<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Traffic :: Airlock Microgateway</title>
    <link>https://docs.airlock.com/microgateway/5.2/configuration-guides/traffic/</link>
    <description>This chapter contains configuration guides for traffic management.&#xA;For traffic-related topics, see also the Kubernetes Gateway API User Guides, especially the guides on routing, redirects and rewrites, traffic splitting, and TLS. They provide additional background and examples for common traffic management tasks.</description>
    <generator>Hugo</generator>
    <language>en-US</language>
    <atom:link href="https://docs.airlock.com/microgateway/5.2/configuration-guides/traffic/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Downstream HTTP/3</title>
      <link>https://docs.airlock.com/microgateway/5.2/configuration-guides/traffic/downstream-http-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>https://docs.airlock.com/microgateway/5.2/configuration-guides/traffic/downstream-http-3/</guid>
      <description>HTTP/3 is the latest version of HTTP and runs over QUIC (UDP). Compared to HTTP/2, it reduces connection setup time and avoids transport-level head-of-line blocking, which improves performance on lossy networks like mobile and Wi-Fi. This chapter explains how to enable HTTP/3 in real-world deployments.&#xA;Prerequisites What doesn’t work&#xA;HTTP/3 requires TLS 1.3&#xA;Ensure your Gateway negotiates TLS 1.3, otherwise clients will fall back to HTTP/2 or HTTP/1.1. You can also enforce TLS 1.3 on the Gateway by disallowing earlier TLS versions. In that case, only clients that support TLS 1.3 will be able to connect.</description>
    </item>
    <item>
      <title>Geolocation (GeoIP)</title>
      <link>https://docs.airlock.com/microgateway/5.2/configuration-guides/traffic/geolocation/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>https://docs.airlock.com/microgateway/5.2/configuration-guides/traffic/geolocation/</guid>
      <description>Airlock Microgateway uses a GeoIP database to determine the country associated with a request’s remote IP address. You can use this information in country-based request conditions and HTTP headers. Country information is also available in access logs and on metrics that provide a country label.&#xA;Prerequisites A Gateway Deployment. Permissions to modify the applicable Microgateway and Kubernetes resources. For a custom GeoIP database: a compatible database that can be made available to the Microgateway Engine. Configuration Configure client IP detection GeoIP lookups use the remote IP address selected by Microgateway’s client IP detection. Configure spec.defaults.downstream.remoteIP in the applicable GatewayParameters resource to match your deployment topology.</description>
    </item>
    <item>
      <title>Post-quantum Cryptography</title>
      <link>https://docs.airlock.com/microgateway/5.2/configuration-guides/traffic/post-quantum-cryptography/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>https://docs.airlock.com/microgateway/5.2/configuration-guides/traffic/post-quantum-cryptography/</guid>
      <description>TLS integration&#xA;With the advent of quantum computers capable of breaking classical public-key cryptographic schemes, widely used algorithms (including RSA and elliptic-curve cryptography) will become insecure. This already poses a serious risk to long-term confidentiality. In harvest-now-decrypt-later attacks, encrypted traffic is recorded today and stored so it can be decrypted later when sufficiently capable quantum computers become available.&#xA;Post-quantum cryptography (PQC) mitigates this threat by introducing algorithms designed to withstand both classical and quantum attacks. Airlock Microgateway integrates PQC in the TLS handshake using hybrid key exchange groups (classical and PQC combined). This maintains compatibility because clients that do not support PQC can negotiate traditional groups (e.g, X25519). Some performance overhead may be observed due to the additional computational cost of post-quantum algorithms.</description>
    </item>
  </channel>
</rss>