Web Application Firewall (WAF) protects against web attacks such as SQL injection, cross-site scripting, CC attacks, and malicious bots. This topic describes how to purchase a WAF 3.0 subscription instance based on your business needs.
If your account has a WAF 2.0 instance activated and you need to use a WAF 3.0 instance, perform operations based on your scenario:
Your WAF 2.0 instance has running services: Use the migration tool to upgrade a WAF 2.0 instance to WAF 3.0.
Your WAF 2.0 instance has no running services: Release the WAF 2.0 instance and then perform the purchase operations described in this topic.
Select an edition
Subscription WAF 3.0 is available in four editions: Basic, Pro, Enterprise, and Ultimate. Select an edition based on your business scenario and security requirements. For a detailed edition comparison, see Edition comparison.
Edition | Basic | Pro | Enterprise | Ultimate | |
Scenarios | Small or personal websites with no special security requirements. | Small and medium-sized websites with no special security requirements. | Medium-sized enterprise websites, or services that are open to the public with high security standards. | Medium to large enterprise websites with large-scale services, or that require customized security configurations. | |
Included features | Peak QPS | 10 QPS | 2,000 QPS | 5,000 QPS | 10,000 QPS |
Number of domain names | 3 | 5 | 10 | 50 | |
Supported ports | Standard ports: 80, 8080, 443, and 8443 | Standard ports: 80, 8080, 443, and 8443 | Standard and non-standard ports | Standard and non-standard ports | |
Hybrid cloud nodes | 1 | 1 | |||
Protection for critical events | Available as a paid add-on | Available as a paid add-on | |||
Paid add-on features | Advanced security features such as Log Service, exclusive IP addresses, bot management, and API security | ||||
Domain extension | Up to 10 | Up to 500 | Up to 2,000 | Up to 5,000 | |
Additional QPS (prepaid) | |||||
Elastic QPS (pay-as-you-go) | |||||
Purchase a WAF instance
Go to the Web Application Firewall 3.0 (Subscription) purchase page.
Set Billing Method to Subscription, and then configure the following parameters.
Purchase a Basic instance
Parameter
Description
Version
Select the edition based on your edition selection in the previous step.
Region
Specifies the location of WAF protection nodes, which affects access latency and data compliance.
If your web server is deployed in the Chinese mainland, select Chinese Mainland. Otherwise, select Outside Chinese Mainland.
Elastic QPS
This feature is enabled by default and cannot be disabled. When your business traffic peak exceeds the purchased QPS quota, the excess is billed on a pay-as-you-go basis based on usage. This helps you handle sudden traffic surges caused by attacks or promotional events.
Additional Domains
If the number of domain names that you need to protect exceeds the quota provided by the selected edition, you can purchase additional domain extensions.
Service-Linked Role
To provide services such as traffic access control and monitoring and analytics, WAF requires access to your cloud resources. Click Create Service-Linked Role. The system automatically creates the service-linked role AliyunServiceRoleForWaf. You do not need to manually modify this role.
Duration
Specify the subscription duration for the WAF 3.0 instance and whether to enable Auto-Renewal.
NoteTo conduct a proof of concept (POC) test, submit a request to your account manager and set Duration to 7-day POC.
Purchase a Pro instance
Parameter
Description
Version
Select the edition based on your edition selection in the previous step.
Region
Specifies the location of WAF protection nodes, which affects access latency and data compliance.
If your web server is deployed in the Chinese mainland, select Chinese Mainland. Otherwise, select Outside Chinese Mainland.
API Security
We recommend that you enable this module if your services involve a large number of API calls and you need to protect against sensitive data leaks or malicious attacks.
Bot Management - Web Protection
We recommend that you enable this module to protect your website against malicious bot traffic, such as data scraping, spam registration, business fraud, or cheating. This module applies to webpages and H5 pages that are accessed through browsers, including H5 pages used in apps.
Bot Management - App Protection
We recommend that you enable this module to protect your services against malicious bot traffic, such as data scraping, spam registration, business fraud, or cheating. This module applies to native apps developed for iOS or Android, but excludes H5 pages used in apps.
Risk Identification
If you have enabled the bot management module, you can enable this feature. It uses the built-in mobile number reputation database of WAF to prevent spam account registration and marketing fraud.
Peak Traffic Throttling
If you have promotional events, you can enable this feature to allow only a fixed QPS or a specific ratio of traffic to reach your backend servers, which ensures business stability.
Additional QPS
If the peak QPS of traffic that you need to protect exceeds the quota provided by the selected edition, you can purchase additional QPS.
Elastic QPS
This feature is enabled by default and cannot be disabled. When your business traffic peak exceeds the purchased QPS quota, the excess is billed on a pay-as-you-go basis based on usage. This helps you handle sudden traffic surges caused by attacks or promotional events.
Additional Domains
If the number of domain names that you need to protect exceeds the quota provided by the selected edition, you can purchase additional domain extensions.
