---
name: azion-configure-http-and-https-ports
description: >-
  Choose the HTTP and HTTPS ports a workload listens on, and send each port to an origin port, from Azion Console, the Azion CLI, or the API.
---

# Configure HTTP and HTTPS ports

You can choose the ports a [workload](/en/documentation/platform/workloads/) listens on for HTTP and HTTPS, and send the requests of each port to an origin port, from Azion Console, the [Azion CLI](/en/documentation/devtools/cli/), or the API. For the TLS version and the cipher suite of the HTTPS ports, refer to [Set the TLS cipher suite](/en/documentation/guides/application-security/tls-and-certificates/ciphers/).

Two ports take part in every request. The delivery port is the port your users connect to, and the workload sets it. The origin port is the port Azion connects to on your origin, and the [connector](/en/documentation/platform/connectors/) of the application sets it. Each one has a default, `80` for HTTP and `443` for HTTPS, and you can change either one without the other.

This table shows the combinations, with an example request and the setting each one changes:

| Combination                                                | Origin URL                        | Delivery URL                   | What to change                                                                        |
| ---------------------------------------------------------- | --------------------------------- | ------------------------------ | ------------------------------------------------------------------------------------- |
| Default origin port, default delivery port                 | `https://origin.example.com:443`  | `https://www.example.com:443`  | Nothing                                                                               |
| Default origin port, other protocol than the delivery port | `http://origin.example.com:80`    | `https://www.example.com:443`  | The protocol policy of the connector                                                  |
| Default origin port, custom delivery port                  | `http://origin.example.com:80`    | `http://www.example.com:8080`  | The ports of the workload                                                             |
| Custom origin port, default delivery port                  | `https://origin.example.com:9443` | `https://www.example.com:443`  | The ports of the connector                                                            |
| Custom origin port, custom delivery port                   | `https://origin.example.com:8443` | `https://www.example.com:9443` | The ports of the workload and of the connector, and one rule per custom delivery port |

An account that runs on API v3 sets its delivery ports on the application instead. For more information, refer to [Main Settings](/en/documentation/platform/applications/main-settings-v3/) and [API v4 Migration](/en/documentation/fundamentals/api-v4-migration/).

---

Select an interface. The prerequisites and the steps of each task follow your choice.

## Prerequisites

- A workload whose deployment names an application. To create both, refer to [Workloads quickstart](/en/documentation/platform/workloads/quickstart/).
- For a custom origin port, a connector to your origin that the application's rules can name. To create a connector and a rule, refer to [Applications quickstart](/en/documentation/platform/applications/quickstart/).

**Console**

- Access to Azion Console. For more information, refer to [How to access Azion Console](/en/documentation/guides/platform/account-and-billing/how-to-access-azion-console/).

**CLI**

- The [Azion CLI](/en/documentation/devtools/cli/), authorized with your account. This page matches Azion CLI 4.23.0.
- The workload ID. `azion create workload` prints it as `Created Workload with ID <workload-id>`.
- The application ID and the connector ID, for a custom origin port.

**API**

- A personal token for the `Authorization` header, in the form `Token [TOKEN VALUE]`. To create a token, refer to [Personal tokens](/en/documentation/fundamentals/personal-tokens/).
- `curl` or another HTTP client.
- The workload ID, and, for a custom origin port, the application ID and the connector ID.

---

## Set the ports the workload listens on

The HTTP and HTTPS ports of a workload are two lists in its `protocols.http` object. HTTP ports come from four values: `80`, `8008`, `8080`, and `8880`. HTTPS ports come from twelve: `443`, `8443`, `9440`, `9441`, `9442`, `9443`, `7777`, `8888`, `9553`, `9653`, `8035`, and `8090`. A new workload listens on `80` and `443`.

**Console**

To set the ports in Azion Console:

1. **Open the Workloads page**

   Access [Azion Console](https://console.azion.com/) > **Workloads**.

2. **Open the workload**

   Select the workload that serves the application. Its edit form opens.

