Mobile module
5G Sub-6Ghz SA/NSA: 2.4/3.4 Gbps DL (4x4 MIMO), 900/550 Mbps UL (2x2); 4G LTE: Cat 19 1.6Gbps DL, Cat 18 200Mbps UL; 3G: 42Mbps DL, 5.76Mbps UL
3GPP Release
Version 16
eSIM
Consumer eSIM, profile download and removal operations, up to 7 eSIM profiles; does not include data plans
SIM change
2 x SIM 2FF and 1 x eSIM, automatic switching cases: weak signal, data limit, SMS limit, roaming, no network, network denied, data connection error
State
IMSI, ICCID, operator, operator status, data connection status, network type, AC indicator, bandwidth, connected bandwidth, signal strength (RSSI), SINR, RSRP, RSRQ, EC/IO, RSCP, data sent/received, LAC, TAC, cell ID, ARFCN, UARFCN, EARFCN, MCC and MNC
text message
SMS Status, SMS Configuration, EMAIL to SMS, SMS to EMAIL, SMS to HTTP, SMS to SMS, Scheduled SMS, SMS Auto-Reply, SMPP
USSD
Supports sending and reading unstructured supplemental service data messages
Block/Allow List
List of blocked/allowed operators (by country or separate operators)
Multiple PDN
Ability to use different PDNs for multiple network accesses and services
Bandwidth management
Band lock, display the status of the band used
Inactive SIM Protection Service
It offers the ability to configure the router to periodically switch to the unused SIM card and establish a data connection to prevent the SIM card from being blocked
SIM PIN code management
SIM PIN code management allows you to set, change, or disable your SIM card PIN.
APN
Automatic APN
Bridge
Direct connection (bridge) between mobile ISP and device on LAN
Ride
The router assigns its floating WAN IP address to another device on the LAN
Milling with frame
Frame routing: Supports IP network behind 5G EU
Wireless mode
802.11b/g/n/ac Wave 2 (Wi-Fi 5) with data rates up to 867 Mbps (Dual Band, MU-MIMO), 802.11r Fast Transition, Access Point (AP), Station (STA)
WiFi Security
WPA2-Enterprise - PEAP, WPA2-PSK, WPA-EAP, WPA-PSK, WPA3-SAE, WPA3-EAP, OWE; AES-CCMP, TKIP, self-encryption mode, client separation, EAP-TLS with PKCS#12 certificates, auto-reconnect disabled, 802.11w protected management frames (PMF)
SSID/ESSID
SSID stealth mode and MAC address-based access control
Wi-Fi users
Up to 150 simultaneous connections
Wireless connectivity features
Wireless mesh (802.11s), fast roaming (802.11r), relay, BSS transition management (802.11v), radio resource metering (802.11k)
Wireless MAC Filter
Allowed list, blocked list
Wireless QR Code Generator
Once scanned, the user will automatically log in to your network without having to enter login information.
TravelMate
Forward the Wi-Fi hotspot landing page to a subsequent connected device
Routing
Static routing, dynamic routing (BGP, OSPF v2, RIP v1/v2, EIGRP, NHRP), policy-based routing
Network protocols
TCP, UDP, IPv4, IPv6, ICMP, NTP, DNS, HTTP, HTTPS, FTP, SMTP, SSL v3, TLS, ARP, VRRP, PPP, PPPoE, UPNP, SSH, DHCP, Telnet, SMPP, SNMP, MQTT, TCP, UDP, IPv4, IPv6, ICMP, NTP, DNS, HTTP, HTTPS, SFTP, FTP, SMTP, SSL/TLS, ARP, VRRP, PPP, PPPoE, UPNP, SSH, DHCP, Telnet, SMPP, SNMP, MQTT, Wake On Lan (WOL)
VoIP passthrough support
H.323 and SIP-alg protocol NAT helpers, which enable correct routing of VoIP packets
Connection monitoring
Ping Reboot, Wget Reboot, Periodic Reboot, LCP and ICMP for link inspection
Wall of Fire
Port forwarding, traffic rules, custom rules, TTL lens customization
Firewall Status Page
View all firewall statistics, rules and rule counters
Port Management
View the device's ports, enable and disable each of them, turn automatic configuration on or off, change the transmission speed, and so on.
