Products / SD-WAN Platform

SD-WAN Platform

One SD-WAN platform, from branch to data center

One platform runs the whole portfolio — from all-in-one branch and edge appliances at the spokes to high-capacity gateways at the hub — converging SD-WAN, firewall, VPN, Wi-Fi, and IoT under a single cloud. High-performance and cost-effective, with no hidden software licensing.

RansNet SD-Branch product family — UA-520, HSA-520, UA-800, and XE-300 branch routers
RansNet CMG SD-WAN gateway — the data-center hub of the platform

Capabilities

One platform. The whole network stack.

From connectivity and security to Wi-Fi and IoT, the platform replaces a rack of separate boxes — the same capabilities across branch appliances and data-center gateways, all configured and monitored centrally through mfusion.

All-in-one Appliance

Router, stateful firewall, VPN, Wi-Fi and cellular converged into one appliance — fewer boxes, vendors, and licenses at every site.

Multi-WAN, bonding & failover

Aggregate fiber, broadband, 4G/5G and satellite with WAN/VPN bonding for more bandwidth, plus fast failover — sub-second detection in suitable deployments — on packet loss, latency, or jitter.

VPN overlays

IPSec, WireGuard, GRE, L2TPv3, SSL VPN and VXLAN tunnels in hub-and-spoke or mesh — with proven interoperability to Fortinet, Meraki, and Cisco.

Traffic steering (PBR)

Route by source, application, or port — break SaaS out locally while backhauling sensitive traffic through the tunnel.

Traffic shaping (QoS)

Class-based bandwidth allocation and per-IP limits protect latency-sensitive apps and stop any user monopolizing a shared link.

Application & web filtering

Block by application, domain, or category — firewall objects, DNS filtering, and cloud category lists, layered for bypass resistance.

Segmentation & multi-tenancy

Split each SSID, port, or user group into its own VLAN with dedicated firewall and QoS — and isolate whole tenants end-to-end with VRF over the SD-WAN overlay.

Layer-2 SD-WAN

Extend VLANs and broadcast/OT traffic across sites with VXLAN Layer-2 tunnels — for VM mobility, legacy protocols, and industrial networks.

Native 4G/5G

Integrated dual-SIM 4G/5G — global module options including NSA/SA and mmWave (by model / region) with carrier aggregation. Automatic backup, or the primary link where fiber can’t reach.

Wi-Fi 6 & guest portal

Built-in Wi-Fi 6 with captive portal, RADIUS, and per-user policies. Pair with the HSG gateway and cloud ad manager to turn guest Wi-Fi into a revenue stream.

IoT integration

Built-in MQTT broker collects sensor data at the edge and forwards it to mfusion or your cloud — with store-and-forward through outages, plus Bluetooth and Z-Wave on select models.

Firewall & access control

Zone-based stateful firewall — NAT, port forwarding, and reusable objects — with Network Access Control, so security is built into every site, not bolted on.

Secure by default

Devices open an outbound-only TLS session to mfusion over a secure API — no inbound ports or services are exposed. Everything stays locked down until a service is explicitly enabled, each safeguarded separately.

Central management

Zero-touch provisioning, template-based config, monitoring, and fleet-wide firmware — every site managed from one mfusion console.

Cloud or on-premises

Run mfusion in the RansNet cloud or fully on-premises — the same orchestration and control, with data kept in your own environment when data-sovereignty or compliance demands it.

Explore the capabilities in the docs →

Connectivity

Optimized for wired & wireless WAN (5G/4G)

Every branch and edge model embeds a dedicated next-generation 4G or 5G/NR modem — with its own chipset and processing power — for reliable, high-speed cellular WAN over a direct SIM, with global 4G/5G module options — NSA/SA and mmWave variants by model and region.

  • Dedicated cellular modem with carrier aggregation for maximum speed (UA-800: 4G/LTE, 5G-NSA or 5G-SA)
  • Every Gigabit Ethernet port configurable as WAN or LAN
  • WAN bonding aggregates wired + wireless bandwidth across links
  • Fast failover — sub-second detection in suitable deployments — on packet loss, latency, or jitter
RansNet SD-Branch wired and wireless WAN — dedicated dual-SIM 4G/5G modems aggregating fiber, broadband, leased line, and cellular links

Complete feature set

Enterprise features, no hidden licensing

Everything below is included across the platform — from branch appliances to gateways — one all-in-one package, centrally managed by mfusion.

