Edition Differences
WAF provides cloud and dedicated instances. The access mode varies depending on the instance type you are using. This topic describes comparisons on access modes, service specifications, and functions between different editions, so you can quickly know which type of instance best fits your service requirements.
Service Edition Overview
When you make a purchase decision, consider the access mode, specifications, and functions the WAF edition you plan to use supports.
- Access modes
You can connect a website to WAF in cloud mode or dedicated mode. For more details, see Access Mode Description.
- Service editions
To support different service scenarios, WAF provides multiple editions. For details about the specifications of different editions, see Specifications Supported by Each Edition. For details about the supported functions and features, see Functions Supported by Each Service Edition.
- For cloud mode, WAF can be billed on a yearly/monthly or pay-per-use basis. In yearly/monthly billing mode, you can use the standard, professional, or enterprise edition. For details about the different access modes and service editions, see Figure 1.
In cloud mode, you can change the billing mode between yearly/monthly and pay-per-use.
- For dedicated mode, WAF can be billed only in pay-per-use mode.
- For cloud mode, WAF can be billed on a yearly/monthly or pay-per-use basis. In yearly/monthly billing mode, you can use the standard, professional, or enterprise edition. For details about the different access modes and service editions, see Figure 1.
Access Mode Description
The service edition you can use is restricted by the access mode you want to use. So, before making a purchase, check which WAF access mode best fits your need.
WAF provides cloud mode and dedicated mode access modes. The following figure shows the deployment architectures. For their differences, see Table 1.


| Item | Cloud Mode | Dedicated Mode |
|---|---|---|
| Application scenarios | Suitable for service scenarios of various scales. For details about service scales and cloud mode editions, see Service Editions. | This mode is suitable for large enterprise websites that have a large service scale and have customized security requirements. |
| Where web services are deployed | Service servers are deployed on any cloud or in on-premises data centers. | Service servers are deployed on Huawei Cloud. |
| Protected objects | Domain names | Domain names and IP addresses (public or private IP addresses) |
| Billing mode | Yearly/Monthly and pay-per-use billing | Pay-per-use billing |
| Service editions |
| Edition-agnostic |
| Advantages |
|
|
| Access guide |
Specifications Supported by Each Edition
After selecting an access mode, you need to select a proper service edition based on your service scale. Table 2 lists the service specifications supported by different service editions.
- In cloud mode, the domain name, QPS, and rule expansion package quotas can be shared by the load balancer and CNAME access modes. This is because the same service specifications are provided for the two modes.
- In cloud mode, to protect more domain names and traffic, you can either purchase domain name, QPS, and rule expansion packages or change the edition of your cloud WAF instance. Service edition rankings in terms of performance are as follows: standard, professional, and enterprise, in ascending order.
| Service Scale | Cloud Mode | Cloud Mode (Pay-per-Use) | Dedicated Mode (Pay-per-Use) | ||
|---|---|---|---|---|---|
| Standard | Professional | Enterprise | |||
| Service scale | This edition is suitable for small and medium-sized websites that do not have special security requirements. | This edition is suitable for medium-sized enterprise websites or services that are open to the Internet, focus on data security, and have high security requirements. | This edition is suitable for large and medium-sized enterprise websites that have a large service scale or have customized security requirements. | The mode is recommended if you expect frequent service usage changes. | This mode is suitable for large enterprise websites that have a large service scale and have customized security requirements. |
| Peak rate of normal service requests |
|
|
| WAF-to-Server connections: 6,000 per domain name | The following lists the specifications of a single instance.
NOTE: Maximum QPS values are for your reference only. They may vary depending on your businesses. The real-world QPS is related to the request size and the type and quantity of protection rules you customize. |
| Service bandwidth threshold (origin servers deployed on Huawei Cloud) |
|
|
| 300 Mbit/s | |
| Service bandwidth threshold (origin servers not deployed on Huawei Cloud) |
|
|
| 100 Mbit/s | N/A |
| Number of domain names |
|
|
| 200 | 2,000 |
| Back-to-source IP address quantity (the number of WAF back-to-source IP addresses that can be allowed by a protected domain name) | 20 | 50 | 80 | 20 | N/A |
| Peak rate of CC attack protection | 100,000 QPS | 200,000 QPS | 1,000,000 QPS | 1,000,000 QPS | |
| CC attack protection rules | 20 | 50 | 100 | 200 | 100 |
| Precise protection rules | 20 | 50 | 100 | 200 | 100 |
| Reference table rules | - | 50 | 100 | 200 | 100 |
| IP address blacklist and whitelist rules |
|
|
| 200 | 1,000 |
| Geolocation access control rules | - | 50 | 100 | 200 | 100 |
| Threat intelligence access control rules | - | 20 | 20 | 20 | 20 |
| Web tamper protection rules | 20 | 50 | 100 | 200 | 100 |
| Website anti-crawler protection | - | 50 | 100 | 200 | 100 |
| Information leakage prevention rules | - | 50 | 100 | 200 | 100 |
| Global protection whitelist rules | 1,000 | 1,000 | 1,000 | 2,000 | 1,000 |
| Data masking rules | 20 | 50 | 100 | 200 | 100 |
| How to count protected domain names:
| |||||
Functions Supported by Each Service Edition
After determining the access mode and service edition, you need to consider whether the security functions supported by the selected access mode and service edition meet your service requirements. For details, see Table 3.
