TR7 Add-ons — specialized capability modules that plug into the bundles.

PREMIUM ADD-ON

Central Management (CM)

Manage multiple TR7 appliances from one console; simplify shared settings, surface device-level differences.

In multi-datacenter, high-availability, or service-provider operations, management complexity grows as the number of TR7 appliances grows. Connecting to each device, renewing certificates one by one, manually syncing WAAP rules, and tracking configuration drift by hand wastes time and amplifies the risk of error.

TR7 Central Management (CM) brings that sprawl into a single console. Common settings are managed as shared; per-device differences are made explicit. Certificate distribution, rule updates, license validation, configuration rollout, audit, and rollback all run inside the same management experience.

The result: multi-TR7 operations move out of manual, repetitive work into a controlled, traceable, standardized management model.

Multiple TR7 appliances. One console. Controlled change.

CM unifies the shared/per-node configuration model, bulk rollout, drift visibility, audit trail, and rollback flow into a single operations layer. The operator sees at a glance which settings are common across all devices and which are device-specific.

MANAGEMENT LAYERS

Four Layers That Simplify Multi-Device Operations

CM is not just a UI that lists devices on one screen. It is the central management layer designed to roll out changes safely, surface differences, log every operation, and roll back when needed across multi-TR7 environments.

Shared / Per-Node Configuration Model

Settings that are identical across all devices are shown as shared; per-device differences are separated out. The operator sees clearly which settings are global and which are exceptions.

  • Shared certificate, license, vService, health check, and WAAP settings managed under one view
  • Settings that differ between devices surface as drift
  • When creating a new setting, it is explicit whether it applies to all devices or selected ones
  • Device-specific exceptions don't get mixed into shared settings
  • Reduces the risk of accidentally pushing a per-device setting to all devices

Bulk Rollout and Fan-Out Management

An operation started from the central console is delivered in parallel to the selected TR7 devices. The result from each device is consolidated into a single report.

  • A single operation can roll out configuration to multiple devices
  • Successful, failed, and partial results reported on one screen
  • Certificate renewal, rule updates, license validation, and policy rollout can run in bulk
  • Manual repetitive work drops; operations complete faster
  • Multi-device changes become more predictable and traceable

Safe Change and Rollback

Critical operations are not pushed across all devices without control. For risky changes, protection, approval, and rollback flow take over.

  • Reduces the risk of a faulty bulk change in critical areas
  • Risky actions can be sent to approval or scoped down
  • Rollback to the previous configuration is supported when a change is wrong
  • Concurrent conflicting operations are kept under control
  • Change processes become safer and more auditable

Audit Trail and Drift Visibility

Every change answers who, when, on which device, with what result. Configuration differences across devices are visible on a single screen.

  • All configuration changes are written to the audit log
  • Which setting differs on which device is visible at a glance
  • Audit data can be forwarded to security teams via SIEM integration
  • A central chain of evidence is produced for audit processes
  • The operator detects differences in a multi-device environment in seconds
ARCHITECTURE

The Native Central Management Layer of the TR7 Platform

CM is not positioned as a separate management product; it operates as the multi-device operational capability of the TR7 platform. The goal is not to add a new layer of complexity, but to simplify the existing TR7 environment under a single management model.

  • A single UI sees every TR7 device as a node
  • New TR7 devices can be brought into central management as nodes
  • Bulk management calls are delivered in parallel to selected devices
  • The shared/per-node configuration model reduces UI complexity
  • Safe-change protections lower the risk of inconsistent configuration
  • The audit trail keeps every change under a who/when/which-node context
  • SIEM integration feeds data into enterprise audit and security processes
USE-CASE SCENARIOS

4 Critical Battlefields Where CM Steps In

CM delivers the most value in environments where multiple TR7 devices must be managed under the same policy, certificate, and configuration discipline.

Certificate rotation — one operation across multiple devices

Scenario

The organization needs to renew a shared wildcard or application certificate on multiple TR7 devices. Connecting to each device individually takes time; if one is forgotten, TLS errors and access outages can follow.

Solution

With CM, the certificate is distributed to the selected nodes in a single operation. Which device succeeded and which returned an error is visible centrally. The audit log shows which device the certificate was applied to and when.

Detecting drift in WAAP rule sets

Scenario

The same WAAP policy is supposed to run across different data centers. But an urgent change may have been applied on one device and not the others. Over time, that gap turns into a security exposure or behavioral inconsistency.

Solution

CM shows the shared rule set in shared view and separates devices that have drifted. The operator immediately sees the drifted device and either aligns it with the shared setting or keeps the difference as a deliberate exception.

Disaster recovery — keeping primary and standby environments aligned

Scenario

The organization runs an active-passive or active-active data center architecture. Changes made in the primary environment must be reflected accurately in the standby. During a DR test, a configuration difference can turn into a traffic problem.

Solution

CM manages primary and standby TR7 devices from a single console. Shared configurations are kept as shared; IP, route, or location-specific exceptions are separated per device. DR scenarios run with more control.

MSP — standardized management of multiple customer environments

Scenario

A service provider or MSP runs TR7 devices for different customers. Connecting to each customer's environment individually and doing certificate and rule work by hand makes operations unscalable.

Solution

With CM, customer devices are managed from one console. Node groups, per-customer separation, audit trail, and safe-change controls standardize MSP operations. Reporting and audit processes share the same data foundation.

CAPACITY OPTIONS

Licensed by Managed Device Count

CM licensing is planned by the number of TR7 devices to be managed centrally. Small deployments cover a few devices, mid-size deployments cover multi-datacenter setups, and large deployments support MSP or multi-region operating models.

Included with the Bundle — No Add-on Needed
2 regions
Included with Enterprise Bundle
TR7 Central Management's 2-region scope is included with Enterprise Bundle; primary and standby data centers can be managed from a single console.

Enterprise Bundle ships a baseline two-region scope as standard. For more devices, more regions, or broader operations, CM add-on tiers take over.

2
Devices
5
Devices
10
Devices
25
Devices
50
Devices
Unlimited
Devices

On the Service Provider Platform License, central management is included natively for multi-tenant operations.

COMPLIANCE

A Strong Layer for Change Management and Audit

CM supports controlled change, recordkeeping, and audit-process evidence in environments with multiple TR7 devices.

GDPR Article 32

Supports technical safeguards — secure change management, access control, and audit logging — for systems that process personal data.

SOX & Financial-System Audit

Contributes to multi-system management, operational control, change traceability, and audit requirements in financial-sector environments.

PCI DSS 4.0.1 Req 6 + Req 10

Supports change management and audit-trail processes; provides a central record of who, when, on which device, made which change.

ISO 27001 Annex A.12 + A.14

Offers an operating model aligned with operational procedures, change control, system security, and auditable management processes.

LICENSING

Premium Add-on — Per Managed Device

CM is available as a Premium add-on for all four TR7 bundles (Base, Geo, Secure, and Enterprise). Enterprise Bundle includes a 2-region scope; for broader multi-device and multi-region operations, capacity tiers apply.

  • Attaches to all four bundles — Base, Geo, Secure, and Enterprise
  • Enterprise Bundle includes a 2-region scope — no extra license needed for baseline DR/HA scenarios
  • Runs on a hardware appliance or a virtual machine
  • On the Service Provider Platform License, central management is included natively
  • Audit, rollback, and SIEM streaming are part of the full scope

Move Multi-TR7 Operations into One Console

Let's model your own environment together in a CM demo: how many TR7 devices to manage, which settings should be shared, which devices keep exceptions, and how certificate and WAAP rule distribution should be centralized.

Licensing Guide