Specification |
Teltonika RUT901 – Technical Specifications
Mobile
Mobile module
4G (LTE) – Cat 4 up to 150 Mbps, 3G – Up to 42 Mbps, 2G – Up to 236.8 kbps
3GPP Release
Release 9
SIM switch
2 SIM cards, auto-switch cases: weak signal, data limit, SMS limit, roaming, no network, network denied, data connection fail, SIM idle protection
Status
Signal strength (RSSI), SINR, RSRP, RSRQ, EC/IO, RSCP, Bytes sent/received, connected band, IMSI, ICCID
SMS
SMS status, SMS configuration, send/read SMS via HTTP POST/GET, EMAIL to SMS, SMS to EMAIL, SMS to HTTP, SMS to SMS, scheduled SMS, SMS autoreply, SMPP
USSD
Supports sending and reading Unstructured Supplementary Service Data messages
Black/White list
Operator black/white list
Multiple PDN
Possibility to use different PDNs for multiple network access and services
Band management
Band lock, Used band status display
APN
Auto APN
Bridge
Direct connection (bridge) between mobile ISP and device on LAN
Passthrough
Router assigns its mobile WAN IP address to another device on LAN
Wireless
Wireless mode
IEEE 802.11b/g/n, Access Point (AP), Station (STA)
WiFi security
WPA-PSK/WPA2-PSK Mixed Mode, WPA2-PSK, WPA2-EAP, WPA2-EAP/WPA3-EAP Mixed Mode, WPA3-EAP, WPA2-PSK/WPA3-SAE Mixed Mode, WPA3-SAE, OWE; AES-CCMP, TKIP, Auto Cipher modes, client separation
SSID/ESSID
SSID stealth mode and access control based on MAC address
WiFi users
Up to 100 simultaneous connections
Wireless Hotspot
Captive portal (Hotspot), internal/external Radius server, built-in customizable landing page
Ethernet
WAN
1 x WAN port 10/100 Mbps, compliance IEEE 802.3, IEEE 802.3u standards, supports auto MDI/MDIX
LAN
3 x LAN ports, 10/100 Mbps, compliance IEEE 802.3, IEEE 802.3u standards, supports auto MDI/MDIX
Network
Routing
Static routing, Dynamic routing (BGP, OSPF v2, RIP v1/v2, NHRP)
Network protocols
TCP, UDP, IPv4, IPv6, ICMP, NTP, DNS, HTTP, HTTPS, FTP, SMTP, SSL v3, TLS, ARP, VRRP, PPP, PPPoE, UPNP, SSH, DHCP, Telnet, SMPP, SMNP, MQTT, Wake On Lan (WOL)
VoIP passthrough support
H.323 and SIP-alg protocol NAT helpers, allowing proper routing of VoIP packets
Connection monitoring
Ping Reboot, Wget Reboot, Periodic Reboot, LCP and ICMP for link inspection
Firewall
Port forward, traffic rules, custom rules
DHCP
Static and dynamic IP allocation, DHCP Relay, Relayd
QoS / Smart Queue Management (SQM)
Traffic priority queuing by source/destination, service, protocol or port, WMM, 802.11e
DDNS
Supported >25 service providers, others can be configured manually
Network backup
WiFi WAN, Mobile, VRRP, Wired options, each of which can be used as an automatic Failover
Load balancing
Balance Internet traffic over multiple WAN connections
Hotspot
Captive portal (Hotspot), internal/external Radius server, SMS authorization, internal/external landing page, walled garden, user scripts, URL parameters, user groups, individual user or group limitations, user management, 9 default customizable themes
SSHFS
Possibility to mount remote file system via SSH protocol (not available in standard FW)
Security
Authentication
Pre-shared key, digital certificates, X.509 certificates, TACACS+, Radius, IP & Login attempts block
Firewall
Pre-configured firewall rules can be enabled via WebUI, unlimited firewall configuration via CLI; DMZ; NAT; NAT-T
Attack prevention
DDOS prevention (SYN flood protection, SSH attack prevention, HTTP/HTTPS attack prevention), port scan prevention (SYN-FIN, SYN-RST, X-mas, NULL flags, FIN scan attacks)
VLAN
Port and tag based VLAN separation
Mobile quota control
Custom data limits for both SIM cards
WEB filter
Blacklist for blocking out unwanted websites, Whitelist for specifying allowed sites only
Access control
Flexible access control of TCP, UDP, ICMP packets, MAC address filter
VPN
OpenVPN
Multiple clients and a server can run simultaneously, 27 encryption methods
OpenVPN Encryption
DES-CBC 64, RC2-CBC 128, DES-EDE-CBC 128, DES-EDE3-CBC 192, DESX-CBC 192,
BF-CBC 128, RC2-40-CBC 40, CAST5-CBC 128, RC2-64-CBC 64, AES-128-CBC 128, AES-128-CFB 128, AES-128-CFB1 128, AES-128-CFB8 128, AES-128-OFB 128, AES-128-GCM 128, AES-192-CFB 192, AES-192-CFB1 192, AES-192-CFB8 192, AES-192-OFB 192, AES-192-CBC 192, AES-192-GCM 192, AES-256-GCM 256, AES-256-CFB 256, AES-256-CFB1 256, AES-256-CFB8 256, AES-256-OFB 256, AES-256-CBC 256
IPsec
IKEv1, IKEv2, with 14 encryption methods for IPsec (3DES, DES, AES128, AES192, AES256, AES128GCM8, AES192GCM8, AES256GCM8, AES128GCM12, AES192GCM12, AES256GCM12, AES128GCM16, AES192GCM16, AES256GCM16)
GRE
GRE tunnel, GRE tunnel over IPsec support
PPTP, L2TP
Client/Server instances can run simultaneously, L2TPv3, L2TP over IPsec support
Stunnel
Proxy designed to add TLS encryption functionality to existing clients and servers without any changes in the program’s code
DMVPN
Method of building scalable IPsec VPNs
SSTP
SSTP client instance support
ZeroTier
ZeroTier VPN client support
WireGuard
WireGuard VPN client and server support
Tinc
Tinc offers encryption, authentication, and compression in its tunnels. Client and server support.
|