Notes:
- √: The function is included in the current edition.
- x: The function is not included in the current edition.
- -: This function is not involved because the similar functions are available in ELB.
| Function | Function Description | Cloud Mode | Dedicated Mode (Pay-per-Use) | ||
|---|---|---|---|---|---|
| Standard | Professional | Enterprise | |||
| Domain expansion packages | One domain package can protect 10 domain names, including a maximum of one top-level domain name. | √ | √ | √ | × |
| QPS expansion packages | A QPS expansion package protects up to:
| √ | √ | √ | × |
| Rule expansion packages | A rule expansion package allows you to configure up to 10 IP address blacklist and whitelist rules. | √ | √ | √ | × |
| Wildcard domain names | Wildcard domain names (for example, *.example.com) can be added to WAF. | √ | √ | √ | √ |
| Protection for ports except 80 and 443 | WAF can protect services on specific non-standard ports in addition to standard ports 80 and 443. | √ | √ | √ | √ |
| Protection for ports except ports 80 and 443 | Non-standard ports can be protected. | × | √ | √ | × |
| Batch configuring defense policies | You can flexibly configure protection policies for protected domain names in batches. | × | √ | √ | √ |
| Applying a protection policy to a domain name | When adding a domain name, you can apply a protection policy to it.
| x (System-generated policy supported only) | √ | √ | √ |
| Batch adding domain names to a policy | Batch adding domain names to a policy | × | √ | √ | √ |
| Common web application attack defense | WAF defends against attacks such as SQL injections, XSS, remote overflow vulnerabilities, file inclusions, Bash vulnerabilities, remote command execution, directory traversal, sensitive file access, and command/code injections. | √ | √ | √ | √ |
| Zero-day vulnerability protection | WAF can update protection rules against zero-day vulnerabilities to the latest on the cloud and deliver virtual patches in a timely manner | √ | √ | √ | × |
| Web shell detection | WAF can protect web applications from web shells. | √ | √ | √ | √ |
| Deep inspection | WAF can identify and block evasion attacks, such as the ones that use homomorphic character obfuscation, command injection with deformed wildcard characters, UTF7, data URI scheme, and other techniques. | √ | √ | √ | √ |
| Header inspection | WAF detects all header fields in the requests. | √ | √ | √ | √ |
| CC attack protection | You can customize a CC attack protection rule to restrict access to your website based on an IP address, cookie, or Referer, mitigating CC attacks. | √ | √ | √ | √ |
| Precise protection | You can configure complex conditions by combining common HTTP fields to match requests precisely. You can log only, allow, or block matched requests. | √ (excluding full detection) | √ | √ | √ |
| Reference table management | You can configure protection metrics for the following types all at once: Paths, User Agent, IP, Params, Cookie, Referer, and Header. | × | √ | √ | √ |
| IP address blacklist and whitelist | You can allow or block specific IP addresses in one click. You can also batch import IP addresses and IP address ranges. | √ | √ | √ | √ |
| Geolocation access control | You can allow or block web requests based on the countries that the requests originate from. | × | √ | √ | √ |
| Web tamper protection | You can lock website pages (such as sensitive pages) to prevent malicious content tampering. | √ | √ | √ | √ |
| Anti-crawler protection | WAF can identify and block crawler behavior such as search engines, scanners, script tools, and other crawlers. | × | √ | √ | √ |
| WAF supports JavaScript-based anti-crawler protection. | × | √ | √ | √ | |
| Information leakage prevention | WAF can prevent leakage of privacy data, such as ID card numbers, phone numbers, and email addresses. | × | √ | √ | √ |
| Global protection whitelist rules | You can configure global protection whitelist to ignore false positives. | √ | √ | √ | √ |
| Data masking | You can configure data masking rules to prevent sensitive data such as passwords from being displayed in event logs. | √ | √ | √ | √ |
| Resource requirement suggestions | When using dedicated instances, you are advised to configure resource monitoring and alarms on Cloud Eye. A CPU usage no greater than 70% and a memory usage no greater than 80% are recommended. NOTE: When there are a large number of service requests or complex user-defined protection policies, the CPU and memory usage increases. In extreme cases, the performance fluctuates greatly. You are advised to evaluate the performance specifications based on the pressure tests made on your service model. | - | N/A | - | √ |
