




Tekniska specifikationer
Ethernet
WAN: 1 x WAN port 10/100/1000 Mbps, compliant with IEEE 802.3, IEEE 802.3u, 802.3az standards, supports auto MDI/MDIX cross-connect
LAN: 3 x LAN ports, 10/100/1000 Mbps, compliant with IEEE 802.3, IEEE 802.3u, 802.3az standards, supports auto MDI/MDIX crossover
LAN: 3 x LAN ports, 10/100/1000 Mbps, compliant with IEEE 802.3, IEEE 802.3u, 802.3az standards, supports auto MDI/MDIX crossover
Wireless
Wireless mode: 802.11b/g/n/ac Wave 2 (Wi-Fi 5) with data transfer rates up to 867 Mbps (Dual Band, MU-MIMO), 802.11r fast handover, Access Point (AP), Station (STA)
Wi-Fi Security: WPA2-Enterprise: PEAP, WPA2-PSK, WPA-EAP, WPA-PSK, WPA3-SAE, WPA3-EAP, OWE; AES-CCMP, TKIP, automatic encryption modes, client separation, EAP-TLS with PKCS#12 certificate, disable auto-reconnect, 802.11w Protected Management Frames (PMF)
SSID/ESSID: ESSID stealth mode
Wi-Fi users: Up to 150 simultaneous connections
Wireless connectivity features: Wireless mesh (802.11s), fast roaming (802.11r), Relayd, BSS transition management (802.11v), radio resource metering (802.11k)
Wireless MAC filter: Allow list, block list
QR code generator for Wi-Fi: When scanned, the user automatically enters the network without having to enter login details
TravelMate: Forwards Wi-Fi hotspot login page to a subsequent connected device
Wi-Fi Security: WPA2-Enterprise: PEAP, WPA2-PSK, WPA-EAP, WPA-PSK, WPA3-SAE, WPA3-EAP, OWE; AES-CCMP, TKIP, automatic encryption modes, client separation, EAP-TLS with PKCS#12 certificate, disable auto-reconnect, 802.11w Protected Management Frames (PMF)
SSID/ESSID: ESSID stealth mode
Wi-Fi users: Up to 150 simultaneous connections
Wireless connectivity features: Wireless mesh (802.11s), fast roaming (802.11r), Relayd, BSS transition management (802.11v), radio resource metering (802.11k)
Wireless MAC filter: Allow list, block list
QR code generator for Wi-Fi: When scanned, the user automatically enters the network without having to enter login details
TravelMate: Forwards Wi-Fi hotspot login page to a subsequent connected device
Security
SSL certificate generation: Let's Encrypt and SCEP certificate generation methods
802.1x: Port-based network access control client
Authentication: Distributed key, digital certificates, X.509 certificates, TACACS+, internal and external RADIUS user authentication, IP and login attempt blocking, time-based login blocking, built-in random password generator
Firewall: Pre-configured firewall rules can be enabled via WebUI, unlimited firewall configuration via CLI, DMZ, NAT, NAT-T, NAT64
Attack security: DDOS protection (SYN flood protection, SSH attack security, HTTP/HTTPS attack security), port scan protection (SYN-FIN, SYN-RST, X-mas, NULL flags, FIN scans)
VLAN: Port and tag-based VLAN separation
WEB filter: Blacklist to block unwanted websites, whitelist to allow only specified websites
Access Control: Flexible access control of SSH, web interface, CLI and Telnet
802.1x: Port-based network access control client
Authentication: Distributed key, digital certificates, X.509 certificates, TACACS+, internal and external RADIUS user authentication, IP and login attempt blocking, time-based login blocking, built-in random password generator
Firewall: Pre-configured firewall rules can be enabled via WebUI, unlimited firewall configuration via CLI, DMZ, NAT, NAT-T, NAT64
Attack security: DDOS protection (SYN flood protection, SSH attack security, HTTP/HTTPS attack security), port scan protection (SYN-FIN, SYN-RST, X-mas, NULL flags, FIN scans)
