Mobile module
5G Sub-6 Ghz SA/NSA 2.4/3.4 Gbps DL (4x4 MIMO), 900/550 Mbps UL (2x2); 4G (LTE) – LTE Cat 19 1.6 Gbps DL, Cat 18 200 Mbps UL; 3G – 42Mbps DL, 5.76Mbps UL
eSIM
Consumer eSIM, profile download and removal, up to 7 eSIM profiles; data plans excluded.
3GPP Release
Version 16
SIM Switch
2 SIM cards and 1 eSIM, automatic switching in case of: weak signal, data limit, SMS limit, roaming, no network, network denied, data connection error, SIM inactive protection
State
Signal Strength (RSSI), SINR, RSRP, RSRQ, EC/IO, RSCP, Bytes Sent/Received, Connected Bandwidth, IMSI, ICCID, SIM Provider, Operator, Network Type, Cell ID, LAC, TAC, ARFCN, UARFCN, EARFCN
text message
SMS Status, SMS Configuration, Email to SMS, SMS to Email, SMS to HTTP, SMS to SMS, Scheduled SMS, SMS Auto-Reply, SMPP
USSD
Supports sending and reading Unstructured Supplementary Data (UNSSD) messages.
Block/Allow List
Operator block/allow list (by country or by individual operators)
Multiple PDN
Ability to use different PDNs for multiple network accesses and services
Band Management
Band lock, display the status of the band used
Inactive SIM Protection Service
It offers the ability to configure the router to periodically switch to the unused SIM card and establish a data connection to prevent the SIM card from being blocked.
SIM PIN code management
SIM PIN management allows you to set, change, or disable your SIM card PIN.
APN
Auto APN
Bridge
Direct connection (bridge) between mobile ISP and device on LAN
Ride
The router assigns its floating WAN IP address to another device on the LAN
framed routing
Encapsulated Routing: Supporting an IP network behind a 5G UE
WIFI
Wireless mode
802.11b/g/n/ac/ax (Wi-Fi 6) with data rates up to 2402 Mbps on the 5 GHz band and 576 Mbps on the 2.4 GHz band (Dual Band, MU-MIMO).
Wi-Fi Security
WPA2-Enterprise: PEAP, WPA2-PSK, WPA-EAP, WPA-PSK, WPA3-SAE, WPA3-EAP, OWE; AES-CCMP, TKIP, self-encryption mode, client separation, EAP-TLS with PKCS#12 certificates, auto-reconnect disablement, 802.11w protected management frames (PMF)
SSID/ESSID
SSID stealth mode and MAC address-based access control
WiFi users
Up to 512 simultaneous connections
Wireless connectivity features
Wireless mesh networking (802.11s), fast roaming (802.11r), BSS transition management (802.11v), radio resource metering (802.11k)
Wireless MAC Filter
Allowed list, blocked list
Wireless QR Code Generator
Once scanned, the user will automatically log in to the network without having to enter login credentials.
Travel companion
Forward the Wi-Fi hotspot landing page to a subsequently connected device.
Ethernet
WAN
1 x 10/100/1000 Mbps WAN port, compliant with IEEE 802.3, IEEE 802.3u, 802.3az standards, supports MDI/MDIX auto crossover.
LAN
4 LAN ports, 10/100/1000 Mbps, compliant with IEEE 802.3, IEEE 802.3u, 802.3az standards, supports MDI/MDIX automatic crossover.
Net
Routing
Static routing, dynamic routing (BGP, OSPF v2, RIP v1/v2, EIGRP, NHRP), policy-based routing
Network protocols
TCP, UDP, IPv4, IPv6, ICMP, NTP, DNS, HTTP, HTTPS, SFTP, FTP, SMTP, SSL/TLS, ARP, VRRP, PPP, PPPoE, UPNP, SSH, DHCP, Telnet, SMPP, SNMP, MQTT, Wake On Lan (WOL), VXLAN
Support for VoIP passthrough
NAT helper for H.323 and SIP-alg protocols, which allow correct routing of VoIP packets
Connection Monitoring
Ping Reboot, Wget Reboot, Periodic Reboot, LCP and ICMP for link inspection
Firewall
Port forwarding, traffic rules, custom rules, TTL target customization
Firewall Status Page
View all your firewall statistics, rules and rule counters.
Port management
View the device's ports, enable and disable each of them, enable or disable automatic configuration, change their transmission speed, and so on.
Network topology
Visual representation of the network, showing which devices are connected to which other devices.
DHCP
Static and dynamic IP assignment, DHCP forwarding, DHCP server configuration, status, static leases: wildcard MAC
QoS / Intelligent Queue Management (SQM)
Priority traffic queuing by source/destination, service, protocol, or port, WMM, 802.11e
DDNS
It supports over 77 service providers, others can be configured manually.
