TR7 Add-ons — specialized capability modules that plug into the bundles.

PREMIUM ADD-ON

L4 DDoS Protection

Adaptive defense for network-layer attacks, mitigated inside your own data center based on real traffic behavior.

SYN floods, UDP floods, ICMP floods, amplification, and fragmentation attacks target the network layer. Before they ever reach the application, they can exhaust connection pools, bandwidth, processing capacity, or the network gateway.

Classic static thresholds don't produce the same outcome in every environment. Traffic that is normal for one organization may be an attack for another. A threshold that looks safe during the day may sit far too high at night; a campaign-period threshold may produce false alarms on a normal day.

TR7 L4 DDoS Protection learns your network's normal behavior and decides against that normal during an attack. Attack traffic is filtered on your TR7 ADC platform — not routed off to a third-party scrubbing cloud. Data locality, latency control, and operational ownership stay with you.

Not a static threshold — your network's actual behavior.

L4 DDoS Protection combines baseline learning, multi-vector filtering, and topology-aware thresholds to stop network-layer attacks inside your own network. Defense without sending attack traffic to a third-party scrubbing cloud.

PROTECTION LAYERS

Three-Layer Adaptive Defense for the Network Layer

L4 DDoS Protection combines normal-traffic learning, multi-vector attack filtering, and topology-aware decisions. Instead of a single static threshold, defense follows the organization's actual network behavior.

Adaptive Baseline Learning

TR7 watches your network's normal traffic behavior and builds a baseline over time. During an attack, the decision is made against the organization's own traffic profile — not against generic assumptions.

  • Connection rate, packet rate, SYN/ACK ratio, and fragmentation density monitored
  • Hourly, daily, and weekly traffic profiles built
  • The operator reviews the proposed baseline, approves it, and puts it into policy
  • Baseline can be retrained as the traffic profile changes
  • Reduces the false-positives and slow-response risk of static thresholds

Multi-Vector Filtering

DDoS campaigns usually arrive in more than one form. SYN floods, UDP floods, ICMP floods, amplification, and fragmentation can run together in the same campaign.

  • SYN floods are filtered before the connection pool is exhausted
  • UDP floods are rate-limited by source, destination, rate, and behavior
  • ICMP flood traffic is brought under control at the protocol level
  • DNS, NTP, and memcached amplification patterns can be detected
  • Fragmentation attacks can be filtered before packet reassembly

Topology-Aware Threshold Model

Every organization has a different network, application set, traffic source, and load cycle. The same threshold doesn't produce the same result everywhere. TR7 evaluates thresholds with service and topology context.

  • A separate behavior profile can be created per vService or traffic zone
  • A normal-traffic model can be built around expected source geographies
  • Day, night, weekend, and peak differences can be reflected in the baseline
  • Service-specific behavior can be tracked instead of total network traffic
  • Anomalous traffic is separated more precisely while real user traffic is preserved
ARCHITECTURE

Built-In L4 Protection on Your Own ADC Platform

L4 DDoS Protection is not a separate appliance or a third-party cloud scrubbing service. It is a premium defense layer that runs on TR7 ADC. Network-layer attacks are absorbed in infrastructure you own — without redirecting traffic anywhere else.

  • Runs on TR7 ADC — no separate DDoS appliance or cloud scrubbing service required
  • Baseline learning can be periodically refreshed against your traffic
  • When an attack is detected, filtering applies at L4, at the packet level
  • Attack traffic is absorbed inside your network; not redirected to a third-party cloud
  • Central Management can standardize policy and baseline across multi-region environments
  • SIEM integration delivers attack time, vector, source geography, and the action taken
USE-CASE SCENARIOS

4 Critical Battlefields Where L4 DDoS Protection Steps In

L4 DDoS Protection delivers value in attacks that target service continuity at the network layer. The goal is not just to block attack traffic, but to keep the service up by protecting real user connections.

