All Products
Search
Document Center

Web Application Firewall:Upgrade and downgrade WAF 3.0 instances

Last Updated:Jul 16, 2026

Web Application Firewall (WAF) provides upgrade and downgrade features that allow you to upgrade the WAF edition you purchased and upgrade or downgrade value-added services based on your business changes. This topic describes how to upgrade or downgrade WAF.

Instance upgrade

Supported upgrade items

  • Upgrade the service edition

    You can upgrade from a lower edition to a higher one. WAF 3.0 editions from lowest to highest are: Basic, Pro, Enterprise, Ultimate.

  • Purchase value-added services

    Supported value-added services include: multi-cloud/hybrid cloud protection, Bot Management - Web Protection, Bot Management - App Protection, API Security, QPS extension, domain extension, exclusive IP, intelligent load balancing, Simple Log Service, risk identification, and traffic spike throttling.

  • Upgrade the specifications of purchased value-added services

    Supported specification upgrades include: multi-cloud/hybrid cloud protection extension nodes, QPS extension specifications, number of domain extensions, number of exclusive IPs, log storage capacity.

Billing

When you upgrade, you must pay the price difference generated by the upgrade, and the order takes effect immediately.

The specific fee is subject to the amount displayed on the upgrade page in the console.

Procedure

  1. Log on to the Web Application Firewall 3.0 console. From the top menu bar, select the resource group and region (Chinese Mainland or Outside Chinese Mainland) for the WAF instance.

  2. In the left navigation pane, click Overview.

  3. In the upper-right corner of the Overview page, in the instance basic information card area, click Upgrade Now.

    Note

    You can also click Upgrade next to Protected Domain Names, QPS, or Exclusive IP Addresses, or click Upgrade next to Intelligent Load Balancing to upgrade the corresponding specification.

  4. Select the configuration you want to change, carefully read and select Terms of Service, and click Purchase Now to complete the payment.

Instance downgrade

Currently WAF 3.0 does not support edition downgrade. You can only adjust specifications within the same edition. For example, you cannot downgrade from Enterprise to Pro, but you can reduce specification items within the current edition to reduce costs.

Unsupported downgrade scenarios

  • Additional Domains, Exclusive IP Addresses, and Additional Protection Nodes that are already in use cannot be downgraded.

  • For example, if you have purchased a subscription-based Pro instance (which includes 5 free domains) and purchased Additional Domains with a specification of 10. If you have added 7 domains, which means 2 domain extension specifications are already in use, you can only reduce the Additional Domains specification to a minimum of 2.

Supported downgrade items

  • Reduce the specifications of purchased value-added services

    Supported value-added service specification downgrades include: QPS extension specifications, number of domain extensions, number of exclusive IPs, log storage capacity, multi-cloud/hybrid cloud WAF.

  • Disable purchased value-added services

    • Value-added services that can be disabled by submitting a Tickets: Bot Management - Web Protection, Bot Management - App Protection, API Security.

    • Value-added services that can be disabled directly: intelligent load balancing, traffic spike throttling.

Downgrade impacts

If log storage usage exceeds the log storage capacity limit after the downgrade, new log data cannot be written, resulting in incomplete log data. The minimum activation capacity for Simple Log Service is 3 TB and cannot be downgraded below the minimum activation capacity.

Refund description

When you downgrade, the amount corresponding to orders that are no longer used in the purchased orders is refunded. For more details on refund calculation, see Rules for unsubscribing from resources.

When calculating the refund, the actual consumption amount is calculated based on the daily average unit price and then multiplied by a factor of 1.5.

Procedure

You can only perform one downgrade operation per calendar month.

  1. Log on to the Web Application Firewall 3.0 console. From the top menu bar, select the resource group and region (Chinese Mainland or Outside Chinese Mainland) for the WAF instance.

  2. In the left navigation pane, click Overview.

  3. In the upper-right corner of the Overview page, in the instance basic information card area, click More and then click Downgrade.

  4. In the Downgrade panel, select the configuration you want to change, carefully read and select Terms of Service, and click Purchase Now to complete the payment.