All Products
Search
Document Center

Web Application Firewall:Billing rules of subscription WAF 3.0 instances

Last Updated:Dec 05, 2024

Subscription is a billing method that requires you to pay for resources before you can use the resources. If your protection resource usage is relatively stable and predictable, or your web services require long-term protection, we recommend that you select the subscription billing method. This billing method provides lower prices than the pay-as-you-go billing method and can help reduce the cost of web application protection. This topic describes the billing rules of subscription Web Application Firewall (WAF) 3.0 instances.

Scenarios

The subscription billing method is more suitable than the pay-as-you-go billing method for the following scenarios:

  • Your protection resource usage is relatively stable and predictable:

    • If your protection resource usage is relatively stable and predictable, you can select the subscription billing method and purchase resources based on your business requirements to reduce costs.

    • If the number of queries per second (QPS) is relatively stable, you can select the subscription billing method and enable the burstable QPS (pay-as-you-go) value-added feature to reduce costs. If you enable the feature, requests that exceed the purchased QPS quota are billed on a pay-as-you-go basis. The following figure illustrates this billing scenario.

      image
  • Your web services require long-term WAF protection: If your web services require long-term WAF protection, you can select the subscription billing method and select the WAF edition that best meets your business requirements to reduce costs.

  • Your web services belong to multiple accounts or your web services are added to WAF in hybrid cloud mode: Only subscription WAF instances that run Enterprise and Ultimate editions support the multi-account management feature and the hybrid cloud mode.

Billable items

Important
  • The product and service prices may change. Refer to your Alibaba Cloud bill for the final amount.

  • If you enable WAF protection for an Application Load Balancer (ALB) instance, you are charged by WAF and ALB. For more information, see Activate and manage WAF-enabled ALB instances.

Major event protection fees

If you enable the major event protection feature, you are charged based on the subscription duration of the feature. The minimum subscription duration is 30 days. For more information about the major event protection feature and the fees for the feature, see Major event protection.

Note
  • To enable the major event protection feature, perform the following steps: Log on to the WAF 3.0 console and select the resource group and region in which your WAF instance is deployed. In the left-side navigation pane, choose Protection Configuration > Protection for Major Events. On the Protection for Major Events page, enable the major event protection feature.

  • The major event protection feature takes effect immediately after you enable it. The validity period of the feature is the subscription duration that you specify when you enable the feature. After the validity period ends, the major event protection feature no longer protects your services.

Subscription WAF instance fees

If you purchase a subscription WAF instance, you are charged basic service fees and value-added service fees.

  • Basic service fees (required): fees for the edition, specifications, and subscription duration that you specify when you purchase the subscription WAF instance.

  • Value-added service fees (optional): fees for value-added features. You can enable one or more value-added features based on your business requirements. You must pay for value-added features before you can use the features. This does not apply to the burstable QPS (pay-as-you-go) and fraud detection features, which are billed on a pay-as-you-go basis.

The following figure shows the billable items.

Note

If you purchase a subscription WAF instance and enable the major event protection, hybrid cloud protection, bot management for web application protection, bot management for app protection, or API security value-added feature, you cannot perform self-service unsubscription in the WAF console.

Billable items of subscription WAF instances

image

Billing details

Basic service fees

Note

For more information about the basic features and value-added features supported by each edition, see Editions.

Edition

Unit price

Basic edition

USD 140 per month

Pro edition

USD 556 per month

Enterprise edition

USD 1,400 per month

Ultimate edition

USD 4,260 per month

Value-added service fees (subscription)

Note
  • If your WAF instance runs the Pro, Enterprise, or Ultimate edition, you can use a free trial of the bot management for web application protection, bot management for app protection, and API security features.

  • The free trial is valid for seven days. If you do not enable the features after the free trial ends, the protection settings configured for the features are automatically deleted. If you want to retain the data that is generated during the trial period and continue using the protection settings configured for the features, you must enable the features before the trial period ends.

Billable item

Basic edition

Pro edition

Enterprise edition

Ultimate edition

Billed based on feature status

Bot management for web application protection

Not supported

USD 500 per month

USD 1,000 per month

USD 1,720 per month

Bot management for app protection

Not supported

USD 300 per month

API security

Not supported

USD 720 per month

USD 1,400 per month

USD 2,880 per month

Intelligent load balancing

Not supported

USD 150 per month

Traffic Spike Throttling

Not supported

USD 1,200 per month

Billed based on specifications

Additional domain name quota

Tiered pricing based on the additional domain name quota that is purchased:

  • 0 ≤ Quota ≤ 10: USD 22 per domain name-month

  • 10 < Quota ≤ 100: USD 16 per domain name-month for the 11th to 100th domain names

  • 100 < Quota ≤ 300: USD 9 per domain name-month for the 101st to 300th domain names

  • 300 < Quota ≤ 500: USD 5 per domain name-month for the 301st to 500th domain names

  • 500 < Quota ≤ 2,000: USD 3 per domain name-month for the 501st to 2,000th domain names

  • 2,000 < Quota ≤ 5,000: USD 2 per domain name-month for the 2,001st to 5,000th domain names

Note
  • You can purchase an additional domain name quota of 10 for a WAF instance that runs the Basic edition.

