TR7 Add-ons — specialized capability modules that plug into the bundles.

PREMIUM ADD-ON

vTenant — Hardware-Partitioned Multi-Tenancy

Multiple tenants with separated resources and isolated management on a single physical TR7 appliance.

Service providers, holding structures, and multi-region organizations often face the same need: make efficient use of one powerful hardware investment, but draw a clear security boundary for each customer, department, or environment.

Classic multi-tenancy usually adds software-level separation on top of shared resources. That model can be enough for small environments; but when customer isolation, compliance scope, resource guarantees, and operational safety are required, a stronger boundary is needed.

TR7 vTenant delivers hardware-assisted tenant separation on the physical TR7 appliance. Every tenant gets its own CPU, RAM, disk, network, and management domain. Multiple independent TR7 environments can run on a single device; tenants don't consume each other's resources, can't see each other's policies, and can't reach into each other's operational space.

One physical TR7. Multiple isolated tenants.

vTenant partitions CPU, RAM, disk, network, and management domains on a per-tenant basis. MSP customers, subsidiaries, PCI scopes, and test/production environments can run on the same physical appliance — under control and fully isolated.

ISOLATION LAYERS

Four-Layer Separation: Resources, Network, Management, and License Scope

vTenant doesn't just add a tenant label in the UI. Resource usage, network domain, management authority, and product scope are defined separately per tenant. That makes it possible to operate multiple independent environments on the same physical device.

Hardware-Assisted Resource Separation

CPU, RAM, disk, and log space are planned separately per vTenant. One tenant's load or misconfiguration doesn't affect the others.

  • Dedicated CPU resource area per tenant
  • Per-tenant RAM quota and resource limit
  • Disk and log space separated at the tenant boundary
  • Heavy traffic or faulty configuration does not bleed into other tenants
  • Resource usage can be monitored and reported per tenant

Network Isolation and Segmentation

Tenant traffic doesn't mix into a shared network domain. A separate network context, route table, and firewall boundary can be defined for each tenant.

  • A separate virtual network interface can be assigned per tenant
  • MAC prefix prevents addressing conflicts
  • Route tables and firewall policies are separated per tenant
  • Cross-tenant traffic is blocked by default
  • A provable network boundary is established for compliance and customer separation

Independent Management per Tenant

Each tenant runs with its own admin group, role model, policy domain, and audit trail. One tenant's administrator can't see another tenant's configuration.

  • Separate admin account and role matrix per tenant
  • Independent policy and configuration domain per tenant
  • One tenant's administrator cannot see other tenants
  • From a super-admin layer (MSP/service-provider), all tenants can be monitored
  • Audit, reporting, and compliance output produced per tenant

Reflecting Product and License Scope into the Tenant

Products licensed on the TR7 platform can be made available inside the tenant scope. ADC, WAAP, AAM, GTM, and additional security capabilities are delivered to tenants under control.

  • Products on the platform license can be used inside the tenant scope
  • Without a WAAP license, WAAP capability is not opened to tenants
  • Bandwidth, vService, and resource limits can be distributed per tenant
  • L4/L7 DDoS, L7 Reporting, and similar add-ons can be included in tenant scope
  • In MSP scenarios, per-customer capacity and service separation can be applied
ARCHITECTURE

Isolated Tenants on a Single Physical TR7 Appliance

vTenant partitions the physical TR7 appliance into multiple isolated tenant areas. The goal is to clearly separate resource, network, and management boundaries while sharing the same hardware investment.

  • Available only on the physical TR7 appliance
  • CPU, RAM, disk, and network resources can be assigned per tenant
  • MAC prefix and network interface separation keep tenant traffic from mixing
  • Cross-tenant traffic is kept under control
  • Every tenant runs with its own management area and audit trail
  • Central Management can monitor multi-region tenant structures from one console
  • SIEM streaming can be delivered per tenant via separate channels or tags
USE-CASE SCENARIOS

4 Critical Battlefields Where vTenant Steps In

vTenant delivers the most value in scenarios where one physical TR7 platform must be safely partitioned across multiple customers, business units, compliance scopes, or environments.

MSP — multi-customer service on a single device

Scenario

A Managed Service Provider wants to offer ADC, WAAP, or AAM services to different customers. Separate appliances per customer would be expensive; but customer resources, management, and audit areas must be kept apart.

Solution

With vTenant, each customer is defined as a separate tenant. Customer resources, network policies, admin accounts, and audit logs are separated. The MSP runs multi-customer services on a single physical TR7 appliance — more controlled and more scalable.

Holding and subsidiary separation

Scenario

In a holding structure, different companies or business units want to use the same TR7 infrastructure. Each unit has its own applications, policies, administrators, and audit scope.

Solution

Each business unit is positioned as a separate vTenant. The shared hardware investment is preserved, but management authority, configuration, and audit trail are separated per unit.

Environments that need scope separation (PCI/HIPAA)

Scenario

The organization wants to run both sensitive-data-scoped applications and general applications on the same TR7 appliance. Audits require clear separation of these areas.

Solution

A separate vTenant is created for the sensitive-data scope. Its resources, network context, management, and audit trail are separated from the general application area. Audit teams see scope separation more clearly.

Production and test separation on one device

Scenario

The organization wants a separate TR7 capacity for test and development; the production environment must continue running on the same device without being affected. Test load or misconfiguration must not bleed into production.

Solution

Production and test run as separate vTenants. Load, rule changes, or configuration errors in the test environment don't affect the production tenant. The same physical device is used more efficiently.

CAPACITY OPTIONS

Licensed by Tenant Count

The vTenant add-on is licensed by the number of tenants to be created on the physical TR7 appliance. Small deployments cover a few tenants; large enterprise and service-provider scenarios use broader tenant capacity.

1
Tenant
2
Tenants
5
Tenants
10
Tenants
25
Tenants
50
Tenants
Unlimited
Tenants

vTenant is available only on the physical TR7 appliance. On the Service Provider Platform License, tenant scope can be considered natively for MSP and multi-customer operations.

COMPLIANCE

A Strong Layer for Scope Separation and Multi-Tenant Isolation

vTenant clarifies resource, network, management, and audit boundaries in structures that require separation by customer, business unit, regulatory scope, or environment.

PCI DSS 4.0.1 Req 1 — Network Segmentation

Supports separation of the cardholder data environment from the general application area. Per-tenant network and management boundaries provide a strong technical control for scope separation.

GDPR Article 32

Strengthens technical safeguards on systems that process personal data — through resource, access, and network separation.

SOX & Financial-System Audit

Supports separation of different services, customers, or operational scopes in financial systems and an auditable management model.

HIPAA & Health Data Regulations

A separated tenant model can be created for systems that process patient data — by clinic, service, organization, or application.

LICENSING

Premium Add-on — Per Tenant on a Physical Appliance

vTenant is available as a Premium add-on for all four TR7 bundles (Base, Geo, Secure, and Enterprise). It is delivered only on the physical TR7 appliance; the number of tenants is set by the license scope.

  • Attaches to all four bundles — Base, Geo, Secure, and Enterprise
  • Runs only on the physical TR7 appliance
  • On the Service Provider Platform License, tenant scope can be available natively
  • Central Management can monitor multi-region tenant structures from one console
  • Each tenant runs within the product family and add-on capabilities of the platform license
  • Per-tenant audit trail and SIEM streaming are supported

Run Isolated Tenants on a Single TR7 Appliance

Let's model your scenario together in a vTenant demo: how many tenants you need, which resources to separate, which tenants use which products, and how network and management boundaries will be defined.

Licensing Guide