Overview
For technology companies, cloud expansion is no longer a preference — it is a capacity and agility requirement. Yet research consistently points to the weakest link in the move: according to Gartner's prediction, 99% of cloud security failures stem from customer configuration rather than the provider, and the large majority of organizations manage more than one environment at the same time.[1]
This enterprise technology company operated a mature security and delivery layer on the TR7 platform in its data center: fine-tuned WAF rules, application-specific exception lists, load balancing, and SSL/TLS profiles. Its growth plan called for new workloads to launch on Azure and for some existing services to move to the cloud gradually.
The critical question was this: build a separate security stack on the cloud side with native services, or carry the existing protection layer to the cloud? The first option meant translating years of accumulated rules "approximately" to another engine — and the risk of permanent policy drift between the two environments.[2]
The Challenge
Rule Translation Risk
The WAF rule set matured over years could not be translated one-to-one to a different cloud WAF engine; every translation difference carried the risk of either false blocking or a protection gap.
Double Audit Evidence
Two different security products would have required proving the same protection in two separate forms during compliance audits, multiplying audit preparation effort.
Second Tool Learning Curve
The security and infrastructure teams would have had to learn a separate product's configuration language, exception process, and troubleshooting flow for the cloud side.
Time Pressure
The cloud expansion timeline had been set by the business units; standing up the security layer could not be allowed to delay the project schedule.
The Solution
Azure Marketplace Deployment
The TR7 virtual platform was deployed directly in the company's subscription through Azure Marketplace, positioned at the edge of the hub VNet as the single entry point for all inbound traffic.
Policy Import
Existing WAF rules, exception lists, SSL/TLS profiles, and load balancing configuration were imported into the Azure instance without rule translation.
Hybrid Traffic Distribution with GTM
User traffic was routed between the data center and Azure legs based on health and latency; the migration proceeded gradually and reversibly.
Single-Console Management
The TR7 instances on-prem and on Azure were unified in a single management plane; logs, metrics, and event records were collected in one place.
Results
The migration was completed without compromising the security posture and without delaying the project schedule:
Existing WAF and delivery policies ran unchanged on Azure
The same protection level in both environments throughout the migration
Two environments, one console, one set of audit evidence
With Marketplace deployment, the security layer did not delay the project schedule
Trend: Organizations Bring Their Own Security Layer to the Cloud
Starting from scratch with native services during a cloud expansion means abandoning a mature body of rules. More and more organizations move their data-center-proven ADC and WAF platform to the cloud through cloud marketplaces: the same engine, the same policy, one management plane. This approach structurally eliminates policy drift — the most costly problem of the hybrid era.
Customer references available for qualified organizations upon request.
Plan Your Cloud Expansion Without Security Regression
You don't have to rebuild your existing protection and delivery policies when moving to Azure. Talk to our team to see how TR7's Azure Marketplace deployment would work in your hybrid architecture.
Customer references available for qualified organizations upon request.
Request a Demo