All Products
Search
Document Center

Web Application Firewall:Purchase a WAF 3.0 subscription instance

Last Updated:Jul 16, 2026

Web Application Firewall (WAF) protects against web attacks such as SQL injection, cross-site scripting, CC attacks, and malicious bots. This topic describes how to purchase a WAF 3.0 subscription instance based on your business needs.

Note

If your account has a WAF 2.0 instance activated and you need to use a WAF 3.0 instance, perform operations based on your scenario:

  • Your WAF 2.0 instance has running services: Use the migration tool to upgrade a WAF 2.0 instance to WAF 3.0.

  • Your WAF 2.0 instance has no running services: Release the WAF 2.0 instance and then perform the purchase operations described in this topic.

Select an edition

Subscription WAF 3.0 is available in four editions: Basic, Pro, Enterprise, and Ultimate. Select an edition based on your business scenario and security requirements. For a detailed edition comparison, see Edition comparison.

Edition

Basic

Pro

Enterprise

Ultimate

Scenarios

Small or personal websites with no special security requirements.

Small and medium-sized websites with no special security requirements.

Medium-sized enterprise websites, or services that are open to the public with high security standards.

Medium to large enterprise websites with large-scale services, or that require customized security configurations.

Included features

Peak QPS

10 QPS

2,000 QPS

5,000 QPS

10,000 QPS

Number of domain names

3

5

10

50

Supported ports

Standard ports: 80, 8080, 443, and 8443

Standard ports: 80, 8080, 443, and 8443

Standard and non-standard ports

Standard and non-standard ports

Hybrid cloud nodes

Unsupported

Unsupported

1

1

Protection for critical events

Unsupported

Available as a paid add-on

Available as a paid add-on

Supported

Paid add-on features

Advanced security features such as Log Service, exclusive IP addresses, bot management, and API security

Unsupported

Supported

Supported

Supported

Domain extension

Up to 10

Up to 500

Up to 2,000

Up to 5,000

Additional QPS (prepaid)

Unsupported

Supported

Supported

Supported

Elastic QPS (pay-as-you-go)

Supported

Supported

Supported

Supported

Purchase a WAF instance

  1. Go to the Web Application Firewall 3.0 (Subscription) purchase page.

  2. Set Billing Method to Subscription, and then configure the following parameters.

    Purchase a Basic instance

    Parameter

    Description

    Version

    Select the edition based on your edition selection in the previous step.

    Region

    Specifies the location of WAF protection nodes, which affects access latency and data compliance.

    If your web server is deployed in the Chinese mainland, select Chinese Mainland. Otherwise, select Outside Chinese Mainland.

    Elastic QPS

    This feature is enabled by default and cannot be disabled. When your business traffic peak exceeds the purchased QPS quota, the excess is billed on a pay-as-you-go basis based on usage. This helps you handle sudden traffic surges caused by attacks or promotional events.

    Additional Domains

    If the number of domain names that you need to protect exceeds the quota provided by the selected edition, you can purchase additional domain extensions.

    Service-Linked Role

    To provide services such as traffic access control and monitoring and analytics, WAF requires access to your cloud resources. Click Create Service-Linked Role. The system automatically creates the service-linked role AliyunServiceRoleForWaf. You do not need to manually modify this role.

    Duration

    Specify the subscription duration for the WAF 3.0 instance and whether to enable Auto-Renewal.

    Note

    To conduct a proof of concept (POC) test, submit a request to your account manager and set Duration to 7-day POC.

    Purchase a Pro instance

    Parameter

    Description

    Version

    Select the edition based on your edition selection in the previous step.

    Region

    Specifies the location of WAF protection nodes, which affects access latency and data compliance.

    If your web server is deployed in the Chinese mainland, select Chinese Mainland. Otherwise, select Outside Chinese Mainland.

    API Security

    We recommend that you enable this module if your services involve a large number of API calls and you need to protect against sensitive data leaks or malicious attacks.

    Bot Management - Web Protection

    We recommend that you enable this module to protect your website against malicious bot traffic, such as data scraping, spam registration, business fraud, or cheating. This module applies to webpages and H5 pages that are accessed through browsers, including H5 pages used in apps.

    Bot Management - App Protection

    We recommend that you enable this module to protect your services against malicious bot traffic, such as data scraping, spam registration, business fraud, or cheating. This module applies to native apps developed for iOS or Android, but excludes H5 pages used in apps.

    Risk Identification

    If you have enabled the bot management module, you can enable this feature. It uses the built-in mobile number reputation database of WAF to prevent spam account registration and marketing fraud.

    Peak Traffic Throttling

    If you have promotional events, you can enable this feature to allow only a fixed QPS or a specific ratio of traffic to reach your backend servers, which ensures business stability.

    Additional QPS

    If the peak QPS of traffic that you need to protect exceeds the quota provided by the selected edition, you can purchase additional QPS.

    Elastic QPS

    This feature is enabled by default and cannot be disabled. When your business traffic peak exceeds the purchased QPS quota, the excess is billed on a pay-as-you-go basis based on usage. This helps you handle sudden traffic surges caused by attacks or promotional events.

    Additional Domains

    If the number of domain names that you need to protect exceeds the quota provided by the selected edition, you can purchase additional domain extensions.