Volumetric SYN flood attack

Scenario

The attacker sends a very high number of SYN packets, trying to exhaust the connection pool. If a static threshold triggers too late, the service slows; if it triggers too aggressively, real users are also affected.

Solution

TR7 already knows the normal SYN/ACK behavior from the baseline. When the anomalous SYN wave is detected, the attack traffic is filtered before the connection pool is exhausted; real user traffic is preserved.

DNS amplification attack

Scenario

The attacker uses DNS reflectors to direct high-volume response traffic at the organization's uplink. From the outside, the traffic looks like DNS responses — but it consumes bandwidth.

Solution

TR7 evaluates source diversity, packet size, traffic rate, and service context together. When the amplification pattern is detected, traffic is rate-limited or filtered.

Attack detection across day/night traffic cycles

Scenario

A finance or government application sees heavy daytime traffic and low nighttime traffic. An attacker may launch a lower-volume but effective attack at night. A static daytime threshold can miss this.

Solution

TR7 separates the nighttime normal with hourly and seasonal baselines. Traffic anomalous against the night profile is detected earlier and the appropriate filtering is applied.

High volume from unexpected geographies

Scenario

An organization focused on its home market suddenly receives high traffic volume from unexpected countries. The attack may originate from a distributed botnet.

Solution

TR7 evaluates the expected source geographies and normal traffic distribution as part of the baseline. Geographic anomaly, packet rate, and service target are analyzed together to apply the appropriate rate-limit or filtering.

CAPACITY OPTIONS

Licensed by Routing Table Count

L4 DDoS Protection is licensed by the number of routing tables to be protected. It scales from single-segment deployments to multi-segment enterprise networks and to multi-tenant service-provider environments.

Included with the Bundle — No Add-on Needed
2 routing tables
Included with every ADC license
Adaptive L4 DDoS protection ships with every ADC license at standard limits.

Every ADC license ships baseline adaptive L4 DDoS protection for a standard number of routing tables. For broader scope, the capacity tiers below take over.

1
Routing Table
2
Routing Tables
5
Routing Tables
10
Routing Tables
25
Routing Tables
Unlimited
Protection

For PAYG customers, L4 DDoS Protection can be delivered with L7 DDoS and L7 Reporting capabilities together as part of the PAYG Extra Pack.

COMPLIANCE

A Strong Defense for Service Continuity and Network-Layer Protection

L4 DDoS Protection provides a strong additional security layer for keeping critical services running, applying technical measures against network-layer attacks, and tracking attack events under auditable record.

GDPR Article 32

Supports technical measures for service continuity and data security on systems that process personal data. Helps reduce the risk of service interruption.

SOX & Financial-System Audit

Contributes to service-continuity, network-security, event-traceability, and DDoS-defense requirements in financial systems.

ISO 27001 Annex A.13 & NIST CSF

Provides additional control for DDoS protection, traffic integrity, and network-layer security in critical infrastructure and enterprise networks.

PCI DSS 4.0.1 Req 6.4

Supports protection of production environments and resilience of critical application infrastructure against attacks.

LICENSING

Premium Add-on — Expanded L4 DDoS Scope

L4 DDoS Protection is available as a Premium add-on for all four TR7 bundles (Base, Geo, Secure, and Enterprise). Adaptive baseline learning, multi-vector filtering, topology-aware thresholds, SIEM streaming, and audit trail are included in the add-on scope.

  • Attaches to all four bundles — Base, Geo, Secure, and Enterprise
  • Runs on a hardware appliance or a virtual machine
  • Runs natively on TR7 ADC; a separate DDoS appliance or cloud service is not required
  • Central Management supports baseline and policy standardization across multi-region environments
  • SIEM streaming and audit trail are part of the full scope

Stop Network-Layer Attacks on Your Own Infrastructure

Let's model your environment together in an L4 DDoS Protection demo: which routing tables will be protected, how the normal traffic baseline will be learned, which attack vectors take priority, and how the SIEM stream will be configured.

Licensing Guide