Skip to main content

TR7 Cloud: the same platform, deployed from the marketplaces of the major public clouds.

CLOUD · MICROSOFT AZURE

TR7 on Microsoft Azure Marketplace

The application delivery and security platform you run in your data center, now one click away in your Azure subscription.

Organizations moving workloads to Azure can deploy the TR7 Enterprise Application Delivery and Security Platform directly from Microsoft Azure Marketplace, with the same engine, the same policy model and the same management interface they use on premises.

Existing WAF rules, load balancing configurations, TLS profiles and access policies carry over without rule translation. Your security posture stays consistent across data center and cloud, and billing runs through the Azure subscription you already have.

Same platform. Same policies. Now on Azure.

Transactable virtual machine offer, licensed by throughput tier, billed hourly through Azure, with a 30-day free trial to prove it in your own environment.

WHY TR7 ON AZURE

Bring Your Own Delivery and Security Layer Instead of Rebuilding It

Azure ships basic load balancing and signature-based web protection. Enterprises still bring their own application delivery platform to the cloud, for three reasons.

Policy Consistency

WAF rules matured in your data center run line-for-line the same on Azure. No rule translation, no behavioral drift, no second exception list.

  • Import existing configurations, certificates and WAF policies as-is
  • One rule language, one exception process across on-prem and cloud
  • One evidence set for PCI DSS, ISO 27001 and sector audits

Depth Beyond Built-in Services

Bot management, adaptive DDoS learning, sensitive data masking, virtual patching, API discovery and forensic logging need an enterprise-class engine, not a checkbox.

  • Signature and adaptive-learning WAAP with anomaly scoring
  • L4 and L7 DDoS protection built into the same appliance
  • Application Access Management with SSO, MFA, SAML and OIDC

Single Management Plane

On-prem and Azure instances are managed from one console. Logs, metrics and events land in one place; the cloud side does not need its own monitoring stack.

  • Same web console and CLI on hardware, virtual and Azure
  • HA clustering with automatic VIP failover inside Azure
  • GTM steers traffic between data center and Azure for phased migration
OFFERS AND PLANS

Pick the Bundle, Then Pick the Throughput

TR7 is published on Azure Marketplace as one offer per bundle. Under each offer, plans are throughput tiers, the same tier ladder as our virtual appliances. Offer = which products; plan = how much traffic.

OfferModules includedBest for
TR7 EnterpriseADC + WAAP + AAM + GTMEnd-to-end delivery and security, multi-region
TR7 SecureADC + WAAP + AAMProtected delivery with identity-based access
TR7 GeoAccessADC + AAM + GTMIdentity-aware delivery across regions
TR7 GeoADC + GTMMulti-region routing and failover
TR7 BaseADC + AAMApplication delivery and access, single region

Throughput plans under every offer

Each plan caps total appliance throughput. Pick the tier that matches the workload; the appliance enforces the tier automatically after deployment.

50 Mbps
200 Mbps
500 Mbps
1 Gbps
5 Gbps
10 Gbps

An Azure VM's plan is fixed at creation time. To move to a higher tier or a different offer, deploy a new VM on the target plan and restore your configuration from backup, it takes minutes, and the cloud team can walk you through it.

LICENSING ON AZURE

Pay-as-you-go, Billed Through Azure

No procurement cycle, no separate invoice. TR7 is metered hourly and appears on your Azure bill under standard Marketplace terms.

  • Hourly pay-as-you-go pricing, licensed by throughput tier
  • 30-day free trial on every plan: full feature set, cancel any time
  • Microsoft Standard Contract; privacy policy and terms linked on the listing
  • Eligible for Azure Marketplace procurement workflows and consolidated billing
  • Existing TR7 customers keep the same management model, support entitlement and upgrade path

Need enterprise terms?

For committed volumes, custom throughput tiers or multi-year agreements, TR7 issues an Azure Marketplace Private Offer to your subscription, same deployment path, negotiated terms.

ARCHITECTURE

Where TR7 Sits in Your Azure Network

TR7 deploys as a virtual machine in your own VNet. It terminates client traffic on the external side, applies delivery and security policy in one pass, and forwards clean traffic to backends in the same VNet, peered VNets or on premises over ExpressRoute or VPN.