DNS over HTTPS
DNS over HTTPS proxy enables secure DNS resolution by routing DNS queries over HTTPS.
Network Backup
Wi-Fi WAN, Mobile, VRRP, and Wired options, each of which can be used as an automatic failover solution.
Load balancing
Balance Internet traffic across multiple WAN connections
Hot spot
Captive portal (hotspot), internal/external Radius server, Radius MAC authentication, SMS authorization, SSO authentication, internal/external landing page, walled garden, user scripts, URL parameters, user groups, restrictions for individual users or groups, user management, 9 customizable pre-defined themes and the ability to upload and download custom hotspot themes.
Hotspot 2.0
Hotspot 2.0 is a Wi-Fi standard that enables automatic, secure, and seamless connection to reliable wireless networks.
SSHFS
Ability to mount a remote file system via SSH protocol
Traffic management
Real-time monitoring, wireless signal graphs, traffic usage history
Port Mirroring
Replicate network traffic across Ethernet ports for monitoring and analysis.
Safety
802.1x
Port-based network access control client
Authentication
Pre-shared key, digital certificates, X.509 certificates, TACACS+, internal and external RADIUS user authentication, IP and login attempt blocking, time-based login blocking, built-in random password generator
Firewall
Pre-configured firewall rules can be enabled via WebUI, unlimited firewall configuration via CLI, DMZ, NAT, NAT-T, NAT64
Disease attack
DDoS attack prevention (SYN flood protection, SSH attack prevention, HTTP/HTTPS attack prevention), port scan prevention (SYN-FIN, SYN-RST, X-mas, NULL flag, FIN scan attacks)
VLAN
Port and tag-based VLAN separation
Control of moving quotas
Mobile data limit, customizable period, start time, warning limit, phone number
WEB filter
Blocklist to block unwanted websites, allowlist to specify only allowed sites.
Access control
Flexible access control via SSH, web interface, CLI, and Telnet.
TPM
Identification and Authentication Module, TPM 2.0 standard
Certificate Manager
The certificate creation tool allows you to create CA, server, client, Let's Encrypt, and SCEP certificates.
VPN
OpenVPN
You can run multiple clients and one server simultaneously, with 27 encryption methods.
OpenVPN Encryption
DES-CBC 64, RC2-CBC 128, DES-EDE-CBC 128, DES-EDE3-CBC 192, DESX-CBC 192,
BF-CBC 128, RC2-40-CBC 40, CAST5-CBC 128, RC2-64-CBC 64, AES-128-CBC 128, AES-128-CFB 128, AES-128-CFB1 128, AES-128-CFB8 128, AES-128-OFB 128, AES-128-GCM 128, AES-192-CFB 192, AES-192-CFB1 192, AES-192-CFB8 192, AES-192-OFB 192, AES-192-CBC 192, AES-192-GCM 192, AES-256-GCM 256, AES-256-CFB 256, AES-256-CFB1 256, AES-256-CFB8 256, AES-256-OFB 256, AES-256-CBC 256
IPsec
XFRM, IKEv1, IKEv2, con 14 metodi di crittografia per IPsec (3DES, DES, AES128, AES192, AES256, AES128GCM8, AES192GCM8, AES256GCM8, AES128GCM12, AES192GCM12, AES256GCM12, AES128GCM16, AES192GCM16, AES256GCM16)
GRE
GRE Tunnel, support for GRE tunnels over IPsec
PPTP, L2TP
Client/server instances can run concurrently, with support for L2TPv3 and L2TP over IPsec.
Stunnel
Proxy designed to add TLS encryption functionality to existing clients and servers without making any changes to the program code.
DMVPN
Scalable IPsec VPN Creation Method, Phase 2 and Phase 3, and Dual Hub Support
SSTP
support for SSTP client instances
ZeroTier
ZeroTier VPN Customer Support
WireGuard
Support for WireGuard VPN clients and servers
Dyeing
Tinc offers encryption, authentication, and compression in its tunnels. Client and server support.
Tail scale
Tailscale offers speed, stability, and simplicity compared to traditional VPNs. Point-to-point connections are encrypted using the open-source WireGuard protocol.
Netbird
Open-source VPN management platform based on WireGuard® that makes it easy to create secure private networks for your organization or home.
EoIP
Ethernet over IP (EoIP) tunneling is a GRE RFC 1701-based protocol that creates an Ethernet tunnel between two routers over an IP connection.
OpenConnect
Cross-platform, multi-protocol SSL VPN client that supports numerous VPN protocols.
BacNET
Supported modes
Router
Supported connection types
IP, RTU (USB)
Configuration options
Support for multiple BACnet/IP interfaces, network number assignment, pre-configured BDT entries for BBMD (BACnet Broadcast Management Device)
OPC UA
Supported modes
Client, Server
Supported connection types
TCP
MODBUS
Supported modes
Server, Client