TR7 Bundles — pre-grouped product sets for enterprise scenarios.

ENTERPRISE BUNDLE

End-to-End Application Delivery and Security Platform

The four foundational layers of enterprise application infrastructure converge in one bundle, one platform, and one operator UI.

Modern enterprise application infrastructure isn't only about publishing the application. Routing traffic to the right region, distributing the application securely, defending it against web and API attacks, and controlling user access by identity must all run at the same time.

TR7 Enterprise Bundle brings these four layers into one package. ADC publishes the application and distributes it within the region. WAAP protects it against OWASP, bot, API, account-takeover, and adaptive L7 DDoS attacks. AAM governs access against identity, session, and service policy. GTM routes traffic to the right region at the DNS layer. The bundle also includes TR7 Central Management's two-region scope; primary and standby data centers are managed from one console.

Delivery. Protection. Access. Routing. One Platform.

TR7 Enterprise Bundle unifies application delivery, application security, identity-controlled access, and global traffic routing under the same operator UI. Service pools, certificates, health signals, and policies operate together across the four layers.

WHAT'S INSIDE

4 Products + 2 Add-ons, One Bundle

Enterprise Bundle delivers ADC, WAAP, AAM, and GTM at full capability — plus TR7 ETM included for 100 endpoints and TR7 Central Management's two-region scope. Delivery, protection, access, global routing, and device visibility all run on one license, from one UI.

TR7 ADC

The application publishing, load balancing, traffic distribution, and service continuity layer.

  • 13 load-balancing algorithms, 9 session-persistence methods
  • 7+ deployment topologies, IP-takeover inline
  • SSL/TLS termination + ACME automation
  • Content-aware rules — without scripting
  • Built-in adaptive L4/L7 DDoS + on-device L7 reporting
TR7 ADC details

TR7 WAAP

The protection layer against web, API, bot, account-takeover, and application-layer DDoS attacks.

  • OWASP Top 10 + 3000+ rules, virtual patching
  • Bot management, behavioral scoring
  • API security: discovery, OpenAPI/Swagger, GraphQL
  • Account takeover prevention: credential stuffing, brute force
  • Response-side sensitive data masking + local CAPTCHA
TR7 WAAP details

TR7 AAM

The authentication, MFA, per-application access, VPN, and clientless remote access layer.

  • Per-application authentication + Access Portal
  • OAuth2, OIDC, SAML, LDAP, RADIUS, TACACS+
  • MFA: TOTP, SMS, email OTP, certificate
  • SSL VPN, IKEv2, clientless RDP/VNC/SSH
  • Login-attack + session protection
TR7 AAM details

TR7 GTM

The DNS-layer global traffic routing, region selection, and health-based failover layer.

  • Authoritative DNS, 35 record types, on-device DNSSEC
  • 5 routing modes: geography, latency, weight, health, multi-signal
  • Bidirectional failover scenarios
  • Multi-source DC selection with 17 metric types
  • AXFR/IXFR/NOTIFY pipeline + Express zone acceleration
TR7 GTM details
BUNDLED ADD-ONS

TR7 Central Management — Two-Region Scope

Included with EnterpriseTwo regions · one console · all features unlocked
TR7 appliances in the primary and standby data centers are controlled from the same management console. Policy synchronization, rule rollout, certificate distribution, and configuration comparison happen across both regions together. Operations start without deploying a separate central-management VM for DR scenarios.

For more than two regions or a broader device inventory, the TR7 Central Management add-on steps in at full scope.

Explore TR7 Central Management

First 100 Endpoints Included with Enterprise Bundle

Included with Enterprise Bundle100 endpoints · all features unlocked

TR7 Enterprise Bundle adds a 100-endpoint TR7 ETM license alongside ADC, WAAP, AAM, and GTM. Beyond traffic delivery, application-layer protection, user access, and global routing, you gain unified visibility into your devices, mobile endpoints, and servers — all from the same platform.

TR7 ETM delivers live telemetry through a single management layer that runs on laptops, phones, and servers. Which device is on which version, whether the security agent is running, who connected from where, and which server is under load — all monitored from one console.

When a device poses a risk, you can run remote commands, pull files, terminate processes, or isolate the device from the network. On the server side, live data — CPU, RAM, disk, and service health — feeds smarter traffic decisions back into ADC.

100 endpoints are included with Enterprise Bundle. Laptops, mobile devices, and servers all draw from the same pool. When you need more, TR7 ETM scales up with 500, 1,000, and unlimited endpoint options.

Explore TR7 ETM
WHY ALL FOUR TOGETHER

Four Decisions on the Same Policy Plane

When a user request is processed, four decisions are made simultaneously: which region should it go to, how should it be carried, is the content safe, is the user authorized? Splitting these decisions across separate products creates policy inconsistency, audit fragmentation, and operational load. TR7 Enterprise unifies all four decisions on one platform.

Four layers, one decision flow

DNS routing, traffic distribution, security inspection, and identity control all run on the same platform model. No coordination, synchronization, or integration lag has to be added later between four separate products.

One service and policy model

Backend-service pools, certificate store, health checks, and traffic rules are defined once; all four layers share the same definitions. You don't manage four inventories or four separate policy update streams across four products.

One audit trail

Which region the request came from, which WAAP rule inspected it, which MFA step it passed, and which backend service answered — tracked in one stream. The need to stitch fragmented logs after the fact for PCI DSS, GDPR, banking regulators, and similar compliance frameworks is reduced.

One operational discipline

Delivery, security, identity, and DNS teams work from the same operator UI. Policy changes apply through shared rule logic; you don't have to manage integration issues between four separate products.

