Browse all TR7 features
Every capability across ADC, WAAP, AAM, GTM, and ZeroLeak.
Filter by product, add-on, or industry — a technical deep-dive reference for engineering and operations teams.
Subscribe via RSSLoad Balancing Algorithms
Classical, consistent hash, Maglev, SED, and TR7's proprietary two-stage Fastest+ engine. Picked per vService, hot-swapped.
Served Bandwidth Model
Bandwidth is measured at the vService client-facing boundary as combined RX and TX. Pre-vService blocks and application-server pass-through do not count — license the tier you actually need.
Session Affinity
9 ways to keep a user on the same backend across requests — from source-IP to SAM, TR7's configurable cookie engine.
Anti-OCR Protection
Server-rendered pages with pixel-level modifications — readable on screen for the user, nonsense to OCR engines and AI vision models when extracted as an image.
Remote Browser Isolation
Run the protected app inside a fully isolated session on the platform — the user sees only the rendered pixels. No HTML, no JavaScript, no cookies on the endpoint.
Text Cipher
Letters on the page are silently swapped with visually-similar siblings; the area around the cursor reveals the originals. The human reads naturally — an AI fed a screenshot reads different words.
Forensic Watermark
A visible per-user watermark plus an invisible trace ID embedded into the pixels — when a screenshot leaks, the source can be identified even after cropping, scaling, or being photographed.
Browser Context Isolation
Every user session runs in its own isolated browser context — no shared cookies, storage, or process state — with a strict domain allowlist and rendering-level anti-automation defences built in.
Session Recording & Audit
Event-driven screenshots at consequential moments, continuous FFmpeg video, word-level keystroke buffer and clipboard logging — every session reconstructable for compliance and investigation.
SSL VPN and IKEv2
Manage VPN access as part of the AAM identity and device trust policy — not as a separate network exception.
Clientless Application Portal
Browser-only access to RDP, VNC, SSH, Kubernetes and legacy systems — with credential vault, recording, and watermark built in.
Multi-Factor Authentication
Three MFA methods, per-service policy, trusted-device shortcut — no third-party MFA cloud.
Conditional Access Policy Engine
One flow engine decides every authentication outcome — who can reach what, after which factor, under which context.
Continuous Trust Evaluation
Trust earned at login doesn't carry forever. Every session stays under evaluation, every step of the way.
SAML 2.0 Identity Federation
Standards-correct SAML SP — enterprise IdPs, public-sector federation, and per-tenant routing, all coordinated with MFA, conditional access, and posture.
OIDC / OAuth 2.0 Federation
Standards-correct OIDC relying party — authorization code with PKCE, JWKS-verified ID tokens, nonce + state defenses, and per-tenant IdP routing.
LDAP/AD Bind
Your enterprise directory already exists — TR7 AAM does not copy it, it connects to it and turns group membership into access policy.
Additional Identity Provider Integrations
Connect every identity source beyond SAML and OIDC to the same access and audit flow.
Fastest+ Routing
Two-stage live signal — among the lowest-response-time candidates, pick the one with the emptiest queue.
Built-in Network Diagnostics
Diagnose network, DNS, TLS and packet-level issues in production — without opening a shell.
Connection Multiplexing
Carry client traffic to backends without mirroring every connection — fewer handshakes, lower latency.
Cookie Security Flags
Complete missing HttpOnly, Secure and SameSite flags at the response layer — no application changes required.
CORS Policy Rule
Manage preflight and response CORS headers from a single rule, without touching application code.
Hot Config Reload (Zero-Downtime)
Change the config, keep live connections — not every rule update should require a maintenance window.
HTTP Redirect Rules
Manage HTTP→HTTPS transitions, domain migrations, path moves and error redirects without touching application code.
Inline TLS Backend Inspection
WAAP inspection, mTLS identity and data masking keep working even as traffic flows to backends over TLS.
IP Masking and Normalization
Mask IP for log privacy, reconstruct the correct client IP across proxy chains.
Native IPFIX / NetFlow Export
Move beyond L3/L4 — carry HTTP context into your flow records.
JSON Path Operations
Turn JSON body fields and JWT content into first-class signals for every traffic decision.
Native Prometheus + Grafana Integration
Pull Prometheus metrics from TR7 without deploying a separate exporter — dashboards ready out of the box.
Per-vService Traffic Shaping and QoS
Apply per-vService, per-user or shared bandwidth limits and distribute traffic capacity in a controlled way at the application layer.
Response Body Modification
Mask, replace or inject HTML into response content — without changing a line of backend code.
Traffic Quarantine
Observe behavior instead of blocking instantly — isolate sources that exceed a threshold and release them automatically.
URL and Path Rewriting
Change the path, not the backend — the client keeps its URL while a new architecture runs inside.
