Updated on 2026-08-18 GMT+08:00

Checking Dedicated Engine Release History

This topic describes how to manage your dedicated WAF instances (or engines). You can view instance information, view instance monitoring configurations, upgrade the edition of an instance, and delete an instance.

Prerequisites

Dedicated Engine Version Iteration

New dedicated engine versions offer enhanced function reliability across multiple scenarios. You are advised to perform an upgrade. After the upgrade is complete, the dedicated engine is updated to the latest version.

Log in to the WAF console. Choose Assets > Dedicated WAF Engines. On the displayed page, locate the target dedicated engine instance and view the WAF instance version in the Version column.

Table 1 Dedicated WAF versions

Engine Version

Feature

202601

  • Known issues have been fixed.

202512

  • More non-standard HTTP ports are supported.
  • Known issues have been fixed.

202509

  • JS challenges are configured for asynchronous APIs, supporting cross-domain scenarios.
  • The memory usage of dedicated WAF engines has been optimized.
  • Known issues have been fixed.

202507

  • New condition combinations are available in the condition field.
  • More non-standard ports are supported.
  • Known issues have been fixed.

202504.V1

  • Custom fields can be recorded in logs.
  • Inspection conditions can be combined with OR.
  • Known issues have been fixed.

202504

  • The IP threat intelligence database is supported.
  • Advanced JS challenge is supported.
  • Bot protection supports CAPTCHA.
  • JA3 and JA4 fingerprints are supported.
  • Content-Length supports numerical comparison.
  • Known issues have been fixed.

202502

NOTE:

If you want to upgrade your instances to this version, submit a service ticket for consultation.

  • Custom headers can be used as trace IDs.
  • Counting requests to all WAF instances is supported in CC attack protection rules. You need to submit a service ticket to enable this function.
  • Advanced JS challenge is supported.
  • Known issues have been fixed.

202412

  • IPv6 addresses are supported for geolocation access control rules.
  • WAF supports in-house bot mitigation.
  • Custom response headers can be forwarded.
  • Known issues have been fixed.

202410

  • Customizable response headers on the custom block pages
  • Obtaining and processing the TOA field

202408

Known issues have been fixed.

202407

  • In-depth decoding supported in precise protection rules
  • Known issues have been fixed.

202405

  • The health-check API is supported.
  • Cookies can be checked for invalid characters.
  • The Protective Action in CC attack protection rules can be set to JS Challenge.
  • Known feature crawler can be set in the condition list of precise protection rules.
  • When and how to execute a precise rule can be set in the Apply parameter.
  • Requests for only error response codes 4xx and 5xx can be logged. Function parameter: upstream.extend.only_log_abnormal_status.
  • In dedicated mode, the default values of X-Real-IP and X-Hwwaf-Real-IP are returned from $client_ip instead of $remote_addr.

202312

  • A global protection whitelist rule can be set to ignore invalid requests.
  • JavaScript-based anti-crawler rules support more protective actions, including Block, Log only, and Verification code.

202308

  • The $remote_addr field is added to the IP identifier, which can be directly set to the IP address of the TCP connection.
  • IP addresses used in TCP connections can be identified by CC, precise protection, blacklist, and whitelist rules.
  • A block duration can be set if Protective Action is set to Verification code in a CC attack protection rule.

202305

  • HTTP2 is enabled globally by default. There is no need to enable it manually.
  • By default, a request can pass through WAF four times before it goes to the origin server. Error code 523 will be returned if the request exceeds this limit.
  • Strict multipart format verification is supported.
  • Dedicated ELB network load balancers are supported. (In earlier versions, only shared load balancers and dedicated application load balancers are supported.)

202211

  • Built-in tags can be added to attack logs (hit_data) when built-in rules are hit.
  • Destination rate limiting and response code conditions can be configured in CC attack protection rules.

202209

  • TLS v1.3 is supported.
  • Protection for on-premises web servers is supported.
  • Cloud Eye can be used to monitor WAF.
  • More types of statistics are added to heartbeat logs for attacks.
  • HTTPS ports 60700 to 60999 (300 ports) are added to the protection port list.

202207

  • The wildcard domain name matching logic is supported.
  • The global protection whitelist is supported.

202205

Configuring the earliest TLS version based on instances is supported.

202204

  • Rules can be updated and delivered from the management plane.
  • False alarm masking rules can work for all domain names and specified domain names.
  • All conditions can be configured for false alarm masking.

202202

The request logging methods are optimized.

202201

Some regular expression matching rules are optimized.

202111

  • The log only mode is supported for information leakage rules.
  • Attack logs of invalid requests are added.
  • Precise protection rules can work to each IP address (only for IPv4 format) in the XFF request header.
  • Timeout duration can be set for specified domain names.
  • Some functions are optimized.

202110

The performance of some functions is improved.

202109

  • Precise protection rules can work to the request body field.
  • Precise protection rules support regular expression matching and all subfields.
  • Some logs can be interconnected with LTS.

202106

  • The HTTPS port supports HTTP/2.
  • The region ID field is added to access logs.
  • The region ID field and engine IP address are added to attack logs.