WAF overview

Updated at:

ESA combines edge WAF capabilities with configurable rules for fine-grained scrubbing and management of origin-bound traffic.

What is WAF

A Web Application Firewall (WAF) filters and monitors HTTP traffic between your application and the internet. It identifies malicious patterns and forwards only legitimate requests to your origin, preventing attacks that degrade performance or disrupt services.

ESA delivers WAF protection across 3,200 global PoPs, securing websites at the network edge.

Important

Requests blocked by WAF rules are not billed and do not count against your plan's quota.

Feature categories

Feature

Description

Smart rate limiting

Smart Rate Limiting enhances Rate Limiting Rules with the ESA AI engine. Instead of manually analyzing traffic and defining rules, you select a protection level. The system trains a baseline from your site's past seven days of traffic and updates it daily.

Abuse prevention

ESA leverages Alibaba Cloud's network-wide threat intelligence to challenge or block suspicious requests, preventing financial losses from resource abuse.

Custom rules

If your website requires custom access control policies, you can create custom rules. A custom rule allows you to define match conditions for incoming requests and specify an action, such as block or monitor, for matching requests. This gives you flexible control over the content users can access.

Rate limiting rules

Rate limiting rules in control the rate of incoming requests that match specific conditions. When a client exceeds the configured request threshold, rate limiting enforces actions such as slider CAPTCHA verification or temporary IP blacklisting.

Managed rules

Managed rules are intelligent built-in ESA protection rules that defend against OWASP attacks and the latest origin server vulnerabilities, including SQL injection, XSS, code execution, CRLF, remote file inclusion, and WebShell. Enable protection without manual rule configuration or updates.

Scan protection rules

Scan protection identifies scanner behavior and signatures to block large-scale scans against your website, then blocks or blacklists the attack source to reduce intrusion risk and unwanted traffic.

Whitelist rules

Whitelist rules let specific requests bypass all or selected WAF protection modules, preventing false positives from internal services or known partners.

IP access rules

Create security policies based on IP address, ASN, and geographic region. Rules apply to both HTTP (Layer 7) and Layer 4 proxy traffic.

Execution order

WAF evaluates rules in this order: Global WAF → IP access rules → whitelist rules → security level → scan protection rules → managed rules → custom rules → smart rate limiting → rate limiting rules → bot management rules → abuse prevention → Account security (ATO).

Note

A request passes through the rules in sequence until a rule blocks it or a whitelist rule allows it.

image

Feature availability by plan

Feature category

Feature

Free (CNY 0/month)

Basic (CNY 9.9/month)

Standard (CNY 375/month)

Advanced (CNY 3,600/month)

Enterprise (Contact sales for pricing)

WAF

Custom rules

5

10

50

100

100

Rate limiting rules

1

1

3

5

10

Rate limiting: Counting periods

10 seconds

  • 10 seconds

  • 15 minutes

  • 10 seconds

  • 1 minute

  • 15 minutes

  • 10 seconds

  • 1 minute

  • 2 minutes

  • 5 minutes

  • 10 minutes

  • 15 minutes

  • 5 seconds

  • 10 seconds

  • 1 minute

  • 2 minutes

  • 5 minutes

  • 10 minutes

  • 15 minutes

  • 1 hour

Rate limiting: Action durations

10 seconds

  • 10 seconds

  • 1 hour

  • 10 seconds

  • 1 minute

  • 10 minutes

  • 1 hour

  • 10 seconds

  • 1 minute

  • 2 minutes

  • 5 minutes

  • 10 minutes

  • 1 hour

  • 10 seconds

  • 1 minute

  • 2 minutes

  • 5 minutes

  • 10 minutes

  • 1 hour

  • 1 day

Rate limiting: Characteristics

client IP

  • hostname

  • client IP

  • hostname

  • client IP

  • header

  • URI query string

  • cookie value

  • hostname

  • client IP

  • header

  • URI query string

  • cookie value

  • URI

  • URI path

  • ASN number

  • hostname

  • client IP

  • header

  • URI query string

  • cookie value

  • URI

  • URI path

  • ASN number

  • Specific URI query parameter

  • HTTP version

  • User Agent

  • X-Forwarded-For

  • MIME type

Rate limiting on cached requests

Not supported

Not supported

Supported

Supported

Supported

IP access rules

50

200

300

400

400

Allowlist rules

1

2

3

5

10

Managed rules

Supports basic rules

Supports basic rules

Supports all rules

Supports all rules

Supports all rules

Scanning protection rules

Not supported

Not supported

5

10

20

JavaScript challenge

Not supported

Supported

Supported

Supported

Supported

Slider CAPTCHA

Not supported

Not supported

Supported

Supported

Supported

Strict CAPTCHA

Not supported

Not supported

Not supported

Not supported

Supported

Scenario-specific policies

An account-level quota applies, with a default limit of 10 rules.

Custom pages

Custom rule groups

IP CIDR blocks/groups

DDoS alerting

Not supported

Not supported

Not supported

Not supported

Supported

Layer 4 proxy (including Layer 4 DDoS protection)

Not supported

Not supported

Not supported

Not supported

Supported