All Products
Search
Document Center

Web Application Firewall:Editions

Last Updated:Mar 31, 2026

WAF 3.0 comes in five editions. Use this page to compare their capabilities and choose the one that fits your traffic volume, deployment model, and security requirements.

Note

This page covers features only. For pricing, see Subscription billing details and Pay-as-you-go billing details.

Choose an edition

EditionBest forQPS limit
BasicSmall websites and development environments with predictable, low traffic10 QPS
ProGrowing small-to-medium businesses with moderate traffic2,000 QPS
EnterpriseLarge organizations needing hybrid cloud support, compliance features, and multi-account management5,000 QPS
UltimateMission-critical applications requiring maximum scale, dedicated support, and premium threat intelligence10,000 QPS
Pay-as-you-goVariable or unpredictable workloads, testing environments, or high-volume needs without long-term commitments30,000 QPS (Chinese mainland)

Performance and capacity

WAF 3.0 measures throughput in Queries Per Second (QPS) rather than bandwidth, which gives more predictable performance for modern applications. Size your edition based on peak request volume — including API calls, page loads, and AJAX requests.

Domain limits apply per unique hostname or wildcard pattern. For example, example.com, api.example.com, and *.cdn.example.com each consume one domain slot.

FeatureBasicProEnterpriseUltimatePay-as-you-go
QPS limit102,0005,00010,000Chinese mainland: 30,000; Outside the Chinese mainland: 3,000
Additional purchasable QPSChinese mainland: 30,000; Outside the Chinese mainland: 5,000Chinese mainland: 30,000; Outside the Chinese mainland: 5,000Chinese mainland: 30,000; Outside the Chinese mainland: 1,000
Additional purchasable burstable QPS (pay-as-you-go)Chinese mainland: 60,000; Outside the Chinese mainland: 1,000Chinese mainland: 60,000; Outside the Chinese mainland: 1,000Chinese mainland: 60,000; Outside the Chinese mainland: 1,000
Max domain names3510501,000
Additional purchasable domains105002,0005,000
Hybrid cloud protection nodes11
Complimentary domains for hybrid cloud nodes1 node: 100 free domains; 2+ nodes: 200 free domains1 node: 100 free domains; 2+ nodes: 200 free domains
Protected objects (cloud service instances and domains)3006002,50010,00010,000
Protected object groups10101010100
Protected objects per group50505050100
Multi-account management5 accounts20 accounts (customizable)

Deployment and integration

Important

When you add ECS, SLB, and NLB instances in cloud-native mode, make sure that traffic redirection ports do not exceed your protected objects limit.

FeatureBasicProEnterpriseUltimatePay-as-you-go
Cloud-native modeSupportedSupportedSupportedSupportedSupported
CNAME accessSupportedSupportedSupportedSupportedSupported
Hybrid cloudSupportedSupported
CNAME access to non-standard portsSupportedSupportedPaid add-on
IPv6 via CNAME accessChinese mainland: Supported; Outside the Chinese mainland: —Chinese mainland: Supported; Outside the Chinese mainland: —Chinese mainland: Paid add-on; Outside the Chinese mainland: —
Dedicated IP address for domains added via proxy modePaid add-onPaid add-onPaid add-onPaid add-on
Intelligent load balancing via CNAME accessPaid add-onPaid add-onPaid add-onPaid add-on
Max upload file size configuration (default: 2 GB)Supported

Core security features

Important
FeatureBasicProEnterpriseUltimatePay-as-you-go
Default rule group for web core protectionSupportedSupportedSupportedSupportedSupported
Custom rule groups for web core protection103030
Custom protection templates for web core protection310205020
Whitelist templates2020205050
Rules per whitelist template100100100100100
IP blacklist templates5102020
IPs and rules per IP blacklist template400 IPs, 2 rules600 IPs, 3 rules1,000 IPs, 5 rules1,000 IPs, 5 rules
Custom rule templates10205050
Rules per custom rule template100200200200
Match fields for custom rulesIP, URLIP, URL, all headers, regex, bodyIP, URL, all headers, regex, bodyIP, URL, all headers, regex, body
IP addresses per custom rule100100100100
Actions for custom rulesJavaScript validationJS challenge, slider CAPTCHA verificationJS challenge, slider CAPTCHA verificationJS challenge, slider CAPTCHA verification
Rate limiting in custom rulesSupportedSupportedSupported
Webpage tamper-proofing templates10205050
Rules per webpage tamper-proofing template50505050
Data leakage prevention templates10202020
Rules per data leakage prevention template50505050
Geo-blocking templates102020
HTTP flood protection templates5102020
Scanning protection templates5102020
Custom response templates205050
Max protected objects and groups per protection template10100200500100
DDoS basic protection and blackhole filteringSupportedSupportedSupportedSupportedSupported

Enhanced threat detection and intelligence

FeatureBasicProEnterpriseUltimatePay-as-you-go
Bot managementPaid add-on (up to 20 templates)Paid add-on (up to 50 templates)Paid add-on (up to 100 templates)Paid add-on
Critical event protectionAvailable by temporarily upgradingAvailable by temporarily upgradingIncludedPaid add-on
API securityPaid add-onPaid add-onPaid add-onPaid add-on
Peak traffic throttlingPaid add-onPaid add-onPaid add-onPaid add-on
Threat intelligenceSupportedSupportedPaid add-on
IP address book capacity3,000 IPs10,000 IPs50,000 IPs (customizable)3,000 IPs

O&M and monitoring

FeatureBasicProEnterpriseUltimatePay-as-you-go
Asset centerSupportedSupportedSupportedSupported
Alert settingsSupportedSupportedSupportedSupportedSupported
Simple Log ServicePaid add-onPaid add-onPaid add-onSupported
Rule library managementSupportedSupported