VLAN: Port and tag-based VLAN separation
WEB filter: Blacklist to block unwanted websites, whitelist to allow only specified websites
Access Control: Flexible access control of SSH, web interface, CLI and Telnet
Bluetooth
Bluetooth 4.0: Bluetooth Low Energy (LE) for short-range communication
Network
Routing: Static routing, dynamic routing (BGP, OSPF v2, RIP v1/v2, EIGRP, NHRP), policy-based routing
Network protocols: TCP, UDP, IPv4, IPv6, ICMP, NTP, DNS, HTTP, HTTPS, SFTP, FTP, SMTP, SSL/TLS, ARP, VRRP, PPP, PPPoE, UPNP, SSH, DHCP, Telnet, SMPP, SNMP, MQTT, Wake On Lan (WOL), VXLAN
VoIP passthrough support: H.323 and SIP-alg protocol NAT helper that enables correct routing of VoIP packets
Connection Monitoring: Ping Reboot, Wget Reboot, Periodic Reboot, LCP and ICMP for Link Inspection
Firewall: Port forwarding, traffic rules, custom rules, TTL target customization
Firewall Status Page: View all your firewall statistics, rules, and rule counters
Port Management: View device ports, enable and disable each one, turn auto-configuration on or off, change transfer speed, and more
Network topology: Visual representation of your network showing which devices are connected to which other devices
Hotspot: Captive portal (hotspot), internal/external Radius server, Radius MAC authentication, SMS authorization, SSO authentication, internal/external landing page, walled garden, user scripts, URL parameters, user groups, individual user or group restrictions, user management, 9 default customizable themes and the ability to upload and download custom hotspot themes
DHCP: Static and dynamic IP allocation, DHCP relay, DHCP server configuration, status, static leases: MAC with wildcards
QoS / Smart Queue Management (SQM): Prioritized traffic queuing by source/destination, service, protocol or port, WMM, 802.11e
DDNS: Support for >25 service providers, others can be configured manually
DNS over HTTPS: DNS over HTTPS proxy enables secure DNS lookup by routing DNS requests over HTTPS
Network Backup: Wi-Fi WAN, VRRP, wired options, all of which can be used as automatic Failover
Load Balancing: Balancing internet traffic across multiple WAN connections
SSHFS: Ability to mount remote file systems via SSH protocol
VRF support: Initial support for virtual routing and forwarding (VRF)
Traffic Management: Real-time monitoring, wireless signal graphs, traffic consumption history
Network protocols: TCP, UDP, IPv4, IPv6, ICMP, NTP, DNS, HTTP, HTTPS, SFTP, FTP, SMTP, SSL/TLS, ARP, VRRP, PPP, PPPoE, UPNP, SSH, DHCP, Telnet, SMPP, SNMP, MQTT, Wake On Lan (WOL), VXLAN
VoIP passthrough support: H.323 and SIP-alg protocol NAT helper that enables correct routing of VoIP packets
Connection Monitoring: Ping Reboot, Wget Reboot, Periodic Reboot, LCP and ICMP for Link Inspection
Firewall: Port forwarding, traffic rules, custom rules, TTL target customization
Firewall Status Page: View all your firewall statistics, rules, and rule counters
Port Management: View device ports, enable and disable each one, turn auto-configuration on or off, change transfer speed, and more
Network topology: Visual representation of your network showing which devices are connected to which other devices
Hotspot: Captive portal (hotspot), internal/external Radius server, Radius MAC authentication, SMS authorization, SSO authentication, internal/external landing page, walled garden, user scripts, URL parameters, user groups, individual user or group restrictions, user management, 9 default customizable themes and the ability to upload and download custom hotspot themes