USE CASES

Five Scenarios Where Enterprise Bundle Is at Its Strongest

The ADC + WAAP + AAM + GTM combination is designed for scenarios where every foundational layer of enterprise application infrastructure is required in one bundle.

Bank core digital platform — multi-region, regulated

Customer portal, internet banking, mobile API, digital branch, and partner access are managed on one platform. ADC publishes the traffic, WAAP stops the attacks, AAM controls customer and staff access by identity, and GTM routes between primary and DR regions. Banking-regulator, PCI DSS 4.0, and data-protection compliance expectations are met under one operating model.

Telco geographically distributed applications

Multi-region application delivery is required for customer self-service portals, B2B interfaces, operations panels, and regional POPs. Enterprise Bundle combines active-active routing, WAAP, bot protection, identity-controlled access, and intra-region distribution on the same platform.

Public-sector critical infrastructure applications

E-government systems, tax platforms, healthcare portals, and defense interfaces require multi-region, auditable, on-prem, and data-residency-compliant architecture. Enterprise Bundle runs all four layers on the same policy plane; no third-party cloud dependency is created.

Multi-region enterprise SaaS and B2B platforms

For SaaS providers with geographic distribution requirements, tenant isolation, federated SSO, OWASP protection, API rate limiting, multi-region delivery, and health-based failover are all required together. ADC handles local distribution, WAAP handles attack inspection, AAM handles identity federation, and GTM handles the region decision on the same platform.

Healthcare ecosystem — hospital chains, insurance, clinics

Hospital chains, insurance portals, clinical data interfaces, and telehealth applications require sensitive data protection, identity-controlled access, multi-region delivery, and application-layer attack protection. WAAP's response-side sensitive data masking adds an extra security layer in these scenarios.

INTEGRATION

Not Four Separate Products — Four Layers of the Same Platform

In TR7 Enterprise, ADC, WAAP, AAM, and GTM share the same service definitions, certificate store, health view, and operator experience. Integration isn't a project set up later — it's how the bundle natively operates.

One backend-services pool

A backend-services pool is defined once; ADC, WAAP, AAM, and GTM all use the same pool. You operate under a single inventory, single health-check, and single change-management model; the same definitions are not recreated across four products.

One certificate lifecycle

Certificates obtained via ACME or managed through an internal PKI live in one store. All four layers use the same certificate source; renewal, tracking, and distribution processes aren't repeated.

One health and behavior view

Active health monitoring and adaptive L4/L7 DDoS baseline learning are fed by the same signal set. An unhealthy service is taken into account in local distribution, the global DNS response, protection decisions, and access policy.

Hot configuration reload

WAAP policies, identity rules, delivery rules, DNS policies, and certificates apply without dropping active connections. Because all four layers run on the same platform, changes flow through consistently and under control.

BUNDLE vs. BUYING SEPARATELY

One License. No Per-User Counter. No Tier Gating.

Solving delivery, protection, access, and routing layers with separate products grows licensing, integration, audit, and operations cost. TR7 Enterprise simplifies every foundational layer of enterprise application infrastructure under a single bundle.

One license, one price for four layers

ADC, WAAP, AAM, and GTM capabilities ship in one bundle. You don't have to manage a separate license, a separate capacity tier, or a user-based uplift per module.

No tier gating — every capability is standard

OWASP, bot, API, ATO, adaptive L7 DDoS, SSO, MFA, VPN, clientless access, authoritative DNS, GSADC, geographic routing, DNSSEC, and more ship standard in the Enterprise Bundle.

Certificates, service pools, and policy defined once

You don't recreate the same certificate, the same backend-service pool, or the same policy model in four separate products. Defined once, used together by all four layers.

Central Management two-region included — no extra license for DR

TR7 Central Management's two-region scope is included in the Enterprise Bundle for cross-data-center policy synchronization and central management. No separate central-management license is required for DR scenarios.

Adaptive baseline learning across four layers

Adaptive L4/L7 DDoS learns your environment's normal. The same behavior signals feed WAAP attack decisions, ADC traffic distribution, and GTM health-based routing.

On-prem control, no cloud dependency

WAAP rules, identity policies, DNS responses, and traffic decisions are processed in your own infrastructure. Data-sovereignty and regulatory expectations are met without depending on third-party WAAP, ZTNA, or DNS cloud services.

Not an integration project — out-of-the-box platform behavior

Four products are parts of the same platform. Service pools, certificates, health checks, and policies are shared directly; running all four layers together doesn't turn into a weeks-long integration project.

RECOGNITION

Validated by Teams Running the Full Stack on One Platform

Verified G2 reviews from enterprise infrastructure leaders, security architects, platform teams, and disaster-recovery owners.

Verified Review
"We worked with four different vendors: ADC, WAAP, identity, and DNS routing. Each had its own license, operator, and change window. With TR7 Enterprise we consolidated all four onto one platform; integration effort, maintenance load, and audit fragmentation are gone."
Enterprise Infrastructure LeaderEnterprise (1000+ employees) · Banking
Verified Review
"We didn't need to buy a separate central-management product for cross-region policy synchronization; the Enterprise Bundle includes Central Management's two-region scope. Our DR drills run from one console for switch-over and switch-back scenarios."
Disaster Recovery OwnerEnterprise (1000+ employees) · Insurance
Verified Review
"WAAP, bot protection, identity, and global routing share the same health signal. When a backend in one region becomes unhealthy, the DNS response, traffic route, protection decision, and access policy adapt instantly — we don't write coordination code."
Platform Team LeadEnterprise (1000+ employees) · Telecommunications

See the Entire Application Stack on One Platform

Bring your multi-region application portfolio, WAAP policies, identity infrastructure, and DNS requirements. We'll show you how TR7 Enterprise Bundle runs the ADC + WAAP + AAM + GTM layers together from one operator UI in a live demo.