All Products
Search
Document Center

Web Application Firewall:Extra bandwidth package

Last Updated:Aug 06, 2026

Web Application Firewall (WAF) 2.0 provides extra bandwidth packages that you can purchase to increase the clean bandwidth of your WAF instance. WAF 2.0 includes a default clean bandwidth. Estimate the service traffic of the websites you want to add to WAF, then select a WAF edition and extra bandwidth package accordingly. This topic describes clean bandwidth, how to estimate and view it, and what happens when it is exceeded.

Clean bandwidth

Clean bandwidth is the peak traffic bandwidth that a WAF 2.0 instance can process, measured in Mbit/s. For example, a clean bandwidth of 100 Mbit/s supports approximately 4,000 queries per second (QPS).

If you add multiple websites to a WAF 2.0 instance, make sure that the total peak traffic of all websites does not exceed the clean bandwidth of the instance. Otherwise, website access may be affected. For more information, see Impacts when clean bandwidth is exceeded.

The actual clean bandwidth of a WAF 2.0 instance equals the default clean bandwidth plus any extra bandwidth you purchase.

The following table lists the default clean bandwidth and peak QPS for each WAF edition.

WAF 2.0 edition

Default clean bandwidth (origin server on Alibaba Cloud, such as ECS or SLB)

Default clean bandwidth (origin server outside Alibaba Cloud, such as third-party cloud or on-premises servers)

Peak QPS

Pro

50 Mbit/s

10 Mbit/s

2,000 QPS

Business

100 Mbit/s

30 Mbit/s

5,000 QPS

Enterprise

200 Mbit/s

50 Mbit/s

10,000 QPS

If the default clean bandwidth does not meet your website protection needs, you can purchase extra bandwidth packages to increase it. For more information, see Purchase an extra bandwidth package.

Estimate the required clean bandwidth

The clean bandwidth of a WAF 2.0 instance must exceed the total service traffic of the websites you want to add to WAF.

Note

You can estimate service traffic from the monitoring data of your Elastic Compute Service (ECS) instances or from monitoring tools installed on your origin servers. In most cases, the service traffic of a website equals the higher of its inbound and outbound peak traffic. For more information, see View instance monitoring data.

If a website is hosted on multiple ECS instances, estimate the total peak traffic across all instances. For example, if you want to add three websites with origin servers on Alibaba Cloud to WAF, and each website has an outbound peak traffic of approximately 30 Mbit/s, the total peak traffic is approximately 90 Mbit/s. In this case, you can purchase a WAF 2.0 Business edition instance, which provides a default clean bandwidth of 100 Mbit/s. If you purchase a Pro edition instance with a default clean bandwidth of only 50 Mbit/s, you must also purchase extra bandwidth packages.

Impacts when clean bandwidth is exceeded

If the service traffic of a website added to WAF exceeds the clean bandwidth of the WAF 2.0 instance, WAF deprioritizes network and compute resource allocation for the excess traffic. WAF also triggers additional measures such as throttling and random packet dropping. As a result, the website may become slow or even unavailable, and the service-level agreement (SLA) of WAF no longer applies.

In this case, you can upgrade the WAF edition or purchase extra bandwidth packages to increase the clean bandwidth. For more information, see Purchase an extra bandwidth package.

Check whether clean bandwidth is exceeded

If the clean bandwidth of your WAF 2.0 instance is exceeded, a prompt appears at the top of the Web Application Firewall console console. After you log on to the console, check the top of the Overview page. If your bandwidth or QPS exceeds the purchased specifications, an orange alert banner appears. The banner states that your bandwidth or QPS exceeded the purchased specifications in the past 30 days. Prolonged excess automatically throttles your services and affects normal access. We recommend that you upgrade your bandwidth or QPS specifications by using an extra bandwidth package or upgrading your edition at the earliest opportunity. You can click Upgrade Now to upgrade, or click View Details to view the excess details.

To resolve this error, perform the following steps:

  • Click View Details to view Details.

  • Click Upgrade Now to go to the Upgrade/Downgrade page, where you can upgrade the WAF edition or purchase extra bandwidth packages.

    Note

    The actual clean bandwidth of a WAF instance is independent of the bandwidth or traffic limits of other Alibaba Cloud services, such as Alibaba Cloud CDN, Server Load Balancer (SLB), and ECS.

Purchase an extra bandwidth package

You can upgrade a WAF 2.0 instance to add an extra bandwidth package. For more information, see Upgrade a WAF instance.

You can configure the extra bandwidth package to increase or decrease clean bandwidth in increments of 50 Mbit/s. You can specify a value from 0 to 5,000 Mbit/s.