Help Center/ Web Application Firewall/ FAQs/ About Purchase and Specifications Changes/ What Are the Impacts When QPS Exceeds the Allowed Peak Rate?
Updated on 2026-08-18 GMT+08:00

What Are the Impacts When QPS Exceeds the Allowed Peak Rate?

Queries Per Second (QPS) is the number of HTTP/HTTPS requests that WAF can successfully process and analyze per second. It is a key indicator of WAF performance and processing capability. If the peak traffic of your website exceeds the QPS allowed by the selected WAF edition, WAF will be unable to protect the excess traffic. This may cause cascading problems.

Impact of Different Access Modes

  • Cloud CNAME access

    WAF will trigger traffic limiting or random packet loss by intercepting excessive requests. The purpose is to prevent itself from crashing.

    You can check the request time and response time in WAF logs to check whether traffic limiting or random packet loss occurs. If the request time increases significantly, traffic limiting may be the cause. If the request time is normal but the request is marked as failed or timed out, packet loss may be the cause.

  • Cloud load balancer access

    If automatic bypass occurs, requests that exceed the QPS will bypass WAF and directly reach the backend server. As a result, these requests are not protected by WAF (for example, SQL injection and XSS attacks cannot be blocked).

In conclusion, no matter which mode is used, normal services are affected. Specifically, services are unavailable (some users cannot access the services), frame freezing occurs (request processing is slow), and delay occurs (the response time is long). All these significantly affect user experience and service stability.

QPS Specifications Supported by Each Edition

Table 1 lists the QPS specifications supported by each WAF edition.

Table 1 QPS specifications supported by WAF

Edition

Peak Rate of Normal Service Requests

Peak Rate of CC Attack Defense

Standard

2,000 QPS

100,000 QPS

Professional

5,000 QPS

200,000 QPS

Enterprise

10,000 QPS

1,000,000 QPS

Dedicated mode

Specifications of single instance:

  • Specifications: WI-500. Estimated performance:
    • HTTP services: 5,000 QPS (recommended)
    • HTTPS services: 4,000 QPS (recommended)
    • WebSocket service - Maximum concurrent connections: 5,000
    • Maximum WAF-to-server persistent connections: 60,000
  • Specifications: WI-100. Estimated performance:
    • HTTP services: 1,000 QPS (recommended)
    • HTTPS services: 800 QPS (recommended)
    • WebSocket service - Maximum concurrent connections: 1,000
    • Maximum WAF-to-server persistent connections: 60,000
  • Specifications: WI-500. Estimated performance:

    Throughput: 500 Mbit/s

  • Specifications: WI-100. Estimated performance:

    Throughput: 100 Mbit/s

For details, see Edition Differences.