    Exclusive IP

    In CNAME access mode, domain names of the same WAF instance share an IP address by default. If any domain name is targeted by a large-volume DDoS attack, the IP address enters blackhole filtering and access to all domain names is interrupted. You can configure an exclusive IP address for critical domain names to avoid business availability impacts caused by blackhole events.

    Intelligent Load Balancing

    This applies to scenarios where your business requires high availability with automatic disaster recovery and low-latency access in CNAME access mode.

    Log Service

    This applies to scenarios where you need to meet security compliance requirements (such as classified protection) or perform in-depth security analysis.

    Log Storage Capacity

    Select the maximum log storage capacity for the Log Service (starting from 3 TB). Unit: TB.

    We recommend that you purchase an appropriate log storage capacity based on your business requirements. If the capacity reaches the upper limit, WAF no longer writes logs.

    Service-Linked Role

    To provide services such as traffic access control and monitoring and analytics, WAF requires access to your cloud resources. Click Create Service-Linked Role. The system automatically creates the service-linked role AliyunServiceRoleForWaf. You do not need to manually modify this role.

    Duration

    Specify the subscription duration for the WAF 3.0 instance and whether to enable Auto-Renewal.

    Note

    To conduct a proof of concept (POC) test, submit a request to your account manager and set Duration to 7-day POC.

    Purchase an Enterprise or Ultimate instance

    Parameter

    Description

    Version

    Select the edition based on your edition selection in the previous step.

    Region

    Specifies the location of WAF protection nodes, which affects access latency and data compliance.

    If your web server is deployed in the Chinese mainland, select Chinese Mainland. Otherwise, select Outside Chinese Mainland.

    API Security

    We recommend that you enable this module if your services involve a large number of API calls and you need to protect against sensitive data leaks or malicious attacks.

    Bot Management - Web Protection

    We recommend that you enable this module to protect your website against malicious bot traffic, such as data scraping, spam registration, business fraud, or cheating. This module applies to webpages and H5 pages that are accessed through browsers, including H5 pages used in apps.

    Bot Management - App Protection

    We recommend that you enable this module to protect your services against malicious bot traffic, such as data scraping, spam registration, business fraud, or cheating. This module applies to native apps developed for iOS or Android, but excludes H5 pages used in apps.

    Extension Plugins

    You can write custom Lua scripts to intervene in the web request processing pipeline, to implement personalized security logic and complex business customization beyond the native rules of WAF.

    Risk Identification

    If you have enabled the bot management module, you can enable this feature. It uses the built-in mobile number reputation database of WAF to prevent spam account registration and marketing fraud.

    Peak Traffic Throttling

    If you have promotional events, you can enable this feature to allow only a fixed QPS or a specific ratio of traffic to reach your backend servers, which ensures business stability.

    Additional QPS

    If the peak QPS of traffic that you need to protect exceeds the quota provided by the selected edition, you can purchase additional QPS.

    Elastic QPS

    This feature is enabled by default and cannot be disabled. When your business traffic peak exceeds the purchased QPS quota, the excess is billed on a pay-as-you-go basis based on usage. This helps you handle sudden traffic surges caused by attacks or promotional events.

    Additional Domains

    If the number of domain names that you need to protect exceeds the quota provided by the selected edition, you can purchase additional domain extensions.

    Exclusive IP

    In CNAME access mode, domain names of the same WAF instance share an IP address by default. If any domain name is targeted by a large-volume DDoS attack, the IP address enters blackhole filtering and access to all domain names is interrupted. You can configure an exclusive IP address for critical domain names to avoid business availability impacts caused by blackhole events.

    Intelligent Load Balancing

    This applies to scenarios where your business requires high availability with automatic disaster recovery and low-latency access in CNAME access mode.

    Log Service

    This applies to scenarios where you need to meet security compliance requirements (such as classified protection) or perform in-depth security analysis.

    Log Storage Capacity

    Select the maximum log storage capacity for the Log Service (starting from 3 TB). Unit: TB.

    We recommend that you purchase an appropriate log storage capacity based on your business requirements. If the capacity reaches the upper limit, WAF no longer writes logs.

    Additional Protection Nodes

    If your services are deployed on third-party public clouds, private clouds, or on-premises data centers, you can use the hybrid cloud access mode to connect both cloud and on-premises services to WAF for unified protection. If you have hybrid cloud access requirements, contact your account manager.

    Service-Linked Role

    To provide services such as traffic access control and monitoring and analytics, WAF requires access to your cloud resources. Click Create Service-Linked Role. The system automatically creates the service-linked role AliyunServiceRoleForWaf. You do not need to manually modify this role.

    Duration

    Specify the subscription duration for the WAF 3.0 instance and whether to enable Auto-Renewal.

    Note

    To conduct a proof of concept (POC) test, submit a request to your account manager and set Duration to 7-day POC.

  3. Click Purchase Now and complete the payment.

What to do next

After you purchase an instance, you can follow these steps to use WAF 3.0:

  1. Connect your services to WAF 3.0. For more information, see Connection overview.

  2. Configure mitigation policies for the protected objects in WAF 3.0. For more information, see Overview of mitigation settings.

  3. View protection data. For more information, see View security reports.