All Products
Search
Document Center

Web Application Firewall:Announcement on changes to the billing and implementation of pay-as-you-go WAF instances

Last Updated:Mar 31, 2026

Alibaba Cloud is updating the billing rules for pay-as-you-go Web Application Firewall (WAF) instances. Changes take effect at 00:00:00 on December 10, 2024 (UTC+8).

What's changing

1. Empty instances are released

Pay-as-you-go WAF 2.0 and WAF 3.0 instances with no domain names or cloud service assets added are automatically released.

2. Feature renamed

Basic web protection is renamed core web protection.

3. Traffic billing threshold updated

The maximum threshold for traffic billing protection changes to:

  • Chinese mainland: 30,000 queries per second (QPS)

  • Outside the Chinese mainland: 3,000 QPS

To set a higher threshold, contact your account manager or solution architect.

4. Billable items updated

Two new billable items are added, and several existing items are repriced. See New billable items and Repriced billable items below.

Impact on your bills

Bills already generated are not affected. New billing rules apply to subsequent bills only.

New billable items

Billable itemDescriptionUnit price
WAF instanceCharged after you purchase a pay-as-you-go WAF instance0.5 security capacity unit (SeCU) per hour
Peak traffic throttlingSet a request percentage or QPS threshold for specific URLs or regions to trigger throttling. Use this for traffic surge scenarios such as promotions to protect origin server availability.150 SeCUs per rule-hour

Repriced billable items

Billable itemBeforeAfter
Core web protection - protection template1 SeCU per template-hour3 SeCUs per template-hour
Scan protection1 SeCU per rule-hour10 SeCUs per rule-hour
Peak QPS0 SeCUs/hour for peak QPS ≤ 5,000; 1 SeCU per 5 QPS per hour for the portion exceeding 5,000 QPS0 SeCUs/hour for peak QPS ≤ 1,000; 1 SeCU per 5 QPS per hour for the portion exceeding 1,000 QPS
Custom rule - basic1 SeCU per rule-hour2 SeCUs per rule-hour
Custom rule - advanced2 SeCUs per rule-hour5 SeCUs per rule-hour
Region blacklist3 SeCUs per rule-hour10 SeCUs per rule-hour
Bot management1 SeCU per 10,000 requests1 SeCU per 7,500 requests
API security1 SeCU per 10,000 requests1 SeCU per 7,500 requests
Domain names added in CNAME record mode0 SeCU for 1 domain name; 2 SeCUs per additional domain name-hour for each additional domain nameTiered: 0 SeCU for 1 domain name; 5 SeCUs per additional domain name-hour for 2–10 domain names; 3 SeCUs per additional domain name-hour for 11–100 domain names; 1 SeCU per additional domain name-hour for more than 100 domain names

Billing notes

Core web protection - protection template

Charges apply once you add protected objects to WAF. Protection templates are billed regardless of whether they are enabled.

Peak QPS

If the portion exceeding the default QPS limit is less than 5 QPS, it is calculated as 5 QPS.

Custom rule - advanced rule conditions

The conditions that classify a custom rule as an advanced rule change as follows.

Before December 10, 2024, a rule is an advanced rule if it meets any of these conditions:

  • Rule type is throttling

  • Match fields used: Body, Body Parameter

  • Logical operators used: regular expression match or regular expression mismatch

  • Advanced parameters configured: Canary Release, Effective Mode

From December 10, 2024, a rule is an advanced rule if it meets any of these conditions:

  • Rule type is throttling

  • Match fields used: Cookie, Content-Type, Content-Length, X-Forwarded-For, Body, Http-Method, File Extension, Filename, Server-Port, Header, Cookie Namet, Body Parameter

  • Logical operators used: regular expression match or regular expression mismatch

  • Advanced parameters configured: Canary Release, Effective Mode

Rules that do not meet any of the above conditions are basic rules.

Bot management and API security

If the number of requests within an hour is not a multiple of 7,500, it is rounded up to the nearest multiple of 7,500.