This is a cross-vendor reference matrix for the security configuration settings that DDactic recommends most frequently. Each row represents a hardening control; each column shows the directive or setting name for a specific vendor. Use this as a lookup table when implementing DDactic recommendations or performing your own hardening review.
Rate Limiting
| Setting |
Cloudflare |
AWS WAF v2 |
Nginx |
Akamai |
| Per-IP rate limit |
WAF Custom Rule + ratelimit.characteristics=["ip.src"] |
RateBasedStatement, AggregateKeyType=IP |
limit_req_zone $binary_remote_addr |
Rate Policy, limitByIp=true |
| Per-user rate limit |
characteristics=["http.request.headers[\"authorization\"]"] |
AggregateKeyType=HEADER, Header.Name=Authorization |
limit_req_zone $http_authorization (via map) |
clientIdentifier=REQUEST_HEADERS:Authorization |
| Minimum time window |
10 seconds |
300 seconds (5 min) |
1 second (r/s) or 1 minute (r/m) |
1 second |
| Rate limit response code |
Configurable (use 429) |
Configurable via CustomResponse |
limit_req_status (default 503, set to 429) |
Configurable deny response |
| Log/monitor mode |
Action: Log |
Action: Count |
No native mode; use limit_req_log_level warn |
action: alert (not deny) |
TLS Configuration
| Setting |
Nginx |
Apache httpd |
HAProxy |
AWS ALB |
| TLS 1.3 only |
ssl_protocols TLSv1.3; |
SSLProtocol -all +TLSv1.3 |
ssl-min-ver TLSv1.3 |
Security Policy: ELBSecurityPolicy-TLS13-1-2-2021-06 |
| TLS min version |
ssl_protocols TLSv1.2 TLSv1.3; |
SSLProtocol -all +TLSv1.2 +TLSv1.3 |
ssl-min-ver TLSv1.2 |
ELBSecurityPolicy-TLS13-1-2-Res-2021-06 |
| Disable renegotiation |
ssl_conf_command Options -Renegotiation; (Nginx 1.19.4+) |
SSLRenegBufferSize 0 |
ssl-default-bind-options no-tls-tickets |
Not applicable (TLS 1.3 only) |
| HSTS header |
add_header Strict-Transport-Security "max-age=31536000; includeSubDomains"; |
Header always set Strict-Transport-Security "max-age=31536000" |
http-response add-header Strict-Transport-Security "max-age=31536000" |
Via ALB response rule or application |
Connection Limits
| Setting |
Nginx |
Apache httpd |
HAProxy |
| Max connections per IP |
limit_conn conn_zone 20; |
mod_reqtimeout + MaxConnectionsPerChild |
sc_conn_cur, stick-table limit |
| Idle connection timeout |
keepalive_timeout 15s; |
KeepAliveTimeout 15 |
timeout client 15s |
| Request timeout |
client_header_timeout 10s; client_body_timeout 10s; |
RequestReadTimeout header=10 body=20 |
timeout http-request 10s |
| Max body size |
client_max_body_size 1m; |
LimitRequestBody 1048576 |
option http-buffer-request + maxrewrite |
Get Vendor-Specific Recommendations for Your Stack
DDactic assessments identify your specific vendor stack and deliver hardening recommendations using the exact directives from this matrix, pre-configured for your measured saturation thresholds.
Run a Free Scan
WAF Vendor MatrixCloudflareAWS WAFNginxHAProxyAkamaiTLS