Reference topology: hub VNet with three interface roles

Clients / InternetPublic IP → VIPAzure VNetManagement subnetOperator / Central ManagementHTTPS 443 · SSHExternal subnetTR7 applianceADC · WAAP · AAM · GTMTR7 peer (HA)VRRP · VIP failoverSync subnetInternal subnetBackend poolsAKS · App Service · VM scale setsOn-prem via ExpressRoute / VPN
External
Faces clients and the internet. Hosts the service IPs (VIPs). Optionally carries an Azure Public IP.
Internal
Faces the backend servers. Health checks, connection pooling and backend TLS run here.
Management
Created at deployment. The interface you log in through; its Azure private IP is set once and never changes.
Sync (HA only)
A dedicated subnet between the two cluster members for configuration and state synchronization.
  • Three roles are an example, not a requirement, a single interface with multiple IPs works too
  • The one rule: every IP a TR7 interface uses must exist on the Azure NIC and on the TR7 interface
  • Each extra interface gets its own TR7 route table; the Azure gateway is always the subnet's first host address (.1)
  • HA pair spans availability zones; the VIP moves automatically via the Azure Resource Manager API
  • Failover needs only Reader + Network Contributor on the resource group, granted to the VM's managed identity
  • Hybrid: TR7 GTM steers users between data center and Azure by health, geography or latency
DEPLOYMENT GUIDES

From Marketplace to Production, Step by Step

Four guides cover the full path: deploy the VM, lay out the interfaces, build the HA cluster, and create the floating VIP. Every step names the exact portal or TR7 menu you touch.

  1. 1
    Azure portal

    Find the offer

    In Azure Marketplace, search for TR7 and open the offer you want (for example TR7 Secure).

  2. 2
    Azure portal

    Select the plan

    Choose the throughput plan and click Create.

  3. 3
    Azure portal

    Basics tab

    Choose subscription, resource group, region, VM name and size as you prefer.

    Authentication type must be Password. SSH-key authentication is not supported by the TR7 image.

  4. 4
    Azure portal

    Disks tab

    Leave OS disk size at Image default; other settings are up to you.

  5. 5
    Azure portal

    Networking tab

    Pick the VNet, subnet and public IP that match your network design. This becomes the management interface.

  6. 6
    Azure portal

    Management tab

    Configure monitoring and backup as you wish.

    If you will build an HA cluster, enable Enable system assigned managed identity under Identity. Failover cannot move the VIP without it.

  7. 7
    Azure portal

    Monitoring, Advanced, Tags

    No TR7-specific requirements, choose according to your own standards.

  8. 8
    Azure portal

    Review + create

    Run the final validation and create the VM. Log in through the management interface once it boots.

  • The management interface is the single interface the VM starts with. Its Azure private IP appears automatically in TR7 under Network > Interfaces and is never edited by hand.
  • For clusters continue with the HA guide below; for a single appliance continue with the interface layout guide.
DOCUMENTATION

Want to Go Deeper? The Full Documentation Is Here.

Every TR7 feature used in these guides, from interfaces and route tables to HA clustering, vServices, WAF policy and GTM, is documented in detail in the TR7 technical documentation. Use it alongside the guides above when you configure your deployment.

docs.tr7.com · deployment methods, settings, WAF, GTM, FAQs

FAQ

Questions Teams Ask Before Deploying on Azure

Yes. The Marketplace image runs the same TR7 release as our hardware and virtual appliances. Configuration backups, WAF policies, certificates and access policies import without changes, and the same web console and CLI are used.

CONTACT THE CLOUD TEAM

Planning an Azure Deployment? Talk to the Engineers Who Built It.

The TR7 cloud team reviews your architecture, sizes the right plan, and stays with you through deployment, HA setup and cut-over. Send us your questions, technical or commercial.

  • Architecture review for hub-spoke, AKS, App Service and hybrid designs
  • Plan sizing and Private Offer preparation
  • Guided HA cluster and VIP failover setup
  • Migration planning from on-prem TR7 or third-party ADC/WAF

Messages are sent through your verified TR7 account and reach the cloud engineering team directly. Typical response time is one business day.