DHCP: Static and dynamic IP allocation, DHCP relay, DHCP server configuration, status, static leases: MAC with wildcards
QoS / Smart Queue Management (SQM): Prioritized traffic queuing by source/destination, service, protocol or port, WMM, 802.11e
DDNS: Support for >25 service providers, others can be configured manually
DNS over HTTPS: DNS over HTTPS proxy enables secure DNS lookup by routing DNS requests over HTTPS
Network Backup: Wi-Fi WAN, VRRP, wired options, all of which can be used as automatic Failover
Load Balancing: Balancing internet traffic across multiple WAN connections
SSHFS: Ability to mount remote file systems via SSH protocol
VRF support: Initial support for virtual routing and forwarding (VRF)
Traffic Management: Real-time monitoring, wireless signal graphs, traffic consumption history
VPN
OpenVPN: Multiple clients and one server can run simultaneously, 27 encryption methods
OpenVPN encryption: DES-CBC 64, RC2-CBC 128, DES-EDE-CBC 128, DES-EDE3-CBC 192, DESX-CBC 192, BF-CBC 128, RC2-40-CBC 40, CAST5-CBC 128, RC2-64-CBC 64, AES-128-CBC 128, AES-128-CFB 128, AES-128-CFB1 128, AES-128-CFB8 128, AES-128-OFB 128, AES-128-GCM 128, AES-192-CFB 192, AES-192-CFB1 192, AES-192-CFB8 192, AES-192-OFB 192, AES-192-CBC 192, AES-192-GCM 192, AES-256-GCM 256, AES-256-CFB 256, AES-256-CFB1 256, AES-256-CFB8 256, AES-256-OFB 256, AES-256-CBC 256
IPsec: XFRM, IKEv1, IKEv2, with 14 IPsec encryption methods (3DES, DES, AES128, AES192, AES256, AES128GCM8, AES192GCM8, AES256GCM8, AES128GCM12, AES192GCM12, AES256GCM12, AES128GCM16, AES192GCM16, AES256GCM16)
GRE: GRE tunnel, GRE tunnel over IPsec support
PPTP, L2TP: Client and server instances can run simultaneously, L2TPv3, L2TP over IPsec support
Stunnel: Proxy designed to add TLS encryption to existing clients and servers without changes to the application's code
DMVPN: Method for building scalable IPsec VPNs, supporting Phase 2, Phase 3 and Dual Hub
SSTP: SSTP client instance support
ZeroTier: ZeroTier VPN client support
WireGuard: WireGuard VPN client and server support
Tinc: Tinc offers encryption, authentication, and compression in its tunnels. Client and server support.
Tailscale: Tailscale offers speed, stability, and simplicity over traditional VPNs. Encrypted point-to-point connections using the open WireGuard protocol
OpenVPN encryption: DES-CBC 64, RC2-CBC 128, DES-EDE-CBC 128, DES-EDE3-CBC 192, DESX-CBC 192, BF-CBC 128, RC2-40-CBC 40, CAST5-CBC 128, RC2-64-CBC 64, AES-128-CBC 128, AES-128-CFB 128, AES-128-CFB1 128, AES-128-CFB8 128, AES-128-OFB 128, AES-128-GCM 128, AES-192-CFB 192, AES-192-CFB1 192, AES-192-CFB8 192, AES-192-OFB 192, AES-192-CBC 192, AES-192-GCM 192, AES-256-GCM 256, AES-256-CFB 256, AES-256-CFB1 256, AES-256-CFB8 256, AES-256-OFB 256, AES-256-CBC 256
IPsec: XFRM, IKEv1, IKEv2, with 14 IPsec encryption methods (3DES, DES, AES128, AES192, AES256, AES128GCM8, AES192GCM8, AES256GCM8, AES128GCM12, AES192GCM12, AES256GCM12, AES128GCM16, AES192GCM16, AES256GCM16)
GRE: GRE tunnel, GRE tunnel over IPsec support
PPTP, L2TP: Client and server instances can run simultaneously, L2TPv3, L2TP over IPsec support
Stunnel: Proxy designed to add TLS encryption to existing clients and servers without changes to the application's code
DMVPN: Method for building scalable IPsec VPNs, supporting Phase 2, Phase 3 and Dual Hub
SSTP: SSTP client instance support
ZeroTier: ZeroTier VPN client support
WireGuard: WireGuard VPN client and server support
Tinc: Tinc offers encryption, authentication, and compression in its tunnels. Client and server support.