Exclusive IP
In CNAME access mode, domain names of the same WAF instance share an IP address by default. If any domain name is targeted by a large-volume DDoS attack, the IP address enters blackhole filtering and access to all domain names is interrupted. You can configure an exclusive IP address for critical domain names to avoid business availability impacts caused by blackhole events.
Intelligent Load Balancing
This applies to scenarios where your business requires high availability with automatic disaster recovery and low-latency access in CNAME access mode.
Log Service
This applies to scenarios where you need to meet security compliance requirements (such as classified protection) or perform in-depth security analysis.
Log Storage Capacity
Select the maximum log storage capacity for the Log Service (starting from 3 TB). Unit: TB.
We recommend that you purchase an appropriate log storage capacity based on your business requirements. If the capacity reaches the upper limit, WAF no longer writes logs.
Service-Linked Role
To provide services such as traffic access control and monitoring and analytics, WAF requires access to your cloud resources. Click Create Service-Linked Role. The system automatically creates the service-linked role AliyunServiceRoleForWaf. You do not need to manually modify this role.
Duration
Specify the subscription duration for the WAF 3.0 instance and whether to enable Auto-Renewal.
NoteTo conduct a proof of concept (POC) test, submit a request to your account manager and set Duration to 7-day POC.
Purchase an Enterprise or Ultimate instance
Parameter
Description
Version
Select the edition based on your edition selection in the previous step.
Region
Specifies the location of WAF protection nodes, which affects access latency and data compliance.
If your web server is deployed in the Chinese mainland, select Chinese Mainland. Otherwise, select Outside Chinese Mainland.
API Security
We recommend that you enable this module if your services involve a large number of API calls and you need to protect against sensitive data leaks or malicious attacks.
Bot Management - Web Protection
We recommend that you enable this module to protect your website against malicious bot traffic, such as data scraping, spam registration, business fraud, or cheating. This module applies to webpages and H5 pages that are accessed through browsers, including H5 pages used in apps.
Bot Management - App Protection
We recommend that you enable this module to protect your services against malicious bot traffic, such as data scraping, spam registration, business fraud, or cheating. This module applies to native apps developed for iOS or Android, but excludes H5 pages used in apps.
Extension Plugins
You can write custom Lua scripts to intervene in the web request processing pipeline, to implement personalized security logic and complex business customization beyond the native rules of WAF.
Risk Identification
If you have enabled the bot management module, you can enable this feature. It uses the built-in mobile number reputation database of WAF to prevent spam account registration and marketing fraud.
Peak Traffic Throttling
If you have promotional events, you can enable this feature to allow only a fixed QPS or a specific ratio of traffic to reach your backend servers, which ensures business stability.
Additional QPS
If the peak QPS of traffic that you need to protect exceeds the quota provided by the selected edition, you can purchase additional QPS.
Elastic QPS
This feature is enabled by default and cannot be disabled. When your business traffic peak exceeds the purchased QPS quota, the excess is billed on a pay-as-you-go basis based on usage. This helps you handle sudden traffic surges caused by attacks or promotional events.
Additional Domains
If the number of domain names that you need to protect exceeds the quota provided by the selected edition, you can purchase additional domain extensions.
Exclusive IP
In CNAME access mode, domain names of the same WAF instance share an IP address by default. If any domain name is targeted by a large-volume DDoS attack, the IP address enters blackhole filtering and access to all domain names is interrupted. You can configure an exclusive IP address for critical domain names to avoid business availability impacts caused by blackhole events.
Intelligent Load Balancing
This applies to scenarios where your business requires high availability with automatic disaster recovery and low-latency access in CNAME access mode.
Log Service
This applies to scenarios where you need to meet security compliance requirements (such as classified protection) or perform in-depth security analysis.
Log Storage Capacity
Select the maximum log storage capacity for the Log Service (starting from 3 TB). Unit: TB.
We recommend that you purchase an appropriate log storage capacity based on your business requirements. If the capacity reaches the upper limit, WAF no longer writes logs.
Additional Protection Nodes
If your services are deployed on third-party public clouds, private clouds, or on-premises data centers, you can use the hybrid cloud access mode to connect both cloud and on-premises services to WAF for unified protection. If you have hybrid cloud access requirements, contact your account manager.
Service-Linked Role
To provide services such as traffic access control and monitoring and analytics, WAF requires access to your cloud resources. Click Create Service-Linked Role. The system automatically creates the service-linked role AliyunServiceRoleForWaf. You do not need to manually modify this role.
Duration
Specify the subscription duration for the WAF 3.0 instance and whether to enable Auto-Renewal.
NoteTo conduct a proof of concept (POC) test, submit a request to your account manager and set Duration to 7-day POC.
Click Purchase Now and complete the payment.
What to do next
After you purchase an instance, you can follow these steps to use WAF 3.0:
Connect your services to WAF 3.0. For more information, see Connection overview.
Configure mitigation policies for the protected objects in WAF 3.0. For more information, see Overview of mitigation settings.
View protection data. For more information, see View security reports.