Traffic Rules Engine
Write rules visually, get compiled traffic behavior — manage request and response flow without scripting.
FX Expression and Variable Engine
One expression language — traffic, health, logging, GTM, security and access decisions in the same model.
Live Traffic Tracking
See production traffic request by request — turn observation directly into rule actions.
L7 Traffic Analytics & Reporting
30+ breakdown dimensions, three formats (PDF / XLSX / HTML), up to 10 years of on-device history — no separate management server.
WAAP Attack Reporting
3000+ rules, OWASP / API Top 10 / CWE taxonomy, 14 correlation axes, per-host-group + cross-group rollups.
Scheduled Report Delivery
vService profiles, 5 frequency presets, multi-recipient email, cluster-aware single-send — same engine for ad-hoc and scheduled.
Cookie Encryption Rule
Hide cookie values from the client — protect session integrity without touching backend code.
HA Clustering
Run two nodes as a single logical ADC — VIP failover, state replication and controlled maintenance in one cluster model.
VIP and IP Scenarios
Manage VIPs not just as IP addresses — but with interface type, VLAN, cluster role and transition method.
Content-Aware Rules
Move beyond headers — make body content part of the traffic and security decision.
SSL/TLS Acceleration
Move TLS beyond file-based configuration — turn it into a per-service security profile, certificate lifecycle and post-quantum readiness layer.
TLS / mTLS Client-Cert Authentication
Lift the client certificate out of connection control and turn it into an identity object that drives traffic decisions.
Deployment Topology Modes
Insert TR7 ADC into the traffic path without touching backend IP addresses, gateways or routes.
Multi-Namespace Architecture and Cross-NS Routing
Connect services without merging networks — manage overlapping IP plans and tenant isolation with a single vService model.
Active Health Monitoring
Go beyond 200 OK — validate backends at protocol, session and content level.
Response Caching
Serve frequent responses without a backend round-trip — reduce latency and free capacity.
FTP Security Proxy
Manage FTP not as an open port, but as a command-by-command controlled secure file transfer session.
NTP Service
From upstream NTP pools to internal infrastructure — centralized, controlled and isolated time delivery.
Route Table Management
Every tenant in its own routing world — overlapping IPs, static + dynamic routing and gateway monitoring from one panel.
Dynamic Interface Management
No reboot. No maintenance window. Interface changes go live.
Built-In Firewall
ADC, routing and L3/L4 security from a single console.
ACME Cert Renewal
Certificate renewal stops being a calendar task — TR7 ADC monitors, renews and applies the certificate to the service.
Virtual Hosts
One VIP, one port — unlimited domain separation via SNI and Host header.
WAAP Signature & Scoring
Combine signature, score and context in a single engine — manage known attacks with confidence.
Self-Hosted CAPTCHA
Generation, delivery and verification — all inside the ADC. Zero calls to any third-party cloud service.
Adaptive DDoS Learning
Replace static thresholds with service-aware DDoS protection that learns traffic behaviour and acts on conditions.
Sensitive Data Masking
Mask sensitive data at platform level before it reaches the user or the logs.
Account Takeover Protection
Stop credential stuffing, brute-force and session hijacking attempts based on combined risk decision — not a single signal.
API Discovery & Schema
Extract an API inventory from real traffic; bring requests outside the allowed schema under control.
Waiting Room
The queue lives on the platform, not in your application — and the capacity is found before the event, not during it.
Rate Limiting
One IP, one account, one API key — you decide which dimension to limit.
Custom WAAP Rules
Add your own WAAP logic alongside the built-in signature set — same scoring engine, same logs, same policy pipeline.
Geo/ASN Access Control
Turn country and ASN context into access decisions — without dependency on external services.
IP Reputation Feeds
TR7's central feed, external URL lists and your own exceptions converge in a single IP reputation engine.
Login Attack Protection
Three tiers of graduated friction — warn, challenge, lock — across IP, username, or both. Self-hosted CAPTCHA, no external cloud.
Session Protection
From session ID generation to cookie security, IP+UA binding to idle and absolute timeout — protect every session under one policy graph.
SIEM Log Streaming
Send every platform event to your SIEM in the format it expects — JSON, CEF or plainText.
Syslog Forwarding Proxy
Collect, classify, replicate and forward UDP and TCP syslog traffic in front of your SIEM.
DNS Firewall & Application Delivery Controller
Accelerate enterprise DNS traffic and block malicious queries — in a single layer.
On-Prem GSLB
Make DNS and GSLB decisions on your own appliances — zone data and traffic policy never leave your premises.
DNS Geographic Routing
Set resolver IP aside — make DNS decisions based on the user's real subnet, ASN and location.
DC Failover
When the primary DC goes down, DNS reshapes automatically — no manual intervention needed.
Weighted DNS
Percentage-based traffic distribution — in the language of DNS.