Tailscale: Tailscale offers speed, stability, and simplicity over traditional VPNs. Encrypted point-to-point connections using the open WireGuard protocol
OPC UA
Supported modes: Client, Server
Supported connection types: TCP
Supported connection types: TCP
Modbus
Supported modes: Server, Client
Supported connection types: TCP, USB
Custom registers: MODBUS TCP custom register block requests, which read/write to a file inside the router and can be used to extend MODBUS TCP client functionality
Supported data formats: 8-bit: INT, UINT 16-bit: INT, UINT (MSB or LSB first) 32-bit: float, INT, UINT (ABCD (big-endian), DCBA (little-endian), CDAB, BADC), HEX, ASCII
Supported connection types: TCP, USB
Custom registers: MODBUS TCP custom register block requests, which read/write to a file inside the router and can be used to extend MODBUS TCP client functionality
Supported data formats: 8-bit: INT, UINT 16-bit: INT, UINT (MSB or LSB first) 32-bit: float, INT, UINT (ABCD (big-endian), DCBA (little-endian), CDAB, BADC), HEX, ASCII
Data to server
Protocol: HTTP(S), MQTT, Azure MQTT
Data to Server: Extract parameters from multiple sources and different protocols and send them to a single server. Custom LUA scripting allows scripts to leverage the router's Data to Server feature.
Data to Server: Extract parameters from multiple sources and different protocols and send them to a single server. Custom LUA scripting allows scripts to leverage the router's Data to Server feature.
MQTT gateway
Modbus MQTT gateway: Enables sending commands and receiving data from a MODBUS server via an MQTT broker.
DNP3
Supported modes: Station, Outstation
Supported connections: TCP, USB
Supported connections: TCP, USB
DLMS/COSEM
DLMS support: DLMS – standard protocol for data exchange from electricity meters
Supported modes: Client
Supported connection types: TCP, USB
COSEM: Enables scanning of COSEM objects in meters for automatic identification and configuration
Supported modes: Client
Supported connection types: TCP, USB
COSEM: Enables scanning of COSEM objects in meters for automatic identification and configuration
AP
Teltonika Networks Web API support (beta): Extend the capabilities of your device by using a number of configurable API endpoints to retrieve or modify data. For more information, see this documentation: https://developers.teltonika-networks.com
Monitoring
WEB UI: HTTP/HTTPS, status, configuration, FW update, CLI, troubleshoot, multiple event log servers, firmware update availability notifications, event log, system log, kernel log, Internet status
FOTA: Firmware update from server, automatic notification
SSH: SSH (v1, v2)
TR-069: OpenACS, EasyCwmp, ACSLite, tGem, LibreACS, GenieACS, FreeACS, LibCWMP, Friendly tech, AVSystem
MQTT: MQTT Broker, MQTT publisher
SNMP: SNMP (v1, v2, v3), SNMP Trap, Brute force protection
JSON-RPC: Management API over HTTP/HTTPS
RMS: Teltonika Remote Management System (RMS)
FOTA: Firmware update from server, automatic notification
SSH: SSH (v1, v2)
TR-069: OpenACS, EasyCwmp, ACSLite, tGem, LibreACS, GenieACS, FreeACS, LibCWMP, Friendly tech, AVSystem
MQTT: MQTT Broker, MQTT publisher
SNMP: SNMP (v1, v2, v3), SNMP Trap, Brute force protection
JSON-RPC: Management API over HTTP/HTTPS
RMS: Teltonika Remote Management System (RMS)
IoT Platforms
ThingWorx: Enables monitoring of: WAN type, WAN IP
Cumulocity – Cloud of Things: Enables monitoring of: Device model, version and serial number, WAN type and IP. Has reboot and firmware upgrade capabilities
