All Products
Search
Document Center

Cloud Firewall:Enable pay-as-you-go for Cloud Firewall

Last Updated:Sep 16, 2026

Cloud Firewall is a cloud-native firewall service from Alibaba Cloud that provides security features like traffic filtering, intrusion prevention, and threat detection. The pay-as-you-go version of Cloud Firewall bills you based on actual resource usage with no upfront commitment. You can enable or disable the service at any time for flexibility and control. This topic describes how to enable the pay-as-you-go version of Cloud Firewall.

Applicability

This topic applies only to users who have not enabled Cloud Firewall. If Cloud Firewall is already enabled for your account, see the following documents based on your business needs:

  • Change billing method: To switch from the subscription to the pay-as-you-go billing method, see Switch between subscription and pay-as-you-go.

  • Upgrade billing method: If you are using the legacy (1.0) billing method and want to upgrade to the new (2.0) pay-as-you-go model, see Upgrade your billing method from 1.0 to 2.0.

    Note

    Effective October 15, 2025 (UTC+8), Cloud Firewall will launch the pay-as-you-go 2.0 billing method. This method will be the default for all new users.

Enable the pay-as-you-go version

  1. Go to the Cloud Firewall purchase page and set Product Type to pay-as-you-go 2.0.

  2. On the Cloud Firewall (pay-as-you-go) page, configure the following parameters.

    Parameter

    Description

    Billing Method for Sale

    This parameter is set to pay-as-you-go 2.0 and cannot be changed.

    Auto-protect assets

    Select Yes to automatically protect all your public assets after the service is enabled. This helps reduce the exposure risk of your Internet-facing assets. You can change this setting later to enable or disable protection for specific assets as needed.

    Note

    Billing starts immediately after an asset is protected by Cloud Firewall.

    Firewall Log Analysis

    By default, Cloud Firewall provides a 7-day log audit feature for free. To meet longer log retention requirements or compliance standards, we recommend enabling the Log Analysis service.

    If you enable this service, you must also configure the Firewall Log Storage Capacity. The greater your service bandwidth, the more storage you will need. If you are unsure of your bandwidth needs, you can keep the default capacity and increase it later.

    Sizing guidance: For every 10 Mbps of service bandwidth, allocate 1 TB of log storage capacity for a 6-month retention requirement.

    Agentic NDR

    Agentic NDR is an advanced, value-added service for Cloud Firewall. Its log analysis storage is separate from the standard Cloud Firewall log storage. To enable the Agentic NDR log analysis service, you must configure both NDR Log Analysis and NDR Log Storage Capacity.

    Service-linked Role

    Cloud Firewall requires access to your cloud resources to provide services such as access control and performance monitoring. Click Create Service-linked Role to automatically create the AliyunServiceRoleForCloudFW role. Do not make any manual changes to this role.

  3. Read the Cloud Firewall Service Agreement, then click Create Now and complete the payment.

Get started

After you enable Cloud Firewall, follow these steps to configure and use the service:

  1. Confirm public asset protection status: Go to the Firewall > Internet Firewall page and verify that the status of your target public assets is Protected. For more information, see Internet Firewall.

  2. Check intrusion prevention (IPS) configuration: IPS protection is enabled by default. To adjust the settings, go to the Protect > IPS Configuration page. For more information, see IPS configuration.

  3. Configure access control (ACL) policies: Go to the Protect > Access Control > Policy Configuration page to set inbound and outbound traffic rules for each asset for fine-grained control. For more information, see Overview of access control policies.

  4. Audit traffic logs: After your assets are protected and begin to generate traffic, go to the Detection & Response > Log Audit page to view and analyze logs. If you have enabled Log Analysis, go to the Detection & Response > Log Analysis page to view complete logs. For more information, see Log audit and Overview of Log Analysis.

Cost optimization recommendations

In some business scenarios, the pay-as-you-go version of Cloud Firewall can be more expensive, partly due to billable items such as the instance fee.

Scenario assessment

  • Recommended scenarios: Short-term feature trials, testing and validation, personal learning, or scenarios with volatile service traffic.

  • Not recommended for: Long-term use, scenarios with stable total bandwidth, or scenarios with infrequent feature configuration changes.

