Web Application Firewall (WAF) filters incoming traffic to your websites and applications, blocking common web attacks while forwarding legitimate requests to your servers. WAF ensures smooth website operation and safeguards business stability and data security.
Scenarios
WAF protects your websites and applications by detecting and blocking malicious service traffic. WAF inspects and filters all incoming traffic, forwarding only legitimate requests to the origin server. This process prevents issues, such as performance degradation caused by malicious intrusions, and ensures the security of your services and data.
Get started with WAF

To get started, try Protect an ECS instance against CC attacks using WAF.
WAF 3.0 vs WAF 2.0
Version relationship: WAF 3.0 is the next-generation WAF built on WAF 2.0 with a new architecture, updated pricing, redesigned console, and improved experience. You cannot run both versions in the same Alibaba Cloud account.
Purchase policy: WAF 2.0 is no longer available for new purchases. Existing WAF 2.0 users can continue using, renewing, or upgrading their instances. Your SLA remains valid.
Upgrade method: To access enhanced features and an improved experience, upgrade from WAF 2.0 to WAF 3.0. Use the self-service migration tool to automatically migrate your WAF 2.0 instances to WAF 3.0. For steps, see How to upgrade a WAF 2.0 instance to WAF 3.0.
Main differences between WAF 3.0 and WAF 2.0
Billing method
Difference | WAF 3.0 | WAF 2.0 | |
Subscription instance editions | Basic Edition, Pro Edition, Enterprise Edition, Ultimate Edition. | Pro Edition, Enterprise Edition, Ultimate Edition. | |
Billing items | Traffic specification | Uses queries per second (QPS) as the sole traffic metric. No bandwidth management needed. Subscription instances support elastic pay-as-you-go QPS to prevent sandboxing from overuse. | Supports both QPS and bandwidth. You must convert between them. |
Domain name specification | No distinction between primary domains and subdomains. Billed per domain name. | Distinguishes between primary domain names and subdomains. | |
Hybrid cloud access | Included in Enterprise Edition and Ultimate Edition. | Requires separate Hybrid Cloud WAF Exclusive purchase. | |
Pay-as-you-go billing unit | Unified billing unit: Security Capacity Unit (SeCU). Each SeCU costs USD 0.01. | There is no standard billing unit. | |
Asset onboarding and mitigation settings
Difference | WAF 3.0 | WAF 2.0 |
Cloud native mode |
| Transparent proxy mode supports ALB, ECS, and CLB only. |
Protected objects for mitigation rules | WAF automatically creates a protected object when you add a domain name or cloud service instance. Configure mitigation rules in a template and assign protected objects to it. | Configure mitigation rules per domain name. In transparent proxy mode, add all domains of a cloud service instance to WAF before configuring custom rules. Otherwise, only default rules apply. |
View mitigation rules |
| View rules for a single domain name only. |
Supported mitigation modules | New features include Custom Response, Threat Intelligence, Whitelist, Domain asset center, and Security Report. All supported modules are listed in Mitigation Settings Overview. | For a full list of supported mitigation modules, see Overview. |