Azure IoT Hub: Can be configured with Data to Server to send all available parameters to the cloud. Supports Direct Method which enables running RutOS API calls from IoT Hub. Also has Plug and Play integration with Device Provisioning Service which enables automatic device registration to IoT Hub without manual intervention
Cumulocity – Cloud of Things: Enables monitoring of: Device model, version and serial number, WAN type and IP. Has reboot and firmware upgrade capabilities
Azure IoT Hub: Can be configured with Data to Server to send all available parameters to the cloud. Supports Direct Method which enables running RutOS API calls from IoT Hub. Also has Plug and Play integration with Device Provisioning Service which enables automatic device registration to IoT Hub without manual intervention
System properties
CPU: Quad-core ARM Cortex A7, 717 MHz
RAM: 256MB, DDR3
FLASH storage: 256 MB, SPI Flash
RAM: 256MB, DDR3
FLASH storage: 256 MB, SPI Flash
Firmware configuration
WEB UI: Update firmware from file, check firmware on server, configuration profiles, configuration backup
FOTA: Update firmware
RMS: Update firmware/configuration for multiple devices at once
Keep settings: Update firmware without losing current configuration
Restore Factory Settings: A full factory reset will restore all system settings, including IP address, PIN, and user data to the manufacturer's default configuration.
FOTA: Update firmware
RMS: Update firmware/configuration for multiple devices at once
Keep settings: Update firmware without losing current configuration
Restore Factory Settings: A full factory reset will restore all system settings, including IP address, PIN, and user data to the manufacturer's default configuration.
Firmware customization
Operating system: RutOS (OpenWrt-based Linux OS)
Supported languages: Busybox shell, Lua, C, C++, Python, Java via Package Manager
Development tools: SDK package with build environment provided
GPL Customization: You can create your own customized, branded firmware and web application by changing colors, logos, and other elements of our firmware to suit your or your customers' needs
Package Manager: The package manager is a service used to install additional software on the device
Supported languages: Busybox shell, Lua, C, C++, Python, Java via Package Manager
Development tools: SDK package with build environment provided
GPL Customization: You can create your own customized, branded firmware and web application by changing colors, logos, and other elements of our firmware to suit your or your customers' needs
Package Manager: The package manager is a service used to install additional software on the device
Location follow-up
NTRIP: Networked Transport of RTCM via Internet Protocol (NTRIP) protocol
USB
Data speed: USB 2.0
Applications: Samba share, USB-to-serial
External devices: Ability to connect external HDD, flash drive, additional modem, printer, USB serial adapter
Storage formats: FAT, FAT32, exFAT, NTFS (read only), ext2, ext3, ext4
Applications: Samba share, USB-to-serial
External devices: Ability to connect external HDD, flash drive, additional modem, printer, USB serial adapter
Storage formats: FAT, FAT32, exFAT, NTFS (read only), ext2, ext3, ext4
Input/Output
Input: 1 x digital input, 0–6 V detected as logic low, 8–30 V detected as logic high
Output: 1 x digital output, open collector output, max 30 V, 300 mA
Events: Email, RMS