Network topology
Visual representation of your network, showing which devices are connected to which other devices
Hot spot
Captive portal (hotspot), internal/external Radius server, Radius MAC authentication, SMS authorization, SSO authentication, internal/external landing page, walled garden, user scripts, URL parameters, user groups, restrictions for individual users or groups, user management, 9 predefined customizable themes and the ability to upload and download custom hotspot themes
Access Point 2.0
Hotspot 2.0 is a Wi-Fi standard that enables seamless, secure, and automatic connection to reliable wireless networks.
DHCP
Static and dynamic IP assignment, DHCP relay, DHCP server configuration, status, static leases: wildcard MAC
QoS / Intelligent Queue Management (SQM)
Traffic priority queue by source/destination, service, protocol, or port, WMM, 802.11e
DDNS
Supported >25 service providers, others can be configured manually
DNS over HTTPS
DNS over HTTPS proxy enables secure DNS resolution by routing DNS queries over HTTPS
Network Backup
Wi-Fi WAN, Mobile, VRRP and Wired options, each of which can be used as automatic failover
Load balancing
Balance Internet traffic across multiple WAN connections
SSHFS
Ability to mount remote file systems via SSH protocol
VRF support
Initial support for Virtual Routing and Forwarding (VRF)
Traffic management
Real-time monitoring, wireless signal graphs, traffic usage history
Wall of Fire
Pre-configured firewall rules can be enabled via WebUI, unlimited firewall configuration via CLI, DMZ, NAT, NAT-T, NAT64
Attack Prevention
DDOS prevention (SYN flood protection, SSH attack prevention, HTTP/HTTPS attack prevention), port scanning prevention (SYN-FIN, SYN-RST, X-mas, NULL flag, FIN scanning attacks)
VLAN
Port and tag-based VLAN separation
Control of moving quotas
Custom data limits for your SIM card
WEB filter
Blacklist to block unwanted websites, Whitelist to specify only allowed sites
Access control
Flexible access control SSH, Web interface, CLI and Telnet
TPM
Identification and Authentication Module, TPM 2.0 standard
Generating the SSL certificate
Let's Encrypt and SCEP certificate generation methods
802.1x
Port-based network access control client
OpenVPN
Multiple clients and one server can run simultaneously, 27 encryption methods
OpenVPN Encryption
DES-CBC 64, RC2-CBC 128, DES-EDE-CBC 128, DES-EDE3-CBC 192, DESX-CBC 192,
BF-CBC 128, RC2-40-CBC 40, CAST5-CBC 128, RC2-64-CBC 64, AES-128-CBC 128, AES-128-CFB 128, AES-128-CFB1 128, AES-128-CFB8 128, AES-128-OFB 128, AES-128-GCM 128, AES-192-CFB 192, AES-192-CFB1 192, AES-192-CFB8 192, AES-192-OFB 192, AES-192-CBC 192, AES-192-GCM 192, AES-256-GCM 256, AES-256-CFB 256, AES-256-CFB1 256, AES-256-CFB8 256, AES-256-OFB 256, AES-256-CBC 256
IPsec
XFRM, IKEv1, IKEv2, con 14 metodi di crittografia per IPsec (3DES, DES, AES128, AES192, AES256, AES128GCM8, AES192GCM8, AES256GCM8, AES128GCM12, AES192GCM12, AES256GCM12, AES128GCM16, AES192GCM16, AES256GCM16)
GRE
GRE Tunnel, GRE tunnel support over IPsec
PPTP, L2TP
Client/server instances can run concurrently, L2TPv3 support, L2TP over IPsec
Stunnel
Proxy designed to add TLS encryption capabilities to existing clients and servers without any changes to the program code
DMVPN
Scalable IPsec VPN creation method, Phase 2 and Phase 3, and Dual Hub support
SSTP
Support for SSTP client instances
ZeroTier
ZeroTier VPN Client Support
WireGuard
WireGuard VPN client and server support
Tench
Tinc offers encryption, authentication, and compression in its tunnels. Client and server support.
Tail ladder
Tailscale offers speed, stability, and simplicity compared to traditional VPNs. Point-to-point connections are encrypted using the open-source WireGuard protocol.