3. **Select the HTTP ports**

   In the **Protocol Settings** section, select each port the workload listens on for HTTP in **HTTP Ports**.

4. **Select the HTTPS ports**

   With **HTTPS support** turned on, select each port the workload listens on for HTTPS in **HTTPS Ports**.

5. **Save the workload**

   Select **Save**.

Azion Console shows "Your workload has been updated", and the **Protocol Settings** section lists the ports you selected.

**CLI**

To set the ports with the Azion CLI, save a JSON file with the workload ID and the whole `protocols.http` object, here as `ports.json`. This example listens on `80` and `8080` for HTTP, and on `443` and `8443` for HTTPS:

```json
{
  "id": <workload-id>,
  "protocols": {
    "http": {
      "versions": ["http1", "http2"],
      "http_ports": [80, 8080],
      "https_ports": [443, 8443],
      "quic_ports": null
    }
  }
}
```

The `versions` list in this file leaves out HTTP/3. To keep HTTP/3, add `http3` to `versions` and an HTTP/3 port to `quic_ports`, as [Workload settings](/en/documentation/platform/workloads/settings/#protocols-and-ports) describes.

Update the workload with the file:

```bash
azion update workload --file ports.json
```

The command prints the ID of the workload it updated:

```text
Updated Workload with ID <workload-id>
```

To confirm the change, describe the workload:

```bash
azion describe workload --workload-id <workload-id> --format json
```

This excerpt of the output shows the ports in `protocols.http`:

```json
{
 "protocols": {
  "http": {
   "http_ports": [
    80,
    8080
   ],
   "https_ports": [
    443,
    8443
   ],
   "versions": [
    "http1",
    "http2"
   ]
  }
 },
 …
}
```

**API**

To set the ports with the API, send a `PATCH` request to the workload with the whole `protocols.http` object. This example listens on `80` and `8080` for HTTP, and on `443` and `8443` for HTTPS:

```bash
curl --request PATCH \
  --url https://api.azion.com/v4/workspace/workloads/<workload-id> \
  --header 'Accept: application/json' \
  --header 'Authorization: Token [TOKEN VALUE]' \
  --header 'Content-Type: application/json' \
  --data '{
  "protocols": {
    "http": {
      "versions": ["http1", "http2"],
      "http_ports": [80, 8080],
      "https_ports": [443, 8443],
      "quic_ports": null
    }
  }
}'
```

The API accepts the update, and the workload then lists the ports in `protocols.http`. The `versions` list in this request leaves out HTTP/3. To keep HTTP/3, add `http3` to `versions` and an HTTP/3 port to `quic_ports`, as [Workload settings](/en/documentation/platform/workloads/settings/#protocols-and-ports) describes.

Two refusals stop the change. An HTTP port outside the four values is refused with `Invalid choices for multiple choices field: [80, 8008, 8080, 8880].` A `versions` list that holds `http3` without `http1` and `http2` is refused with `Missing required choices for multiple choices field: ['http1', 'http2'].` For every refusal and its fix, refer to [Workload settings](/en/documentation/platform/workloads/settings/#errors).

A workload change takes several minutes to reach all of Azion's distributed infrastructure, and requests can receive the old or the new ports meanwhile. Repeat a request until the answers agree.

---

## Set the origin port on the connector

The origin port belongs to the connector that a rule of the application names, not to the workload. Each address of a connector carries two origin ports: `http_port`, `80` by default, and `https_port`, `443` by default. For an origin that listens on another port, set that port on the address when you create or edit the connector.

The connector's `transport_policy` decides whether Azion connects to the origin over HTTP or HTTPS. For example, `force_https` makes every connection to the origin use HTTPS, whatever protocol the user's request used. For each policy and the protocol it uses, refer to [Connector settings](/en/documentation/platform/connectors/settings/#connection-options).

When two delivery ports need different origin ports, create one connector per origin port. Then route each delivery port to its connector with a rule, as Route a custom port to its connector shows.

