Updated on 2025-07-04 GMT+08:00

WAF Specifications

Description

The dedicated WAF supports two specifications: WI-500 and WI-100. The following table lists the applicable service scales.

Table 1 Applicable service scales

Service Scale

Dedicated Mode

Peak rate of normal service requests

Specifications of a single instance:

  • Specifications: WI-500. Referenced performance:
    • HTTP services: 5,000 QPS (recommended)
    • HTTPS services: 4,000 QPS (recommended)
    • WebSocket service - Maximum concurrent connections: 5,000
    • Maximum WAF-to-server persistent connections: 60,000
  • Specifications: WI-100. Referenced performance:
    • HTTP services: 1,000 QPS (recommended)
    • HTTPS services: 800 QPS (recommended)
    • WebSocket service - Maximum concurrent connections: 1,000
    • Maximum WAF-to-server persistent connections: 60,000

Number of domain names

2,000

Back-to-source IP address quantity (the number of WAF IP addresses that can be allowed by a protected domain name)

-

Quantity of supported ports

  • Standard ports: two (80 and 443)
  • Non-standard ports: You can use as many ports as you want as long as the port is supported by WAF. For details, see Ports Supported by WAF.

Peak rate of CC attack protection

  • Specifications: WI-500. Referenced performance:

    Maximum QPS: 20,000

  • Specifications: WI-100. Referenced performance:

    Maximum QPS: 4,000

CC attack prevention rules

100

Precise protection rules

100

Reference table rules

100

IP address blacklist and whitelist rules

1,000

Geolocation access control rules

100

Web tamper protection rules

100

Information leakage prevention rules

100

Number of global protection whitelist (formerly false alarm masking) rules

1,000

Data masking rules

100

Security report templates

20