify this behavior by attempting a connection with a lower TLS version using `curl --tlsv1.1 --tls-max 1.1 https://yourdomain.com`. The request will fail with a TLS handshake error if your minimum TLS version is set to 1.2 or higher.
:::

---

## TLS Ciphers

Ciphers are cryptography algorithms utilized to encrypt *plaintext* into *ciphertext*, which requires a key to be decrypted. Azion gives you the possibility to change the *cipher suite* your application will use in order to protect your application against TLS attacks.

The cipher suite will determine which cryptographic algorithms will be used in the TLS connections of your application. Both client and server will *negotiate* the cipher suite to securely encrypt and decrypt the data exchanged during the session.

The table below shows all ciphers available across cipher suites, ordered by TLS version and security level (most to least secure within each version).

| TLS Version | Cipher | MLKEM (PQC) | TLSv1.2_2018 | TLSv1.2_2019 | TLSv1.2_2021 | TLSv1.3_2022 | Legacy_v2025Q1 | Compatible_v2025Q1 | Modern_v2025Q1 | Legacy_v2017Q1 |
| --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- |
| **TLS 1.3** | TLS_AES_256_GCM_SHA384 | ✔︎ | ✔︎ | ✔︎ | ✔︎ | ✕ | ✔︎ | ✔︎ | ✔︎ | ✔︎ |
| **TLS 1.3** | TLS_CHACHA20_POLY1305_SHA256 | ✔︎ | ✔︎ | ✔︎ | ✔︎ | ✕ | ✔︎ | ✔︎ | ✔︎ | ✔︎ |
| **TLS 1.3** | TLS_AES_128_GCM_SHA256 | ✔︎ | ✔︎ | ✔︎ | ✔︎ | ✕ | ✔︎ | ✔︎ | ✔︎ | ✔︎ |
| **TLS 1.2** | ECDHE-ECDSA-AES256-GCM-SHA384 | ✕ | ✔︎ | ✔︎ | ✔︎ | ✔︎ | ✔︎ | ✔︎ | ✔︎ | ✔︎ |
| **TLS 1.2** | ECDHE-RSA-AES256-GCM-SHA384 | ✕ | ✔︎ | ✔︎ | ✔︎ | ✔︎ | ✔︎ | ✔︎ | ✔︎ | ✔︎ |
| **TLS 1.2** | ECDHE-ECDSA-CHACHA20-POLY1305 | ✕ | ✔︎ | ✔︎ | ✔︎ | ✔︎ | ✔︎ | ✔︎ | ✔︎ | ✔︎ |
| **TLS 1.2** | ECDHE-RSA-CHACHA20-POLY1305 | ✕ | ✔︎ | ✔︎ | ✔︎ | ✔︎ | ✔︎ | ✔︎ | ✔︎ | ✔︎ |
| **TLS 1.2** | ECDHE-ECDSA-AES128-GCM-SHA256 | ✕ | ✔︎ | ✔︎ | ✔︎ | ✔︎ | ✔︎ | ✔︎ | ✔︎ | ✔︎ |
| **TLS 1.2** | ECDHE-RSA-AES128-GCM-SHA256 | ✕ | ✔︎ | ✔︎ | ✔︎ | ✔︎ | ✔︎ | ✔︎ | ✔︎ | ✔︎ |
| **TLS 1.2** | ECDHE-ECDSA-AES256-SHA384 | ✕ | ✔︎ | ✔︎ | ✕ | ✕ | ✔︎ | ✔︎ | ✕ | ✔︎ |
| **TLS 1.2** | ECDHE-RSA-AES256-SHA384 | ✕ | ✔︎ | ✔︎ | ✕ | ✕ | ✔︎ | ✔︎ | ✕ | ✔︎ |
| **TLS 1.2** | ECDHE-ECDSA-AES128-SHA256 | ✕ | ✔︎ | ✔︎ | ✕ | ✕ | ✔︎ | ✔︎ | ✕ | ✔︎ |
| **TLS 1.2** | ECDHE-RSA-AES128-SHA256 | ✕ | ✔︎ | ✔︎ | ✕ | ✕ | ✔︎ | ✔︎ | ✕ | ✔︎ |
| **TLS 1.2** | ECDHE-ECDSA-AES256-SHA | ✕ | ✕ | ✕ | ✕ | ✕ | ✕ | ✕ | ✕ | ✔︎ |
| **TLS 1.2** | ECDHE-ECDSA-AES128-SHA | ✕ | ✕ | ✕ | ✕ | ✕ | ✕ | ✕ | ✕ | ✔︎ |
| **TLS 1.2** | ECDHE-RSA-AES256-SHA | ✕ | ✕ | ✕ | ✕ | ✕ | ✕ | ✕ | ✕ | ✔︎ |
| **TLS 1.2** | ECDHE-RSA-AES128-SHA | ✕ | ✕ | ✕ | ✕ | ✕ | ✕ | ✕ | ✕ | ✔︎ |
| **TLS 1.2** | AES256-GCM-SHA384 | ✕ | ✔︎ | ✕ | ✕ | ✕ | ✔︎ | ✔︎ | ✕ | ✔︎ |
| **TLS 1.2** | AES128-GCM-SHA256 | ✕ | ✔︎ | ✕ | ✕ | ✕ | ✔︎ | ✔︎ | ✕ | ✔︎ |
| **TLS 1.2** | AES256-SHA | ✕ | ✕ | ✕ | ✕ | ✕ | ✔︎ | ✕ | ✕ | ✔︎ |
| **TLS 1.2** | AES128-SHA256 | ✕ | ✔︎ | ✕ | ✕ | ✕ | ✔︎ | ✕ | ✕ | ✔︎ |
| **TLS 1.2** | AES128-SHA | ✕ | ✕ | ✕ | ✕ | ✕ | ✔︎ | ✕ | ✕ | ✔︎ |
| **TLS 1.2** | AES256-CCM | ✕ | ✕ | ✕ | ✕ | ✕ | ✕ | ✕ | ✕ | ✔︎ |
| **TLS 1.2** | AES256-CCM8 | ✕ | ✕ | ✕ | ✕ | ✕ | ✕ | ✕ | ✕ | ✔︎ |
| **TLS 1.2** | AES128-CCM | ✕ | ✕ | ✕ | ✕ | ✕ | ✕ | ✕ | ✕ | ✔︎ |
| **TLS 1.2** | AES128-CCM8 | ✕ | ✕ | ✕ | ✕ | ✕ | ✕ | ✕ | ✕ | ✔︎ |

:::note
**Post-Quantum Cryptography (MLKEM)**: TLS 1.3 ciphers support hybrid key exchange using ECDH/MLKEM (Module-Lattice-Based Key-Encapsulation Mechanism). This provides quantum-resistant encryption on TLS 1.3 connections. MLKEM is the NIST-standardized post-quantum algorithm (formerly known as Kyber).
:::

<DocButton href="/en/documentation/products/guides/secure/ciphers/" label="go to configure TLS cipher suite guide" kind="secondary" size="medium" />