You Don't Have to Rebuild Your Security Layer When Moving to the Cloud
Cloud migration stalls on the same question in most organizations: "Do we have to rebuild in Azure the security and delivery layer we spent years maturing in the data center?" With native cloud services, the answer is usually "yes" — rule sets get rewritten, teams learn a new tool, exception lists are built from scratch, and policy drift between the two environments starts on day one.
TR7's arrival on Azure Marketplace changes that equation. The same software that runs on your TR7 hardware or virtual appliances in the data center now spins up in your Azure subscription in minutes: the same WAF engine, the same policy language, the same management interface. Your load balancing algorithms, SSL/TLS profiles, custom WAF rules, and access policies move to Azure without rule translation.
This post covers three things: what the Marketplace deployment delivers in practice, where TR7 fits in your Azure architecture, and which license model suits which scenario.
Why Bring Your Own ADC and WAF to Azure?
Azure offers native services for basic load balancing and signature-based web protection. So why do organizations bring their own application delivery platforms to the cloud? Four reasons stand out:
Policy Consistency
WAF rules tested and matured in the data center run line-for-line the same on Azure. No rule translation, no behavioral differences, no two separate exception lists. You present a single evidence set at audit.
Depth Beyond Native Services
Capabilities such as advanced bot management, behavioral DDoS learning, sensitive data masking, virtual patching, and forensic logging require an enterprise-grade platform. The gap left by basic services is exactly where attackers operate.
Portability
TR7 licenses are tied to the organization, not the platform. They move with your workload across Azure, GCP, VMware, or any supported hypervisor; there is no cloud lock-in.
Single Management Plane
All TR7 instances, on-prem and on Azure, are managed from a single console; logs, metrics, and event records are collected in one place. You don't build a separate monitoring and reporting setup for the cloud side.
Deployment and License Models
The TR7 image on Azure Marketplace is available under two license models, with a third hybrid path for existing hardware customers:
| Model | Best-Fit Scenario | Payment |
|---|---|---|
| PAYG (billed through Azure) | Quick starts, variable workloads, PoCs and short-term projects | Hourly, no upfront commitment |
| Fixed-Term BYOL | Planned production workloads, predictable capacity | Fixed-term license; portable to Azure and other platforms |
| Hybrid (hardware + Azure) | Gradual cloud expansion, disaster recovery, burst capacity | Existing hardware license + cloud instance |
Where Does TR7 Fit in Your Azure Architecture?
The most common placement is at the edge of the hub VNet in a hub-spoke topology. TR7 is positioned as the single entry point for all inbound traffic: SSL/TLS termination, WAF inspection, bot management, and load balancing are applied in a single pass, and the cleaned traffic is distributed to workloads in the spoke VNets. AKS clusters, App Service applications, and VM scale sets are defined as backend pools — TR7's layer 7 routing, session affinity, and health monitoring capabilities work in front of these services exactly as they do elsewhere.
For high availability, TR7 instances are clustered active-active across availability zones. If a zone is lost, traffic fails over seamlessly to the instance in the healthy zone; configuration and session state are synchronized within the cluster.
In the hybrid scenario, TR7 GTM comes into play over an ExpressRoute or VPN connection between the data center and Azure: user traffic is routed between the on-prem and Azure legs based on geography, latency, or data center health. This is also the backbone of a gradual migration — Azure first as a passive/DR leg, then active-active deployment, and eventually full cloud if you choose.
Going Live in Five Steps
Choose Your Plan on the Marketplace
Search for TR7 on Azure Marketplace; select the PAYG or BYOL plan and deploy it to your subscription.
Define Network and Size
Choose the VNet, subnet, and public IP configuration; select an instance size that matches your expected traffic profile.
Activate the License
In the first-boot wizard, activation is automatic for PAYG; for BYOL, activate with your license key.
Import Your Policies
Import your existing TR7 configuration, WAF rules, and certificates; define the backend pools.
Shift Traffic Gradually
Send a portion of traffic to the Azure leg via DNS or GTM; increase the share after validation.
Existing TR7 virtual platform licenses can be moved to Azure at no additional cost. You can start with PAYG and switch to BYOL after validation; the license follows your workload between Azure and other supported platforms. In capacity planning, hardware and cloud instances are managed as a single inventory.
Try TR7 on Azure
Bring the protection and delivery policies from your data center to Azure on the same engine. Explore the capabilities of the TR7 virtual platform, or ask our team for a tailored demo for your Azure deployment.
Explore the TR7 Virtual Platform