The pay-as-you-go edition of Cloud Firewall uses a post-paid billing method. You can pair it with a prepaid Pay-as-you-go Savings Plan to reduce costs.
Effective October 15, 2025, Cloud Firewall billable items have been upgraded to Billing 2.0. New purchases use Billing 2.0 by default. Existing users can continue with Billing 1.0 and can optionally upgrade to Billing 2.0.
This document describes Billing 2.0. If you are on Billing 1.0, see Billing 1.0 and upgrade instructions for information about Billing 1.0 billable items and how to upgrade to Billing 2.0.
How it works
Fees for the pay-as-you-go edition of Cloud Firewall consist of three parts: an instance fee, a traffic processing fee, and a feature fee. Fees are settled daily (UTC+8). After a settlement, a new billing cycle begins. On the following day, the system calculates the fees from the previous day and automatically deducts them from your account.
Billing cycle and rules
Minimum billing period: The minimum billing period is a clock hour.
Billing rule: You are billed for a full hour for any usage within a clock hour, even if the usage is less than one hour. If your usage spans multiple clock hours, you are billed for each of those hours.
Example: If you use the service from 15:55 to 16:05, the actual usage is only 10 minutes. However, because the usage spans two clock hours (15:00–16:00 and 16:00–17:00), you are billed for 2 hours.
Overdue payments and resource release policy
Overdue for more than 15 days: If your account has an insufficient balance and payments are overdue for more than 15 consecutive days, your pay-as-you-go instance is automatically released. Historical alert data and configurations are deleted.
No assets connected for more than 30 days: Under the Pay-as-you-go 2.0 billing method, if a Cloud Firewall instance has no connected assets and incurs no fees for 30 consecutive days, the instance is automatically released. Historical alert data and configurations are deleted.
Billable items
This topic describes only the pricing for the billable items of the pay-as-you-go edition of Cloud Firewall. For information about the differences in protection capabilities between Cloud Firewall editions, see Compare and select Cloud Firewall editions.
Instance fee
Billable item | Unit price | Description |
Instance fee | $0.36/instance/hour | This fee is based on the number of firewall instances created for each boundary type. The number of instances is calculated as follows:
|
Traffic processing fee
Billable item | Unit price | Description |
Traffic processing fee | $0.06/GB | This fee applies to the total traffic of the Internet Firewall, NAT Firewall, and VPC Firewall. The maximum supported peak bandwidth is 10 Gbps. To request a larger quota, contact your sales manager or architect. |
Sensitive data leak detection: Traffic fee | $0.026/GB | Used to detect sensitive data leaks in active outbound traffic. |
Feature fee
Billable item | Unit price | Description |
Access control policy quota | Free | The access control policy (ACL) feature allows you to configure up to 10,000 policies. For a larger quota, upgrade to the Enterprise subscription edition or higher, or contact your sales manager. |
Sensitive data leak detection: Feature fee | $0.43/hour | Used to detect sensitive data leaks in active outbound traffic. |
Synchronization node | Free | You can configure up to five ACK and five DNS synchronization nodes. |
IPS threat intelligence capability | $0.36/hour | The IPS threat intelligence capability syncs malicious IP addresses detected across the Alibaba Cloud network to your Cloud Firewall. You can enable this feature on demand. |
Log Analysis | $0.3/TB/hour | You are charged based on the selected Log Analysis storage capacity. The minimum capacity is 1 TB. |
Billing examples
Scenario | Hourly cost |
You activate the pay-as-you-go edition of Cloud Firewall. You do not enable other features or connect any assets for protection. | Free |
You activate the pay-as-you-go edition of Cloud Firewall and use one Internet Firewall instance to protect a group of IP assets in the same region. The total inbound and outbound traffic processed by the firewall is about 1 GB per hour. | 1 × $0.36 + 1 GB × $0.06/GB = $0.42 |
View billing details
The pay-as-you-go edition of Cloud Firewall is billed hourly. Fees from the previous day are calculated and settled on the current day. You can view the details of your pay-as-you-go bills to understand your charges. For more information, see Bill Management.
