Alibaba Cloud is updating the billing rules for pay-as-you-go Web Application Firewall (WAF) instances. Changes take effect at 00:00:00 on December 10, 2024 (UTC+8).
What's changing
1. Empty instances are released
Pay-as-you-go WAF 2.0 and WAF 3.0 instances with no domain names or cloud service assets added are automatically released.
2. Feature renamed
Basic web protection is renamed core web protection.
3. Traffic billing threshold updated
The maximum threshold for traffic billing protection changes to:
Chinese mainland: 30,000 queries per second (QPS)
Outside the Chinese mainland: 3,000 QPS
To set a higher threshold, contact your account manager or solution architect.
4. Billable items updated
Two new billable items are added, and several existing items are repriced. See New billable items and Repriced billable items below.
Impact on your bills
Bills already generated are not affected. New billing rules apply to subsequent bills only.
New billable items
| Billable item | Description | Unit price |
|---|---|---|
| WAF instance | Charged after you purchase a pay-as-you-go WAF instance | 0.5 security capacity unit (SeCU) per hour |
| Peak traffic throttling | Set a request percentage or QPS threshold for specific URLs or regions to trigger throttling. Use this for traffic surge scenarios such as promotions to protect origin server availability. | 150 SeCUs per rule-hour |
Repriced billable items
| Billable item | Before | After |
|---|---|---|
| Core web protection - protection template | 1 SeCU per template-hour | 3 SeCUs per template-hour |
| Scan protection | 1 SeCU per rule-hour | 10 SeCUs per rule-hour |
| Peak QPS | 0 SeCUs/hour for peak QPS ≤ 5,000; 1 SeCU per 5 QPS per hour for the portion exceeding 5,000 QPS | 0 SeCUs/hour for peak QPS ≤ 1,000; 1 SeCU per 5 QPS per hour for the portion exceeding 1,000 QPS |
| Custom rule - basic | 1 SeCU per rule-hour | 2 SeCUs per rule-hour |
| Custom rule - advanced | 2 SeCUs per rule-hour | 5 SeCUs per rule-hour |
| Region blacklist | 3 SeCUs per rule-hour | 10 SeCUs per rule-hour |
| Bot management | 1 SeCU per 10,000 requests | 1 SeCU per 7,500 requests |
| API security | 1 SeCU per 10,000 requests | 1 SeCU per 7,500 requests |
| Domain names added in CNAME record mode | 0 SeCU for 1 domain name; 2 SeCUs per additional domain name-hour for each additional domain name | Tiered: 0 SeCU for 1 domain name; 5 SeCUs per additional domain name-hour for 2–10 domain names; 3 SeCUs per additional domain name-hour for 11–100 domain names; 1 SeCU per additional domain name-hour for more than 100 domain names |
Billing notes
Core web protection - protection template
Charges apply once you add protected objects to WAF. Protection templates are billed regardless of whether they are enabled.
Peak QPS
If the portion exceeding the default QPS limit is less than 5 QPS, it is calculated as 5 QPS.
Custom rule - advanced rule conditions
The conditions that classify a custom rule as an advanced rule change as follows.
Before December 10, 2024, a rule is an advanced rule if it meets any of these conditions:
Rule type is throttling
Match fields used: Body, Body Parameter
Logical operators used: regular expression match or regular expression mismatch
Advanced parameters configured: Canary Release, Effective Mode
From December 10, 2024, a rule is an advanced rule if it meets any of these conditions:
Rule type is throttling
Match fields used: Cookie, Content-Type, Content-Length, X-Forwarded-For, Body, Http-Method, File Extension, Filename, Server-Port, Header, Cookie Namet, Body Parameter
Logical operators used: regular expression match or regular expression mismatch
Advanced parameters configured: Canary Release, Effective Mode
Rules that do not meet any of the above conditions are basic rules.
Bot management and API security
If the number of requests within an hour is not a multiple of 7,500, it is rounded up to the nearest multiple of 7,500.