Products / SD-WAN Platform

SD-WAN Platform

One SD-WAN platform, from branch to data center

One platform runs the whole portfolio — from all-in-one branch and edge appliances at the spokes to high-capacity gateways at the hub — converging SD-WAN, firewall, VPN, Wi-Fi, and IoT under a single cloud. High-performance and cost-effective, with no hidden software licensing.

RansNet SD-Branch product family — UA-520, HSA-520, UA-800, and XE-300 branch routers
RansNet CMG SD-WAN gateway — the data-center hub of the platform

Capabilities

One platform. The whole network stack.

From connectivity and security to Wi-Fi and IoT, the platform replaces a rack of separate boxes — the same capabilities across branch appliances and data-center gateways, all configured and monitored centrally through mfusion.

All-in-one Appliance

Router, stateful firewall, VPN, Wi-Fi and cellular converged into one appliance — fewer boxes, vendors, and licenses at every site.

Multi-WAN, bonding & failover

Aggregate fiber, broadband, 4G/5G and satellite with WAN/VPN bonding for more bandwidth, plus fast failover — sub-second detection in suitable deployments — on packet loss, latency, or jitter.

VPN overlays

IPSec, WireGuard, GRE, L2TPv3, SSL VPN and VXLAN tunnels in hub-and-spoke or mesh — with proven interoperability to Fortinet, Meraki, and Cisco.

Traffic steering (PBR)

Route by source, application, or port — break SaaS out locally while backhauling sensitive traffic through the tunnel.

Traffic shaping (QoS)

Class-based bandwidth allocation and per-IP limits protect latency-sensitive apps and stop any user monopolizing a shared link.

Application & web filtering

Block by application, domain, or category — firewall objects, DNS filtering, and cloud category lists, layered for bypass resistance.

Segmentation & multi-tenancy

Split each SSID, port, or user group into its own VLAN with dedicated firewall and QoS — and isolate whole tenants end-to-end with VRF over the SD-WAN overlay.

Layer-2 SD-WAN

Extend VLANs and broadcast/OT traffic across sites with VXLAN Layer-2 tunnels — for VM mobility, legacy protocols, and industrial networks.

Native 4G/5G

Integrated dual-SIM 4G/5G — global module options including NSA/SA and mmWave (by model / region) with carrier aggregation. Automatic backup, or the primary link where fiber can’t reach.

Wi-Fi 6 & guest portal

Built-in Wi-Fi 6 with captive portal, RADIUS, and per-user policies. Pair with the HSG gateway and cloud ad manager to turn guest Wi-Fi into a revenue stream.

IoT integration

Built-in MQTT broker collects sensor data at the edge and forwards it to mfusion or your cloud — with store-and-forward through outages, plus Bluetooth and Z-Wave on select models.

Firewall & access control

Zone-based stateful firewall — NAT, port forwarding, and reusable objects — with Network Access Control, so security is built into every site, not bolted on.

Secure by default

Devices open an outbound-only TLS session to mfusion over a secure API — no inbound ports or services are exposed. Everything stays locked down until a service is explicitly enabled, each safeguarded separately.

Central management

Zero-touch provisioning, template-based config, monitoring, and fleet-wide firmware — every site managed from one mfusion console.

Cloud or on-premises

Run mfusion in the RansNet cloud or fully on-premises — the same orchestration and control, with data kept in your own environment when data-sovereignty or compliance demands it.

Explore the capabilities in the docs →

Connectivity

Optimized for wired & wireless WAN (5G/4G)

Every branch and edge model embeds a dedicated next-generation 4G or 5G/NR modem — with its own chipset and processing power — for reliable, high-speed cellular WAN over a direct SIM, with global 4G/5G module options — NSA/SA and mmWave variants by model and region.

  • Dedicated cellular modem with carrier aggregation for maximum speed (UA-800: 4G/LTE, 5G-NSA or 5G-SA)
  • Every Gigabit Ethernet port configurable as WAN or LAN
  • WAN bonding aggregates wired + wireless bandwidth across links
  • Fast failover — sub-second detection in suitable deployments — on packet loss, latency, or jitter
RansNet SD-Branch wired and wireless WAN — dedicated dual-SIM 4G/5G modems aggregating fiber, broadband, leased line, and cellular links

Multi-WAN

Blend every link into one resilient connection

Combine every link a site has — fiber, broadband, leased line, and 4G/5G. RansNet load-balances across all active links and fails over automatically when one degrades, so users stay online.

  • Weighted load balancing across every active link
  • ICMP health checks with automatic failover in seconds
  • Policy-based routing by source/destination/port/protocol/application
  • Fiber, broadband, leased line, and cellular — no per-feature licensing

See multi-WAN in the docs →

RansNet multi-WAN — fiber, broadband, and 5G backup links converge on a five-port WAN appliance that load-balances and fails over automatically to the LAN

VPN Overlays

Any protocol, any topology, any site

Connect head office, branches, data center, and cloud over encrypted overlays — in whatever protocol and topology each site needs, mixed and matched without re-architecting.