Cost optimization recommendations
In some business scenarios, the pay-as-you-go version of Cloud Firewall can be more expensive, partly due to billable items such as the instance fee.
Scenario assessment
Recommended scenarios: Short-term feature trials, testing and validation, personal learning, or scenarios with volatile service traffic.
Not recommended for: Long-term use, scenarios with stable total bandwidth, or scenarios with infrequent feature configuration changes.
Cost optimization measures
To control pay-as-you-go costs and avoid unexpected high fees, consider the following measures:
Purchase a subscription instance: A subscription-based Cloud Firewall instance is recommended for long-term workloads.
NoteSubscription-based Cloud Firewall instances enable elastic bandwidth by default. If your actual bandwidth exceeds the purchased specification, the excess traffic is billed on a pay-as-you-go basis.
Purchase a Savings Plan: If you plan to use the pay-as-you-go version long-term, purchasing a Savings Plan is recommended to reduce your pay-as-you-go costs through a prepaid model.
Manually release pay-as-you-go instances promptly: For scenarios such as functional evaluation, if you no longer need the service, go to the Overview page in the console. In the Version Information area, click More > Self-service Release to stop billing.
FAQ
Why am I billed for an inactive pay-as-you-go instance?
Features such as Log Analysis, threat intelligence (IPS), and sensitive data leak detection are billed separately from the boundary firewalls.
To completely stop billing, log on to the Cloud Firewall console. In the upper-right corner of the Overview page, select . After you release the instance, the system generates a final bill the next day (T+1) that includes charges incurred before the release. No new bills are generated after that.
Why am I billed after releasing an instance?
You may receive a bill after releasing a pay-as-you-go instance for the following reasons:
Delayed billing: Pay-as-you-go instances are billed daily. After you release an instance, the system generates a bill on the next day (T+1). This bill includes charges incurred before the release. No new bills are generated after this.
Late instance release: If you do not manually release an instance after its free trial or savings plan expires, you will continue to be billed for the service at the standard rate.
Incorrect service termination: Disabling border firewall protection does not stop billing. To stop billing completely, Log on to the Cloud Firewall console. on the Overview page, in the upper-right corner, select .
Why am I charged after the free trial?
When you sign up for the Cloud Firewall free trial, the system activates the pay-as-you-go edition of Cloud Firewall and provides a Pay-as-you-go Savings Plan with a specific amount of credit. This credit is used to offset charges. After the credit in the savings plan is depleted, the system automatically charges for any excess usage based on the pay-as-you-go billing rules.
Log on to Billing & Cost Management. In the left-side navigation pane, choose Account > Savings Plan > Overview to view the remaining credit and usage of your Pay-as-you-go Savings Plan.
To avoid incurring charges, you must release the instance before the plan's credit is depleted. Log on to the Cloud Firewall console. In the upper-right corner of the Overview page, select .
Traffic fees: Pay-as-you-go vs. subscription
The cost-effectiveness of each billing method depends on your traffic volume and usage period. Consider the following scenarios:
Subscription edition: This method is best for services with high, stable traffic over a long period. You pay upfront to reserve resources, which results in a lower per-unit traffic cost and a lower overall cost.
Pay-as-you-go edition: This method is best for services with low or fluctuating traffic, or for services in a testing phase. You are billed only for the traffic you use, which prevents paying for idle resources. You can also combine this method with a Pay-as-you-go Savings Plan. These plans offer a discount in exchange for a spending commitment over a specific period, providing both flexibility and cost optimization.
Recommendation: For stable, long-term production environments, choose the subscription edition to save costs. For short-term testing or for scenarios with unpredictable traffic, choose the pay-as-you-go edition and combine it with a Pay-as-you-go Savings Plan to further reduce costs.
Whitelist for billing exemption
No.