Comparison of WAF 3.0 and WAF 2.0
Web Application Firewall (WAF) 3.0 is an all-new version. Compared with WAF 2.0, WAF 3.0 features optimizations in integration methods, protection configuration, and billing methods. This topic compares the two versions to describe the key optimizations of WAF 3.0.
WAF 3.0 has a different underlying architecture, editions, console configuration logic, and interactive experience from WAF 2.0. Therefore, it cannot coexist with WAF 2.0 under the same Alibaba Cloud account ID. If you have purchased a WAF 2.0 instance, you log on to the version 2.0 console. If you have purchased a WAF 3.0 instance, you log on to the version 3.0 console.
You can use a self-service tool to automatically migrate your WAF 2.0 instances to WAF 3.0. For more information, see WAF 3.0 migration wizard.
Access modes
WAF supports two access modes: CNAME record mode and cloud native access mode.
Access mode | WAF 3.0 | WAF 2.0 |
CNAME record mode (Figure ①) | Supported.
For more information, see CNAME record mode. | Supported. |
Cloud native access mode (WAF as a transparent proxy cluster) (Figure ②) | Supported.
For more information, see Enable WAF protection for a CLB instance and Enable WAF protection for an ECS instance. | Supported, but with the following limitations:
|
Cloud native access mode (WAF as an SDK integration) (Figure ③) | Supported. If your services are running on Application Load Balancer (ALB), Microservices Engine (MSE), Function Compute (FC), or Serverless App Engine (SAE) 2.0, this access mode is recommended.
For more information, see Enable WAF protection for an ALB instance, Enable WAF protection for an MSE cloud-native gateway instance, Enable WAF protection for a custom domain name in Function Compute, and Enable WAF protection for a custom domain name in SAE 2.0. | Not supported. |
Protection configuration
Protection configuration | WAF 3.0 | WAF 2.0 |
Bulk configuration of protection rules | Supported. In WAF 3.0, you can define domains or instances as protected objects and group them into a protected object group.
| Not supported. WAF 2.0 uses domains as protected objects and only allows you to configure rules for one domain at a time. To apply the same rule to 100 domains, you must repeat the configuration 100 times. |
Protection rules for traffic from non-domain sources (e.g., transparently connected instances) | Supported. Instances added via cloud native access mode automatically become protected objects, allowing you to configure and modify their protection rules. | Not supported. If transparent proxy is enabled but no specific domains are added, traffic is automatically protected by a built-in default rule set. This rule set is not visible and cannot be customized. Domain quota consumption
Prerequisites for rule modification In transparent proxy mode, if an instance contains 100 domains, all 100 domains must be added to WAF before you can modify any protection rules. Otherwise, all traffic is subject to the unchangeable default protection rules. |
Centralized view of protection rules | Supported. WAF 3.0 provides a card-based layout where you can view and manage rules for each protection module. This layout clearly shows which protection templates apply to which protected objects or protected object groups. You can also search for protection rules by their rule ID. | Not supported. To determine which protection rules apply to a specific domain, you must review each protection rule individually. |
Modify default protection rules | Supported. The protection rule templates in WAF 3.0 have default properties. If you want the default protection rules for newly added domains to be set to Monitor mode, you can set the default template to Monitor mode. Then, the protection action for all newly added protected objects is set to Monitor mode, and you do not need to manually change the setting each time. | Not supported. If you want to set the default protection rules for all newly added domains to Monitor mode, you cannot do so with WAF 2.0. After you add the domains, you must manually modify their protection rules. |
Feature enhancements
Compared to WAF 2.0, WAF 3.0 introduces the following feature enhancements:
Custom response rules
This feature lets you customize the block page that WAF returns to clients, including the response headers, body, and status code. For more information, see Configure a custom response page.
Critical event protection
This feature provides intelligent protection policies based on Alibaba Cloud's extensive experience securing critical events. You can enable high-level protection with a single click, without configuring complex rules manually. For more information, see critical event protection.
A new asset center
This feature helps you manage your domain assets across on-premises and cloud environments. It assesses risk levels based on attack trends, giving you a holistic view of your security posture. For more information, see Domain asset center.
New security reports
Security reports display protection data from all enabled modules, allowing you to perform security analysis for your services. For more information, see security reports.
Unified whitelist
This feature supports centralized management of global whitelist rules. For more information, see whitelist.
Billing methods
WAF 3.0 introduces the following optimizations for its subscription and pay-as-you-go billing methods:
Subscription
WAF 3.0 introduces a Basic edition suitable for users with low traffic.
Billing is simplified:
Traffic is now measured only by QPS, not bps. Elastic capacity is available on a pay-as-you-go basis to prevent service disruptions from QPS overages.
WAF no longer distinguishes between primary and other domains for billing. Instead, additional domains use tiered pricing, where the unit price decreases as you add more domains.
Hybrid Cloud Protection is available in more editions.
After a WAF 2.0 instance is migrated to WAF 3.0, its billing method and edition remain unchanged. For information about billing changes after migration, see Changes in fees for subscription instances.
Pay-as-you-go
This billing method uses the security capacity unit (SeCU) to simplify billing. SeCU resource plans feature tiered pricing, where the price decreases as usage increases.
WAF 3.0 supports hourly billing. Charges automatically cease when you disable a feature or delete its configuration, requiring no manual deprovisioning.
Related documents
Access overview: Learn about the access modes and onboarding procedures for WAF 3.0.
Protection configuration overview: Learn about the protection configuration workflow and supported settings in WAF 3.0.
Subscription billing: Learn about the WAF 3.0 subscription billing method.
Pay-as-you-go billing: Learn about the WAF 3.0 pay-as-you-go billing method.