WAF overview
ESA combines edge WAF capabilities with configurable rules for fine-grained scrubbing and management of origin-bound traffic.
What is WAF
A Web Application Firewall (WAF) filters and monitors HTTP traffic between your application and the internet. It identifies malicious patterns and forwards only legitimate requests to your origin, preventing attacks that degrade performance or disrupt services.
ESA delivers WAF protection across 3,200 global PoPs, securing websites at the network edge.
Requests blocked by WAF rules are not billed and do not count against your plan's quota.
Feature categories
Feature | Description |
Smart Rate Limiting enhances Rate Limiting Rules with the ESA AI engine. Instead of manually analyzing traffic and defining rules, you select a protection level. The system trains a baseline from your site's past seven days of traffic and updates it daily. | |
ESA leverages Alibaba Cloud's network-wide threat intelligence to challenge or block suspicious requests, preventing financial losses from resource abuse. | |
If your website requires custom access control policies, you can create custom rules. A custom rule allows you to define match conditions for incoming requests and specify an action, such as block or monitor, for matching requests. This gives you flexible control over the content users can access. | |
Rate limiting rules in control the rate of incoming requests that match specific conditions. When a client exceeds the configured request threshold, rate limiting enforces actions such as slider CAPTCHA verification or temporary IP blacklisting. | |
Managed rules are intelligent built-in ESA protection rules that defend against OWASP attacks and the latest origin server vulnerabilities, including SQL injection, XSS, code execution, CRLF, remote file inclusion, and WebShell. Enable protection without manual rule configuration or updates. | |
Scan protection identifies scanner behavior and signatures to block large-scale scans against your website, then blocks or blacklists the attack source to reduce intrusion risk and unwanted traffic. | |
Whitelist rules let specific requests bypass all or selected WAF protection modules, preventing false positives from internal services or known partners. | |
Create security policies based on IP address, ASN, and geographic region. Rules apply to both HTTP (Layer 7) and Layer 4 proxy traffic. |
Execution order
WAF evaluates rules in this order: Global WAF → IP access rules → whitelist rules → security level → scan protection rules → managed rules → custom rules → smart rate limiting → rate limiting rules → bot management rules → abuse prevention → Account security (ATO).
A request passes through the rules in sequence until a rule blocks it or a whitelist rule allows it.

Feature availability by plan
Feature category | Feature | Free (CNY 0/month) | Basic (CNY 9.9/month) | Standard (CNY 375/month) | Advanced (CNY 3,600/month) | Enterprise (Contact sales for pricing) |
5 | 10 | 50 | 100 | 100 | ||
1 | 1 | 3 | 5 | 10 | ||
Rate limiting: Counting periods | 10 seconds |
|
|
|
| |
Rate limiting: Action durations | 10 seconds |
|
|
|
| |
Rate limiting: Characteristics | client IP |
|
|
|
| |
Rate limiting on cached requests | ||||||
50 | 200 | 300 | 400 | 400 | ||
1 | 2 | 3 | 5 | 10 | ||
Supports basic rules | Supports basic rules | Supports all rules | Supports all rules | Supports all rules | ||
5 | 10 | 20 | ||||
Strict CAPTCHA | ||||||
An account-level quota applies, with a default limit of 10 rules. | ||||||
DDoS alerting | ||||||
Layer 4 proxy (including Layer 4 DDoS protection) | ||||||