Updated on 2025-07-04 GMT+08:00

WAF Modes

Description

Deployment architecture

Differences Between the Cloud and Dedicated Modes

Table 1 WAF modes description

Project

Cloud Mode

Dedicated Mode

CNAME Access

ELB Access

Billing mode

  • Yearly/Monthly
  • Pay-per-use
NOTE:

If you are using cloud WAF, you can change the billing mode between yearly/monthly and pay-per-use.

In WAF cloud mode, you can connect domain names to WAF in either CNAME access mode or load balancer access mode. If you buy the standard, professional, or enterprise edition WAF, the domain name, QPS, and rule expansion packages are shared among the two access modes.

Pay-per-use

Service editions

The following editions support the yearly/monthly billing mode:

  • Standard
  • Professional
  • Enterprise

-

-

Application scenarios

Service servers are deployed on any cloud or in on-premises data centers.

The application scenarios for different editions are as follows:

  • Standard

    This edition is suitable for small and medium-sized websites that do not have special security requirements.

  • Professional

    This edition is suitable for medium-sized enterprise websites or services that are open to the Internet, focus on data security, and have high security requirements.

  • Enterprise

    This edition is suitable for large and medium-sized enterprise websites that have a large service scale or have customized security requirements.

Service servers are deployed on Huawei Cloud.

This mode suitable for large enterprise websites having high security requirements on service stability.

Service servers are deployed on Huawei Cloud.

This mode is suitable for large enterprise websites that have a large service scale and have customized security requirements.

Protected objects

Domain names

  • Domain names
  • IP addresses
  • Domain names
  • IP addresses

Advantages

  • Protection capability scaling by upgrading specifications
  • Protection for cloud and on-premises web services
  • IPv6 protection
  • Scaling out of WAF protection capabilities without changing your service architecture
  • Non-inline deployment of WAF instances and zero impact on your website services
  • High reliability.

    Should a WAF instance become faulty, the load balancer directly distributes website traffic over the origin servers, eliminating adverse impact incurred such on customer's normal business.

  • Flexible deployment
  • Exclusive use of WAF instances
  • Protection against large-scale traffic attacks
  • Low network latency with dedicated WAF instances being deployed in a VPC
Table 2 WAF modes description

Project

Cloud Mode

Dedicated Mode

Billing mode

  • Yearly/Monthly
  • Pay-per-use

Pay-per-use

Service editions

The following editions support the yearly/monthly billing mode:

  • Standard
  • Professional
  • Enterprise

-

Application scenarios

Service servers are deployed on a cloud or in on-premises data centers.

The application scenarios for different editions are as follows:

  • Standard

    This edition is suitable for small and medium-sized websites that do not have special security requirements.

  • Professional

    This edition is suitable for medium-sized enterprise websites or services that are open to the Internet, focus on data security, and have high security requirements.

  • Enterprise

    This edition is suitable for large and medium-sized enterprise websites that have a large service scale or have customized security requirements.

Service servers are deployed on the cloud.

This mode is suitable for large enterprise websites that have a large service scale and have customized security requirements.

Protected objects

Domain names

  • Domain names
  • IP addresses (public or private IP addresses)

Advantages

  • Protection capability scaling by upgrading specifications
  • Protection for on- and off-cloud web services
  • IPv6 protection
  • Flexible deployment
  • Exclusive use of WAF instances
  • Protection against large-scale traffic attacks
  • Low network latency with dedicated WAF instances being deployed in a VPC