Comparison of WAF 3.0 and WAF 2.0

Updated at:

Web Application Firewall (WAF) 3.0 is an all-new version. Compared with WAF 2.0, WAF 3.0 features optimizations in integration methods, protection configuration, and billing methods. This topic compares the two versions to describe the key optimizations of WAF 3.0.

Important
  • WAF 3.0 has a different underlying architecture, editions, console configuration logic, and interactive experience from WAF 2.0. Therefore, it cannot coexist with WAF 2.0 under the same Alibaba Cloud account ID. If you have purchased a WAF 2.0 instance, you log on to the version 2.0 console. If you have purchased a WAF 3.0 instance, you log on to the version 3.0 console.

  • You can use a self-service tool to automatically migrate your WAF 2.0 instances to WAF 3.0. For more information, see WAF 3.0 migration wizard.

Access modes

WAF supports two access modes: CNAME record mode and cloud native access mode.

image

Access mode

WAF 3.0

WAF 2.0

CNAME record mode (Figure ①)

Supported.

  • You add your domain to WAF and point its DNS record to the provided WAF CNAME address. WAF then routes your traffic, inspecting it for attacks, blocking malicious requests, and forwarding legitimate traffic to your origin server.

  • In this mode, WAF acts as a reverse proxy cluster, handling both traffic forwarding and security inspection.

For more information, see CNAME record mode.

Supported.

Cloud native access mode (WAF as a transparent proxy cluster) (Figure ②)

Supported.

  • You add traffic redirection ports to WAF. This automatically updates the cloud product gateway's routing to forward web traffic to WAF. WAF inspects for attacks, blocks malicious requests, and forwards legitimate traffic to the origin server.

  • In this mode, WAF acts as a transparent proxy cluster, handling both traffic forwarding and security inspection.

For more information, see Enable WAF protection for a CLB instance and Enable WAF protection for an ECS instance.

Supported, but with the following limitations:

  • TLS protocol limitation: WAF supports only TLS 1.0 and 1.1 by default and does not allow you to customize TLS versions.

  • Cookie attribute: You cannot set the Secure attribute for the acw_tc cookie.

Cloud native access mode (WAF as an SDK integration) (Figure ③)

Supported.

If your services are running on Application Load Balancer (ALB), Microservices Engine (MSE), Function Compute (FC), or Serverless App Engine (SAE) 2.0, this access mode is recommended.

  • WAF 3.0 integrates with cloud product gateways as an SDK module. The embedded SDK extracts traffic for inspection and protection. In this mode, WAF does not forward traffic. This approach avoids the compatibility and stability issues caused by an extra forwarding layer.

  • You can enable protection for an instance with a single click. This simplified process requires no changes to DNS records or configurations for certificates, ports, or back-to-origin algorithms, minimizing the impact on your existing services.

  • This mode provides broader coverage by supporting all regions where the native Alibaba Cloud products are available.

  • You can integrate WAF with self-managed gateways, such as Nginx, in multi-cloud or hybrid cloud environments.

  • With SDK integration, WAF 3.0 offers flexible access options for various business scenarios. It supports deployment in multiple environments based on your network and compliance requirements, all managed from a unified console.

For more information, see Enable WAF protection for an ALB instance, Enable WAF protection for an MSE cloud-native gateway instance, Enable WAF protection for a custom domain name in Function Compute, and Enable WAF protection for a custom domain name in SAE 2.0.

Not supported.

Protection configuration

Protection configuration

WAF 3.0

WAF 2.0

Bulk configuration of protection rules

Supported.

In WAF 3.0, you can define domains or instances as protected objects and group them into a protected object group.

  • You can apply a single protection rule to a protected object group to configure rules for multiple objects at once.

  • You can also add a specific domain from a cloud native instance as a separate protected object to apply customized rules.

Not supported.

WAF 2.0 uses domains as protected objects and only allows you to configure rules for one domain at a time. To apply the same rule to 100 domains, you must repeat the configuration 100 times.

Protection rules for traffic from non-domain sources (e.g., transparently connected instances)

Supported.

Instances added via cloud native access mode automatically become protected objects, allowing you to configure and modify their protection rules.

Not supported. If transparent proxy is enabled but no specific domains are added, traffic is automatically protected by a built-in default rule set. This rule set is not visible and cannot be customized.

Domain quota consumption

  • Explicitly added: Domains explicitly added in transparent proxy mode consume the "Number of Protected Domains" quota from your subscription plan.

  • Default protection: Traffic protected only by the default core rules (where no specific domain is added) does not consume the "Number of Protected Domains" quota.

Prerequisites for rule modification

In transparent proxy mode, if an instance contains 100 domains, all 100 domains must be added to WAF before you can modify any protection rules. Otherwise, all traffic is subject to the unchangeable default protection rules.

Centralized view of protection rules

Supported.

WAF 3.0 provides a card-based layout where you can view and manage rules for each protection module. This layout clearly shows which protection templates apply to which protected objects or protected object groups. You can also search for protection rules by their rule ID.

Not supported.

To determine which protection rules apply to a specific domain, you must review each protection rule individually.

Modify default protection rules

Supported.

The protection rule templates in WAF 3.0 have default properties. If you want the default protection rules for newly added domains to be set to Monitor mode, you can set the default template to Monitor mode. Then, the protection action for all newly added protected objects is set to Monitor mode, and you do not need to manually change the setting each time.

Not supported.

If you want to set the default protection rules for all newly added domains to Monitor mode, you cannot do so with WAF 2.0. After you add the domains, you must manually modify their protection rules.

Feature enhancements

Compared to WAF 2.0, WAF 3.0 introduces the following feature enhancements:

  • Custom response rules

    This feature lets you customize the block page that WAF returns to clients, including the response headers, body, and status code. For more information, see Configure a custom response page.

  • Critical event protection

    This feature provides intelligent protection policies based on Alibaba Cloud's extensive experience securing critical events. You can enable high-level protection with a single click, without configuring complex rules manually. For more information, see critical event protection.

  • A new asset center

    This feature helps you manage your domain assets across on-premises and cloud environments. It assesses risk levels based on attack trends, giving you a holistic view of your security posture. For more information, see Domain asset center.

  • New security reports

    Security reports display protection data from all enabled modules, allowing you to perform security analysis for your services. For more information, see security reports.

  • Unified whitelist

    This feature supports centralized management of global whitelist rules. For more information, see whitelist.

Billing methods

WAF 3.0 introduces the following optimizations for its subscription and pay-as-you-go billing methods:

Subscription

  • WAF 3.0 introduces a Basic edition suitable for users with low traffic.

  • Billing is simplified:

    • Traffic is now measured only by QPS, not bps. Elastic capacity is available on a pay-as-you-go basis to prevent service disruptions from QPS overages.

    • WAF no longer distinguishes between primary and other domains for billing. Instead, additional domains use tiered pricing, where the unit price decreases as you add more domains.

  • Hybrid Cloud Protection is available in more editions.

  • After a WAF 2.0 instance is migrated to WAF 3.0, its billing method and edition remain unchanged. For information about billing changes after migration, see Changes in fees for subscription instances.

Pay-as-you-go

  • This billing method uses the security capacity unit (SeCU) to simplify billing. SeCU resource plans feature tiered pricing, where the price decreases as usage increases.

  • WAF 3.0 supports hourly billing. Charges automatically cease when you disable a feature or delete its configuration, requiring no manual deprovisioning.

Related documents