I/O Juggler: Allows you to set certain I/O conditions to initiate an event
Output: 1 x digital output, open collector output, max 30 V, 300 mA
Events: Email, RMS
I/O Juggler: Allows you to set certain I/O conditions to initiate an event
Current
Connector: 4-pin industrial DC power connector
Input voltage: 9–50 V DC, reverse polarity protection, surge/transient protection
PoE (passive): Ability to power the device via the LAN1 port, not compatible with IEEE802.3af, 802.3at and 802.3bt standards, Mode B, 9–50 V DC
Power consumption: Max 9 W
Input voltage: 9–50 V DC, reverse polarity protection, surge/transient protection
PoE (passive): Ability to power the device via the LAN1 port, not compatible with IEEE802.3af, 802.3at and 802.3bt standards, Mode B, 9–50 V DC
Power consumption: Max 9 W
Physical interfaces
Ethernet: 4 x RJ45 ports, 10/100/1000 Mbps
I/O: 1 x digital input, 1 x digital output on 4-pin power connector
Status LEDs: 8 x LAN status LEDs, 1 x Power LED, 2 x 2.4 GHz and 5 GHz Wi-Fi LEDs
Power: 1 x 4-pin power connector
Antenna: 2 x RP-SMA for Wi-Fi, 1 x RP-SMA for Bluetooth
USB: 1 x USB A port for external devices
Reset: Restart/user reset/factory reset button
Other: 1 x ground screw
I/O: 1 x digital input, 1 x digital output on 4-pin power connector
Status LEDs: 8 x LAN status LEDs, 1 x Power LED, 2 x 2.4 GHz and 5 GHz Wi-Fi LEDs
Power: 1 x 4-pin power connector
Antenna: 2 x RP-SMA for Wi-Fi, 1 x RP-SMA for Bluetooth
USB: 1 x USB A port for external devices
Reset: Restart/user reset/factory reset button
Other: 1 x ground screw
Physical specifications
Housing material: Aluminum housing
Dimensions (W x H x D): 115 x 32.2 x 95.2 mm
Weight: 355g
Mounting options: DIN rail, wall mount, flat surface (all require additional kit)
Dimensions (W x H x D): 115 x 32.2 x 95.2 mm
Weight: 355g
Mounting options: DIN rail, wall mount, flat surface (all require additional kit)
Operating area
Operating temperature: -40°C to 75°C
Operating humidity: 10% to 90% non-condensing
Protection class: IP30
Operating humidity: 10% to 90% non-condensing
Protection class: IP30
Regulations & Type Approval
Regulations: CE, UKCA, EAC, UCRF, CITC, ICASA, ANRT, FCC, IC, PTCRB, RCM, IMDA, SIRIM, NTC, E-mark, Railway, UL/CSA Safety, CB, NOM, Anatel, Giteki
EMC
Standards: EN 55032:2015 + A11:2020, EN 55035:2017 + A11:2020, EN 301 489-1 V2.2.3, EN 301 489-3 V2.1.2, EN 301 489-17 V3.2.4
Radiation immunity: EN IEC 61000-4-3:2006 + A1:2008 + A2:2010
EFT (Electromagnetic Fast Transient): EN 61000-4-4:2012
Surge immunity (AC mains power port): EN 61000-4-5:2014 + A1:2017
CS (conducted interference): EN 61000-4-6:2014
DIP (Voltage Dips and Interruptions): EN 61000-4-11:2004
Radiation immunity: EN IEC 61000-4-3:2006 + A1:2008 + A2:2010
EFT (Electromagnetic Fast Transient): EN 61000-4-4:2012
Surge immunity (AC mains power port): EN 61000-4-5:2014 + A1:2017
CS (conducted interference): EN 61000-4-6:2014
DIP (Voltage Dips and Interruptions): EN 61000-4-11:2004
RF
Standards: EN 300 328 V2.2.2, EN 301 893 V2.1.1, EN 300 440 V2.2.1
Security
Standards: CE: EN IEC 62368-1:2020 + A11:2020, EN 62311:2020
RCM: AS/NZS 62368.1:2022
CB: IEC 62368-1:2018
RCM: AS/NZS 62368.1:2022
CB: IEC 62368-1:2018
Garanti
2 års fabriksgaranti

High-performance network segmentation

Fast wireless connection

Encrypted and protected remote connection

Centralized remote monitoring
Do you want to know more about the product?
Contact us for a demo or if you have any questions.