Health Check Scenarios
Take DNS responses beyond static records — let data-centre, application and service health drive every decision.
Express Zone Acceleration
Authoritative DNS pulled from a hidden master, served from memory at line rate.
Bidirectional HC Scenarios
The path into failover and the path back are separately policy-controlled.
Multi-Source DC Selection
Decide which data center wins each query — using host, service, and client-side signals together.
WAN/LAN Dual-Path Monitoring
Each data center's WAN and LAN access paths are monitored independently — partial reachability is a recognized state, not a binary.
On-Prem DNSSEC
Per-domain DNSSEC with key custody on your own infrastructure — no third-party signing service.
Interactive PTY CLI
Full interactive console from the browser with no SSH wait — production-safe with RBAC and audit.
RBAC and Administrative Roles
Sixteen roles, scoped per user — and the same permission model in the interface, the CLI and the API.
Central Management
Manage N TR7 appliances from one console — share common settings, see differences per device.
ETM Device Trust → AAM Access
The AAM-integrated pillar of the ETM add-on: device posture becomes a live signal in the access decision.
Continuous Device Telemetry
Know the device not by a few fields at VPN connection time, but continuously and in depth throughout the session.
Remote Actions and Live Query
Don't just observe the device; send commands, query state, isolate when needed — all under one console.
Mobile Device Management (MDM)
Manage Android and iOS devices from the same console as your desktop estate; no separate MDM platform required.
Server Telemetry and Routing Intelligence
The same ETM agent runs on servers; CPU, RAM, IO, and process health flow directly into ADC routing decisions.
ETM Server Integrity and Deployment Intelligence
An ADC that doesn't know its servers' files runs a blind operator.
L4 DDoS Attack Coverage
Packet-level filtering against SYN/UDP/ICMP flood, amplification, and fragment attacks — with operator-confirmed adaptive baseline.
L7 DDoS Attack Coverage
Per-vService behavioral protection against HTTP flood, Slowloris, R.U.D.Y., and bot attacks — with ddosCond combined conditions.
vTenant Virtualization
One TR7. Many tenants. Resources, network and operations boundaries each kept separate.
Layer 7 Reporting Add-on
Make every L7 request measurable, filterable and reportable.
Advanced PDF Reporting
Produce branded, scheduled and on-demand PDF/XLSX reports in a single reporting pipeline.
Process Monitoring
Every process runs in its own profile — resource limits, restart and visibility built into the platform.
Recovery Mode — Lockout-Free Operations
Controlled emergency access from the appliance console — recover the admin login without re-imaging.
L4 Modes
TCP, UDP, DSR and IP tunnel — packet-level L4 load balancing on a single ADC.
Three Service Types
Pick the service type and TR7 shows only the right features — backend groups managed in the same model.
UDP Load Balancing
Manage DNS, RADIUS, SIP and NTP services with production-grade L4 load balancing, session affinity and health checks.
CA Management
Your own root, server CA and device CA — issue, enrol, revoke and track certificates inside TR7.
Smart ACL Conditions
Not just an IP list — real traffic intelligence across 60+ criteria, AND/OR/NOT groups and Smart Function chains.
Timeout Profiles
Not just one idle value — 9 independent timeout axes in a single named profile, applied per pool to match every traffic type.
Pool Connection Limits
Encode backend capacity across 8 axes — connections, rate, session, SSL, buffer and retry in one profile.
Virtual Patching
Close a vulnerability at the traffic layer in minutes — no code change required.
GraphQL Deep Inspection
Do not treat GraphQL traffic as a plain POST body — catch introspection, nested DoS and query batching patterns inside your WAAP.
Client-Side Script Protection
Apply 8 security headers at the ADC layer without touching application code.
WAAP Compliance Reporting
Turn raw WAAP logs into readable evidence reports for auditors, management and customers.
Block Page Customization
Replace the generic 'access denied' screen with a controlled, branded experience that carries your message, language and reason code.
Custom Login Page Templates
Branded login UX per gateway with centrally-managed shared templates. A separate template for every brand, tenant or application; no separate web server.
Backend SSO
Modern auth at the front, identity injected downstream as header, Authorization, or cookie — legacy apps stay legacy.
Password Lifecycle
Change, forgot, and reset flows on one engine — single-use tokens, recipient masking, audit on every step.
Proximity-Based DNS Routing
Steer every query to the closest data center — geographic proximity as a latency proxy, decided on-device.
DNS Record Management
35 record types, DNSSEC and AXFR — the GSLB decision engine paired with full DNS operations on one platform.
GTM Triggers and Forwarders
GTM does more than produce DNS answers — when health state changes it fires external triggers and routes DNS queries to the right forwarder.
Notification System
Get every event to the right person, on the right channel, with the right context.