  • You can purchase an additional domain name quota of 500 for a WAF instance that runs the Pro edition.

  • You can purchase an additional domain name quota of 2,000 for a WAF instance that runs the Enterprise edition.

  • You can purchase an additional domain name quota of 5,000 for a WAF instance that runs the Ultimate edition.

For more information about the limits on the additional domain name quota, see Release notes.

Exclusive IP address

Not supported

USD 30 per IP address-month

Additional QPS quota

Not supported

Chinese mainland:

  • Basic fee: tiered pricing. Tiered pricing based on the additional QPS quota that is purchased:

    • 0 < Quota ≤ 10,000: USD 0.5 per QPS-month

    • 10,000 < Quota ≤ 30,000: USD 0.48 per QPS-month

  • Feature fee: If you enable the API security or bot management feature, you are charged an additional fee of USD 0.3 per QPS-month for each feature.

Outside the Chinese mainland:

  • Basic fee: USD 0.6 per QPS-month.

  • Feature fee: If you enable the API security or bot management feature, you are charged an additional fee of USD 0.3 per QPS-month for each feature.

Note

Simple Log Service for WAF

Not supported

Log storage capacity: USD 75 per TB-month.

Important

The minimum log storage capacity that can be purchased is 3 TB. You cannot reduce the log storage capacity to less than 3 TB.

Additional quota for hybrid cloud protection nodes

Not supported

Not supported

Tiered pricing based on the additional quota that is purchased:

  • 0 < Quota ≤ 3: USD 1,440 per node-month

  • 3 < Quota ≤ 8: USD 1,360 per node-month for the 4th to 8th nodes

  • 8 < Quota ≤ 500: USD 1,290 per node-month for the 9th to 500th nodes

Note

If you want to use WAF to protect web services that are deployed in multi-cloud environments, data centers, internal networks, and private clouds, but the web services cannot be added to WAF in CNAME record mode, you can purchase additional protection nodes for hybrid cloud clusters to protect the web services by using on-premises servers.

In reverse proxy mode, each node can protect services that support up to 5,000 QPS for HTTP requests or up to 3,000 QPS for HTTPS requests.

In SDK integration mode, each node can protect services that support up to 15,000 QPS for HTTP or HTTPS requests. You can increase the number of nodes to improve protection capabilities.

Value-added service fees (pay-as-you-go)

Billable item

Basic edition

Pro edition

Enterprise edition

Ultimate edition

Risk identification (paid feature of bot management)

Not supported

If you configure rules and traffic hits the rules, you are charged based on the number of hits. Unit price: USD 0.007 per hit.

Note

If you do not configure risk identifications rules or no traffic hits the rules, you are not charged. For more information about the billing of the risk identification feature, see Risk identification.

Burstable QPS (pay-as-you-go)

Not supported

For more information about the billing of the burstable QPS (pay-as-you-go) feature, see Burstable QPS (pay-as-you-go).

Note

If you do not pay for pay-as-you-go value-added features on time, your Alibaba Cloud account may have overdue payments, which affect the use of WAF. We recommend that you check whether your account has overdue payments in the Expenses and Costs console and top up your account at the earliest opportunity. For more information about how to handle overdue payments, see Overdue payments.

Billing cycles

  • The billing cycle of a subscription resource corresponds to the subscription duration that you specify when you purchase the resource and is based on UTC+8 time. The start time of a billing cycle is the exact time when the resource is enabled or renewed, and the end time is at 00:00:00 on the next day of the expiration date. Both the start time and end time are accurate to seconds.

  • Bills for pay-as-you-go value-added features are generated and settled on a daily basis based on UTC+8 time. After a bill is settled, a new billing cycle begins.

Note
  • The billing cycles of subscription resources are based on calendar years or months.

  • The billing cycle of the major event protection feature starts at the time when you enable the feature and ends at the time when the validity period elapses.

  • The bills for pay-as-you-go value-added features are generated and settled each day before 06:00. If you want to change instance configurations, we recommend that you perform the change after 06:00. Otherwise, the change is included in the bill of the previous day.

  • If the available balance in your account, including Alibaba Cloud account balance and vouchers, is less than the amount due for a pending bill, you are notified that your balance is low by text message or email.

Instance expiration

After your WAF instance expires, the instance no longer provides services. The following rules take effect:

  • You receive text message or email notifications 15 days, 7 days, 3 days, and 1 day before your WAF instance expires. The notifications remind you that the instance is about to expire and prompt you to renew the instance at the earliest opportunity.

    If you do not renew the instance before the expiration date, the instance stops providing services upon expiration.

  • After your WAF instance expires, the instance enters a 15-day grace period. During the grace period, the configurations of the instance are retained.

    If you renew the instance within the 15-day grace period, you can continue to use the configurations. Otherwise, the configurations are released and you must repurchase and reconfigure a new instance to continue protecting your web services.

Warning

If you do not renew a WAF instance before the expiration date, the instance may be suspended, and the system reminds or notifies you of the issue. If your web services require WAF protection, we recommend that you renew the instance at the earliest opportunity.

Bill query

You can view the billing details of your subscription WAF instance and the actual usage of pay-as-you-go resources on the Bills page in the WAF console. For more information, see View bills.

References