WAF Vendor Command Matrix: Rate Limiting, TLS, Connection Settings

June 5, 2026 | 15 min read | Configuration Reference

This is a cross-vendor reference matrix for the security configuration settings that DDactic recommends most frequently. Each row represents a hardening control; each column shows the directive or setting name for a specific vendor. Use this as a lookup table when implementing DDactic recommendations or performing your own hardening review.

Rate Limiting

Setting Cloudflare AWS WAF v2 Nginx Akamai
Per-IP rate limit WAF Custom Rule + ratelimit.characteristics=["ip.src"] RateBasedStatement, AggregateKeyType=IP limit_req_zone $binary_remote_addr Rate Policy, limitByIp=true
Per-user rate limit characteristics=["http.request.headers[\"authorization\"]"] AggregateKeyType=HEADER, Header.Name=Authorization limit_req_zone $http_authorization (via map) clientIdentifier=REQUEST_HEADERS:Authorization
Minimum time window 10 seconds 300 seconds (5 min) 1 second (r/s) or 1 minute (r/m) 1 second
Rate limit response code Configurable (use 429) Configurable via CustomResponse limit_req_status (default 503, set to 429) Configurable deny response
Log/monitor mode Action: Log Action: Count No native mode; use limit_req_log_level warn action: alert (not deny)

TLS Configuration

Setting Nginx Apache httpd HAProxy AWS ALB
TLS 1.3 only ssl_protocols TLSv1.3; SSLProtocol -all +TLSv1.3 ssl-min-ver TLSv1.3 Security Policy: ELBSecurityPolicy-TLS13-1-2-2021-06
TLS min version ssl_protocols TLSv1.2 TLSv1.3; SSLProtocol -all +TLSv1.2 +TLSv1.3 ssl-min-ver TLSv1.2 ELBSecurityPolicy-TLS13-1-2-Res-2021-06
Disable renegotiation ssl_conf_command Options -Renegotiation; (Nginx 1.19.4+) SSLRenegBufferSize 0 ssl-default-bind-options no-tls-tickets Not applicable (TLS 1.3 only)
HSTS header add_header Strict-Transport-Security "max-age=31536000; includeSubDomains"; Header always set Strict-Transport-Security "max-age=31536000" http-response add-header Strict-Transport-Security "max-age=31536000" Via ALB response rule or application

Connection Limits

Setting Nginx Apache httpd HAProxy
Max connections per IP limit_conn conn_zone 20; mod_reqtimeout + MaxConnectionsPerChild sc_conn_cur, stick-table limit
Idle connection timeout keepalive_timeout 15s; KeepAliveTimeout 15 timeout client 15s
Request timeout client_header_timeout 10s; client_body_timeout 10s; RequestReadTimeout header=10 body=20 timeout http-request 10s
Max body size client_max_body_size 1m; LimitRequestBody 1048576 option http-buffer-request + maxrewrite

Get Vendor-Specific Recommendations for Your Stack

DDactic assessments identify your specific vendor stack and deliver hardening recommendations using the exact directives from this matrix, pre-configured for your measured saturation thresholds.

Run a Free Scan
WAF Vendor MatrixCloudflareAWS WAFNginxHAProxyAkamaiTLS