All Products
Search
Document Center

Web Application Firewall:WAF overview

Last Updated:Sep 15, 2026

Web Application Firewall (WAF) filters incoming traffic to your websites and applications, blocking common web attacks while forwarding legitimate requests to your servers. WAF ensures smooth website operation and safeguards business stability and data security.

Scenarios

WAF protects your websites and applications by detecting and blocking malicious service traffic. WAF inspects and filters all incoming traffic, forwarding only legitimate requests to the origin server. This process prevents issues, such as performance degradation caused by malicious intrusions, and ensures the security of your services and data.

Get started with WAF

How to use WAF

To get started, try Protect an ECS instance against CC attacks using WAF.

WAF 3.0 vs WAF 2.0

  • Version relationship: WAF 3.0 is the next-generation WAF built on WAF 2.0 with a new architecture, updated pricing, redesigned console, and improved experience. You cannot run both versions in the same Alibaba Cloud account.

  • Purchase policy: WAF 2.0 is no longer available for new purchases. Existing WAF 2.0 users can continue using, renewing, or upgrading their instances. Your SLA remains valid.

  • Upgrade method: To access enhanced features and an improved experience, upgrade from WAF 2.0 to WAF 3.0. Use the self-service migration tool to automatically migrate your WAF 2.0 instances to WAF 3.0. For steps, see How to upgrade a WAF 2.0 instance to WAF 3.0.

Main differences between WAF 3.0 and WAF 2.0

Billing method

Difference

WAF 3.0

WAF 2.0

Subscription instance editions

Basic Edition, Pro Edition, Enterprise Edition, Ultimate Edition.

Pro Edition, Enterprise Edition, Ultimate Edition.

Billing items

Traffic specification

Uses queries per second (QPS) as the sole traffic metric. No bandwidth management needed. Subscription instances support elastic pay-as-you-go QPS to prevent sandboxing from overuse.

Supports both QPS and bandwidth. You must convert between them.

Domain name specification

No distinction between primary domains and subdomains. Billed per domain name.

Distinguishes between primary domain names and subdomains.

Hybrid cloud access

Included in Enterprise Edition and Ultimate Edition.

Requires separate Hybrid Cloud WAF Exclusive purchase.

Pay-as-you-go billing unit

Unified billing unit: Security Capacity Unit (SeCU). Each SeCU costs USD 0.01.

There is no standard billing unit.

Asset onboarding and mitigation settings

Difference

WAF 3.0

WAF 2.0

Cloud native mode

  • Integrate with ALB, FC, MSE instances through an embedded SDK that handles traffic extraction, detection, and protection. WAF does not forward traffic.

  • Use transparent proxy mode to integrate with ECS, CLB, and NLB instances.

Transparent proxy mode supports ALB, ECS, and CLB only.

Protected objects for mitigation rules

WAF automatically creates a protected object when you add a domain name or cloud service instance. Configure mitigation rules in a template and assign protected objects to it.

Configure mitigation rules per domain name. In transparent proxy mode, add all domains of a cloud service instance to WAF before configuring custom rules. Otherwise, only default rules apply.

View mitigation rules

  • View rules by protected object or object group.

  • View rules by mitigation module.

  • Retrieve a mitigation rule by its ID.

View rules for a single domain name only.

Supported mitigation modules

New features include Custom Response, Threat Intelligence, Whitelist, Domain asset center, and Security Report. All supported modules are listed in Mitigation Settings Overview.

For a full list of supported mitigation modules, see Overview.