---

## Route a custom port to its connector

A rule on the application can send the requests of one delivery port to the connector of one origin port. The rule runs in the request phase. Its criterion compares `${server_port}`, the port of the server that receives the request, with the delivery port. Its behavior, **Set Connector**, names the connector. For the variables and the behavior, refer to [Rules Engine for Applications](/en/documentation/platform/applications/rules-engine/).

This example sends the requests that arrive on delivery port `8080` to a connector whose address uses the origin port you want.

**Console**

To create the rule in Azion Console:

1. **Open the application**

   Access [Azion Console](https://console.azion.com/) > **Applications**, and select the application in the workload's deployment.

2. **Select the Rules Engine tab**

3. **Select + Rule**

4. **Name the rule**

   In **General**, enter `route-port-8080` as the **Name**.

5. **Select the request phase**

   In **Phase**, select *Request Phase*.

6. **Set the criterion**

   Under **Criteria**, select the variable `${server_port}` and the operator `is_equal`, and enter `8080` as the argument.

7. **Select the Set Connector behavior**

   Under **Behaviors**, select **Set Connector**.

8. **Select the connector**

   In **Connector**, select the connector whose address uses the origin port for `8080`.

9. **Select Create**

The rule appears in the **Rules Engine** tab, under the **Request** heading.

**CLI**

To create the rule with the Azion CLI, keep the rule in a file: on a command line, the shell would expand `${server_port}`. Save this body as `rule.json`, and replace `<connector-id>` with the ID of the connector:

```json
{
  "name": "route-port-8080",
  "active": true,
  "criteria": [
    [
      {
        "variable": "${server_port}",
        "conditional": "if",
        "operator": "is_equal",
        "argument": "8080"
      }
    ]
  ],
  "behaviors": [
    {
      "type": "set_connector",
      "attributes": { "value": <connector-id> }
    }
  ]
}
```

Create the rule in the request phase of your application. Replace `<application-id>` with the ID of your application:

```bash
azion create rules-engine --application-id <application-id> --phase request --file rule.json
```

The command prints the ID of the rule it created:

```text
Created Rules Engine with ID <rule-id>
```

**API**

To create the rule with the API, keep the request body in a file: on a command line, the shell would expand `${server_port}`. Save this body as `rule.json`, and replace `<connector-id>` with the ID of the connector:

```json
{
  "name": "route-port-8080",
  "active": true,
  "criteria": [
    [
      {
        "variable": "${server_port}",
        "conditional": "if",
        "operator": "is_equal",
        "argument": "8080"
      }
    ]
  ],
  "behaviors": [
    {
      "type": "set_connector",
      "attributes": { "value": <connector-id> }
    }
  ]
}
```

Send a `POST` request to the request-phase rules of your application. Replace `<application-id>` with the ID of your application:

```bash
curl --request POST \
  --url https://api.azion.com/v4/workspace/applications/<application-id>/request_rules \
  --header 'Accept: application/json' \
  --header 'Authorization: Token [TOKEN VALUE]' \
  --header 'Content-Type: application/json' \
  --data @rule.json
```

The API answers `202`, with `state` set to `pending`, and the response carries the stored rule with its `id`.

Once the rule propagates, a request that arrives on delivery port `8080` reaches your origin on the port of the connector the rule names. For each other custom delivery port, create one more rule with that port as the argument and its own connector.

---

## Next steps

- [Workload settings](/en/documentation/platform/workloads/settings.md): Look up every port value, the HTTP/3 port, and the refusals of the protocols object.
- [Rules Engine for Applications](/en/documentation/platform/applications/rules-engine.md): Combine server\_port with other criteria, and reorder the rules of a phase.
- [Connectors](/en/documentation/platform/connectors.md): Set the addresses, the origin ports, and the protocol policy of a connector.
- [Set the TLS cipher suite](/en/documentation/guides/application-security/tls-and-certificates/ciphers.md): Choose the minimum TLS version and the cipher suite of the HTTPS ports.
