All Products
Search
Document Center

Global Accelerator:Enable WAF protection for Global Accelerator

Last Updated:Jun 22, 2026

You can enable WAF protection for your Global Accelerator (GA) instance to defend against web application layer attacks such as SQL injection and cross-site scripting (XSS). WAF is integrated in bypass mode, separating security checks from traffic forwarding to minimize the impact on network latency.What is Web Application Firewall?

How it works

GA integrates WAF in bypass mode. After you enable this feature, a service-based WAF is deployed in the GA acceleration region. Rather than acting as a separate network node for traffic forwarding, WAF only extracts, inspects, and protects traffic to enhance application security.

image
  1. Request reception: A client request arrives at a GA acceleration node.

  2. Bypass inspection: GA sends the traffic to a WAF 3.0 instance over an internal channel for a security check.

  3. Security analysis: WAF analyzes the request in real time based on your configured protection rules and returns the inspection result (allow or block) to GA.

  4. Decision enforcement: GA enforces the decision based on the inspection result.

    • Allow: The request is forwarded to the origin server.

    • Block: The request is blocked, and a block page is returned to the client. The request does not reach the origin server.

Usage notes

  • The service-based WAF integration for GA is in phased release. To use this feature, contact your account manager.

  • Only pay-as-you-go GA instances support WAF protection.

  • If you have WAF 2.0 instances in your account, you must first release them or migrate to WAF 3.0.

Enable WAF protection

  • After enabling this feature, your GA instance is automatically connected to the WAF 3.0 service. If WAF is not activated for your account, a pay-as-you-go WAF 3.0 instance is automatically created.

  • Supported acceleration regions:

    • If the Accelerated IP Address Type of your instance is EIP, you can enable WAF protection for acceleration regions in the Chinese mainland and regions outside the Chinese mainland separately.

    • If the Accelerated IP Address Type is Anycast EIP, you can enable WAF protection only for acceleration regions outside the Chinese mainland. WAF protection is not currently supported in the UK (London) region.

  • After you enable WAF protection, it takes effect only if the instance meets the following conditions:

    • An HTTP or HTTPS listener is configured.

    • An acceleration region that supports WAF protection is configured.

Enable WAF when creating a GA instance

  1. On the page, in the Basic Instance Configuration section, expand the Web Application Firewall area and select Enable for the protection region.Create Standard Pay-as-you-go Instance

  2. Complete the instance creation. For more information, see Create a standard pay-as-you-go GA instance.

Enable WAF for an existing GA instance

  1. Log on to the and find the target pay-as-you-go instance.Global Accelerator console

  2. Hover over the 未开启 icon next to the target instance ID, and in the Web Application Firewall area, click Configure.

  3. In the Configure Web Application Firewall dialog box, select Enable for the protection region and click OK.

View protection logs

After you enable WAF protection, WAF automatically creates a protected object and enables the core web protection rules by default. You can configure more protection rules as needed.

Protected object naming convention

Acceleration region

Name suffix

Chinese mainland

-cn

Regions outside the Chinese mainland

-intl

  1. On the , find the target instance.Global Accelerator console

  2. Hover over the 未开启 icon next to the target instance ID. In the Web Application Firewall area, click View WAF Report for the corresponding protection region.

Disable WAF protection

After you disable WAF protection, traffic to your GA instance is no longer inspected by WAF. Security reports no longer include data for this traffic, and WAF stops charging request processing fees.

You are still charged for the WAF instance itself and any configured protection rules. To stop all WAF billing, you must disable WAF.
  1. On the , find the target instance.Global Accelerator console

  2. Hover over the 未开启 icon next to the instance ID, and in the Web Application Firewall area, click Configure.

  3. In the Configure Web Application Firewall dialog box, select Close for the corresponding protection region and click OK.

Billing

  • GA fees: Enabling WAF protection does not affect the billing for your GA instance. GA continues to be billed according to its original billing rules.

  • WAF 3.0 fees:

    • If you have not activated WAF, enabling WAF protection for GA automatically creates a WAF 3.0 pay-as-you-go instance.

    • If you already have a WAF 3.0 subscription instance, enabling WAF protection for GA does not incur additional WAF fees.

FAQ

Does WAF protection increase latency?

Data is transmitted between the GA instance and the WAF instance over a dedicated internal channel within the same region. The primary source of latency is the WAF security check, which typically adds 1 to 2 ms.

Why is WAF unavailable in some regions?

Supported regions:

Area

Region

Chinese mainland

China (Qingdao), China (Beijing), China (Ulanqab), China (Shenzhen), China (Guangzhou), China (Hangzhou), China (Shanghai), China (Chengdu)

Asia Pacific

China (Hong Kong), Singapore, Malaysia (Kuala Lumpur), Japan (Tokyo), Indonesia (Jakarta), Philippines (Manila), Thailand (Bangkok)

Europe & Americas

US (Silicon Valley), US (Virginia), Germany (Frankfurt)