Connectivity & Routing

  • Multi-WAN & VPN bonding, fast failover
  • Static routing & Policy-Based Routing
  • Dynamic routing — RIP, OSPF, BGP
  • IPv4 & IPv6
  • DHCP client & server
  • VLAN/trunking (802.1q), bridging (802.1d)
  • High availability (VRRP)

VPN & Overlay

  • IPSec, WireGuard, GRE, L2TPv3
  • SSL VPN
  • VXLAN Layer-2 & Layer-3
  • VRF over SD-WAN

Security

  • Firewall — NAT, SNAT, DNAT, port forwarding
  • Network Access Control (NAC)
  • Application / URL / DNS filtering
  • QoS bandwidth control

Wi-Fi & Guest

  • Wi-Fi 6, multi-SSID with per-SSID VLAN
  • External HotSpot portal (HSG)
  • Wi-Fi monetization & cloud ad manager

IoT & Mobility

  • Built-in MQTT broker
  • Bluetooth & Z-Wave (select models)
  • GNSS/GPS & ignition sensing (mobility models)

Management

  • mfusion orchestration (SD-WAN, Wi-Fi, LAN, NAC, portal)
  • Zero-touch provisioning
  • Cloud monitoring, alerting & reporting
  • Online firmware patching
  • SNMP, Syslog, tcpdump, iperf3, OpenFlow

Observability

See every flow, across every site

You can't manage what you can't see. The platform exports NetFlow from every appliance to a built-in collector, turning raw traffic into per-application and per-user analytics in mfusion — no separate probes or SPAN taps.

  • Real-time per-application and per-user traffic breakdowns
  • Spot bottlenecks, heavy talkers, and anomalies at a glance
  • NetFlow export plus an on-box collector — no extra hardware
  • Fleet-wide dashboards and history in a single pane of glass
RansNet NetFlow analytics in mfusion — per-application and per-user traffic visibility across sites

Reliability

UDP Booster — throughput on lossy links

On lossy 4G/5G and satellite links, every dropped packet forces TCP to back off. UDP Booster wraps traffic in a Reed-Solomon FEC tunnel that rebuilds lost packets at the far end — no waiting for retransmission.

  • Cuts effective packet loss to a fraction of a percent
  • Steadier latency for VoIP, video, and remote desktop
  • Rides the VPN overlay — accelerates all traffic (TCP, UDP, ICMP)
  • Ideal for maritime, vehicle, and remote sites
UDP Booster — Reed-Solomon forward error correction rebuilds lost packets, cutting effective packet loss on lossy 4G/5G and satellite links

How it fits

From the branch to the cloud

Branch devices connect through the all-in-one router, across a multi-WAN underlay and encrypted VPN overlay, to the RansNet gateway and mfusion.

SD-Branch topology — branch LAN, Wi-Fi and IoT devices connect through the all-in-one branch router across a multi-WAN underlay and encrypted VPN overlay to the HQ/CMG gateway and mfusion

Models

Choose the right appliance

Branch and edge appliances at the spokes, high-capacity gateways at the hub — all running the same platform. Full specifications live on the products page.

Branch & edge appliances

UA-520

UA-520

5G branch router with Wi-Fi 6

Datasheet (PDF) →
HSA-520

HSA-520

4G branch router with Wi-Fi 6

Datasheet (PDF) →
UA-800

UA-800

Industrial & vehicle-grade 5G

Datasheet (PDF) →
XE-300

XE-300

Ultra-compact industrial router

Datasheet (PDF) →

SD-WAN gateways (hub)

CMG-1500 / 2000

CMG-1500 / 2000

Business & enterprise hub — 1.5–10 Gbps, up to 500 users

Datasheet (PDF) →
CMG-3000

CMG-3000

Enterprise 1U — 10 Gbps, 1M connections, optional redundant PSU

Datasheet (PDF) →
CMG-5000

CMG-5000

Carrier-grade 2U — 10 Gbps, 3,000 users, redundant PSU

Datasheet (PDF) →

Standardize your whole network on one platform

Tell us about your sites and links — we'll help you design the right SD-WAN rollout.

Talk to an Expert