Cost optimization measures
To control pay-as-you-go costs and avoid unexpected high fees, consider the following measures:

  • Purchase a subscription instance: A subscription-based Cloud Firewall instance is recommended for long-term workloads.

    Note

    Subscription-based Cloud Firewall instances enable elastic bandwidth by default. If your actual bandwidth exceeds the purchased specification, the excess traffic is billed on a pay-as-you-go basis.

  • Purchase a Savings Plan: If you plan to use the pay-as-you-go version long-term, purchasing a Savings Plan is recommended to reduce your pay-as-you-go costs through a prepaid model.

  • Manually release pay-as-you-go instances promptly: For scenarios such as functional evaluation, if you no longer need the service, go to the Overview page in the console. In the Version Information area, click More > Self-service Release to stop billing.

FAQ

How many instances to enable?

You need to enable only one Cloud Firewall instance per Alibaba Cloud account. This single instance can protect your cloud assets across multiple regions, both within and outside the Chinese mainland. After your assets are under protection, the instance fee is calculated based on factors such as the regions and number of your protected cloud assets.

Instance fee calculation

In the pay-as-you-go 2.0 billing method, the instance fee is calculated based on the following rules, which determine the number of required instances:

Instance fee calculation rules

The instance fee is charged based on the number of created Cloud Firewall instances, which covers various firewall boundaries. The unit price is USD 0.36 per instance per hour. The number of instances is determined as follows:

  • Internet firewall: One instance is required for each protected region. Within the same region, only one instance specification is consumed, regardless of the number of protected public IP addresses or whether the IP addresses are IPv4 or IPv6.

  • NAT firewall: One instance is required for each NAT Gateway instance.

  • VPC firewall:

    • In a Cloud Enterprise Network (CEN) Enterprise Edition architecture, one instance is required for each Transit Router (TR).

    • In a CEN Basic Edition architecture, one instance is required for each VPC.

    • In a VPC peering connection architecture, one instance is required for each pair of VPCs.

  • Multi-account Management: If you enable this feature, the assets of each member account consume a Cloud Firewall instance specification and incur a separate instance fee.

Relationship between the instance fee and number of assets

For the Internet Firewall, the instance fee depends on the number of regions in which your protected assets are located, not the total number of assets. All assets within a single region are covered by one firewall instance. The more regions your assets are distributed across, the higher the instance fee.

Why am I billed for an inactive pay-as-you-go instance?

Features such as Log Analysis, threat intelligence (IPS), and sensitive data leak detection are billed separately from the boundary firewalls.

To completely stop billing, log on to the Cloud Firewall console. In the upper-right corner of the Overview page, select More > Self-service Release. After you release the instance, the system generates a final bill the next day (T+1) that includes charges incurred before the release. No new bills are generated after that.

Why am I billed after releasing an instance?

You may receive a bill after releasing a pay-as-you-go instance for the following reasons:

  • Delayed billing: Pay-as-you-go instances are billed daily. After you release an instance, the system generates a bill on the next day (T+1). This bill includes charges incurred before the release. No new bills are generated after this.

  • Late instance release: If you do not manually release an instance after its free trial or savings plan expires, you will continue to be billed for the service at the standard rate.

  • Incorrect service termination: Disabling border firewall protection does not stop billing. To stop billing completely, Log on to the Cloud Firewall console. on the Overview page, in the upper-right corner, select More > Self-service Release.

Why am I charged after the free trial?

When you sign up for the Cloud Firewall free trial, the system activates the pay-as-you-go edition of Cloud Firewall and provides a Pay-as-you-go Savings Plan with a specific amount of credit. This credit is used to offset charges. After the credit in the savings plan is depleted, the system automatically charges for any excess usage based on the pay-as-you-go billing rules.

Log on to Billing & Cost Management. In the left-side navigation pane, choose Account > Savings Plan > Overview to view the remaining credit and usage of your Pay-as-you-go Savings Plan.

To avoid incurring charges, you must release the instance before the plan's credit is depleted. Log on to the Cloud Firewall console. In the upper-right corner of the Overview page, select More > Self-service Release.