WAF 3.0 release and WAF 2.0 end of sale

Updated at:

Web Application Firewall (WAF) 3.0, a new version independent of WAF 2.0, was released for public preview in January 2022. The public preview ended on October 31, 2022. After the preview, WAF 3.0 became available for purchase with both subscription (prepaid) and pay-as-you-go billing models. New purchases of WAF 2.0 have been discontinued.

What's new in WAF 3.0

WAF 3.0 supports the CNAME record mode from WAF 2.0 and introduces a cloud native architecture that integrates with cloud services such as Application Load Balancer (ALB). WAF 3.0 also features a redesigned console for protection configuration, delivering greater security operational efficiency, a smoother user experience, and powerful new capabilities.

Compared with WAF 2.0, WAF 3.0 offers the following key enhancements:

  • New cloud native architecture

    WAF 3.0 deeply integrates as an SDK module into the gateways of cloud services, such as Application Load Balancer (ALB) and Microservices Engine (MSE). An SDK embedded in the gateway extracts traffic for detection and protection. During this process, WAF handles only security logic and does not participate in traffic forwarding. You can enable WAF protection with a single click for your service instances, including internal-facing instances, in any supported region. This eliminates complex setup, such as modifying DNS records or configuring certificates, ports, and back-to-origin algorithms. This improves service performance and stability while lowering access latency. For more information, see Cloud native architecture.

  • New protection configuration model

    WAF 3.0 allows you to flexibly define multi-dimensional protected objects and protected object groups, ranging from cloud product instances to domain names. It also introduces protection templates, which let you apply different protection rules to different protected objects. WAF 3.0 significantly improves configuration efficiency and helps you easily achieve the following goals:

    • Use protected object groups to apply protection rules in bulk to multiple protected objects, such as cloud product instances or domain names. You can define one set of protection rules and apply it to a large number of assets with similar protection requirements, or configure custom rules for a few key assets.

    • Configure a default protection template to uniformly apply predefined protection rules to new assets added to WAF.

    For more information, see Protection configuration model.

  • New pay-as-you-go 3.0 billing model

    WAF 3.0 introduces a pay-as-you-go billing model that uses the Security Capacity Unit (SeCU) as the unified billing unit. All billable items are converted into SeCUs, simplifying the billing logic and lowering the entry cost. You are billed hourly based on your SeCU consumption. This flexible model supports both direct hourly billing and using a resource plan to offset SeCU usage. For more information, see Pay-as-you-go 3.0 billing model.

  • Other features and experience optimizations

    WAF 3.0 supports new features such as custom responses and uses Simple Log Service (SLS) for integrated log management and billing. This allows you to define custom storage durations and capacities for your logs. It also includes significant optimizations for CNAME record mode configuration, security reports, and rule searching. For more information, see Custom responses, Log management, CNAME record mode configuration, and Security reports.

Activation and supported regions

Activation

To activate WAF 3.0, see Activate a subscription WAF 3.0 instance and Activate a pay-as-you-go WAF 3.0 instance.

Supported regions

Relationship between WAF 2.0 and WAF 3.0

  • WAF 3.0 is a completely new version that differs from WAF 2.0 in its underlying architecture, product specifications, console configuration logic, and user experience. For this reason, WAF 2.0 and WAF 3.0 instances cannot coexist in the same Alibaba Cloud account.

  • Existing WAF 2.0 users are not affected. You can continue to use, renew, and upgrade your instances as usual. The service level agreement (SLA) for WAF 2.0 remains in effect.

  • You can use the self-service upgrade tool to automatically upgrade your WAF 2.0 instances to WAF 3.0. For more information, see WAF 3.0 Upgrade Guide.