  • Five protocols — WireGuard, IPsec, SSL VPN, GRE, and VXLAN
  • Hub-and-spoke, spoke-to-spoke, or full-mesh topologies
  • Layer 2 or Layer 3 overlays, with BGP/OSPF dynamic routing
  • IPsec interoperability with Cisco, Fortinet, Palo Alto, AWS, and Azure

See VPN options in the docs →

RansNet VPN overlays — WireGuard, IPsec, SSL VPN, GRE, and VXLAN connecting head office, branches, retail, data center, and factory in hub-and-spoke, spoke-to-spoke, or full-mesh over Layer 2 or Layer 3

Patent-Pending Innovation

Mesh VPN that builds itself

An any-to-any mesh normally means exchanging keys, tunnel IPs, and endpoints between every pair of sites — effort that explodes as the network grows. RansNet's patent-pending mesh VPN technology centralizes every tunnel parameter in mfusion and builds the WireGuard mesh automatically.

  • Direct site-to-site WireGuard tunnels, established automatically — no per-pair configuration
  • Tunnel IPs auto-assigned and keys distributed centrally — conflict-free at any scale
  • Works over dynamic public IPs — peers push changes and the mesh re-syncs
  • Add or remove a site and the topology re-synchronizes on its own

Patent pending — Singapore application 10202503044X, RansNet Singapore Pte Ltd.

RansNet patent-pending mesh VPN — mfusion centrally orchestrates provisioning, keys, tunnel IPs, and topology sync while five sites form direct any-to-any WireGuard tunnels

Security

Block threats before they resolve

The router redirects every DNS request to RansNet's cloud resolver, which enforces category-based policy network-wide — no agent on any device. Malware, phishing, adult, and gambling domains are stopped before a connection is ever made.

  • Category filtering — malware, phishing, adult, gambling, social, streaming, and more
  • Custom allow and block lists, propagated in minutes
  • No client agent — applies to every device on the LAN automatically
  • Cloud-delivered and always current, with per-domain query logs and reports

See web filtering in the docs →

RansNet cloud DNS web filtering — the router redirects LAN DNS to a cloud resolver that allows approved sites and blocks malicious, adult, gambling, and phishing categories, with central policy and reporting

Complete feature set

Enterprise features, no hidden licensing

Everything below is included across the platform — from branch appliances to gateways — one all-in-one package, centrally managed by mfusion.

Connectivity & Routing

  • Multi-WAN & VPN bonding, fast failover
  • Static routing & Policy-Based Routing
  • Dynamic routing — RIP, OSPF, BGP
  • IPv4 & IPv6
  • DHCP client & server
  • VLAN/trunking (802.1q), bridging (802.1d)
  • High availability (VRRP)

VPN & Overlay

  • IPSec, WireGuard, GRE, L2TPv3
  • SSL VPN
  • VXLAN Layer-2 & Layer-3
  • VRF over SD-WAN

Security

  • Firewall — NAT, SNAT, DNAT, port forwarding
  • Network Access Control (NAC)
  • Application / URL / DNS filtering
  • QoS bandwidth control

Wi-Fi & Guest

  • Wi-Fi 6, multi-SSID with per-SSID VLAN
  • External HotSpot portal (HSG)
  • Wi-Fi monetization & cloud ad manager

IoT & Mobility

  • Built-in MQTT broker
  • Bluetooth & Z-Wave (select models)
  • GNSS/GPS & ignition sensing (mobility models)

Management

  • mfusion orchestration (SD-WAN, Wi-Fi, LAN, NAC, portal)
  • Zero-touch provisioning
  • Cloud monitoring, alerting & reporting
  • Online firmware patching
  • SNMP, Syslog, tcpdump, iperf3, OpenFlow

How it fits

From the branch to the cloud

Branch devices connect through the all-in-one router, across a multi-WAN underlay and encrypted VPN overlay, to the RansNet gateway and mfusion.

SD-Branch topology — branch LAN, Wi-Fi and IoT devices connect through the all-in-one branch router across a multi-WAN underlay and encrypted VPN overlay to the HQ/CMG gateway and mfusion

Models

Choose the right appliance

Branch and edge appliances at the spokes, high-capacity gateways at the hub — all running the same platform. Full specifications live on the products page.

Branch & edge appliances

UA-520

UA-520

5G branch router with Wi-Fi 6

Datasheet (PDF) →
HSA-520

HSA-520

4G branch router with Wi-Fi 6

Datasheet (PDF) →
UA-800

UA-800

Industrial & vehicle-grade 5G

Datasheet (PDF) →
XE-300

XE-300

Ultra-compact industrial router

Datasheet (PDF) →

SD-WAN gateways (hub)

CMG-1500 / 2000

CMG-1500 / 2000

Business & enterprise hub — 1.5–10 Gbps, up to 500 users

Datasheet (PDF) →
CMG-3000

CMG-3000

Enterprise 1U — 10 Gbps, 1M connections, optional redundant PSU

Datasheet (PDF) →
CMG-5000

CMG-5000

Carrier-grade 2U — 10 Gbps, 3,000 users, redundant PSU

Datasheet (PDF) →

Standardize your whole network on one platform

Tell us about your sites and links — we'll help you design the right SD-WAN rollout.

Talk to an Expert