-
$
The ER7406 is a gigabit VPN gateway (router) integrated with the Omada SDN system, designed for 19" (1U) Rack mounting. The device functions as the network boundary layer, performing routing, Network Address Translation (NAT), and traffic management. It is equipped with a multi-port interface, including Gigabit Ethernet ports that can be configured as WAN or LAN ports, providing flexibility in network architecture. The device offers extensive support for VPN (Virtual Private Network) for securely connecting remote locations, supporting protocols such as IPsec and SSL VPN. It features a built-in firewall for traffic segmentation and attack protection, and provides functions for bandwidth management and access control. The gateway is managed centrally by the Omada Controller, enabling Zero-Touch Provisioning (ZTP) and centralized monitoring.

Up to 5 WAN Ports
1 USB WAN for Mobile Broadband

SDN (Software Defined Networking) Platform and Cloud Access
Manage your Access Points, Switches, and Gateways located in multiple locations through a single interface.


Secure and Efficient VPN
SSL/ IPSec / GRE / WireGuard / PPTP / L2TP VPN and OpenVPN easily build protected VPN tunnels, enabling secure internet browsing, inter-branch communication, remote work, and learning from home.
DPI (Deep Packet Inspection)
Utilize Deep Packet Inspection (DPI) to effectively block or prioritize specific applications to enhance security and optimize bandwidth allocation. Easily manage internet access permissions and policies through IP/MAC/Location/URL Filtering and Access Control List (ACL).


Attack Prevention with Over 4000 Signature Rules
Increase the effectiveness of threat detection and protection with the integrated IDS/IPS engine. Benefit from continuous security thanks to an extensive attack prevention signature database, containing over 4000 regularly updated signature rules.
Protection Against DoS / DDoS Attacks
The gateway automatically detects and blocks Denial of Service (DoS) attacks, including TCP/UDP/ICMP Flooding, Ping of Death, and related threats, thereby ensuring uninterrupted network performance.

Specifications
| TP-Link ER7406 | |
| Transmission Security | |
|---|---|
| Access Control | Access Control based on Source/Destination IP Address |
| Filtering | WEB Group Filtering§ URL Filtering Network Security |
| ARP Attack Protection | GARP Packet Sending ARP Scanning§ IP and MAC Address Binding |
| Network Attack Protection | TCP/UDP/ICMP Flood Defense TCP Scan Blocking (Stealth FIN/Xmas/Null) Blocking of WAN ping packets |
| Hardware Features | |
| Standards and Protocols | IEEE 802.3, IEEE802.3u, IEEE802.3ab, IEEE802.3z, IEEE 802.3x, IEEE 802.1q TCP/IP, DHCP, ICMP, NAT, PPPoE, NTP, HTTP, HTTPS, DNS, IPSec, PPTP, L2TP, OpenVPN, WireGuard VPN, GRE VPN, SNMP |
| Ports | 1 Gigabit SFP WAN/LAN slot 1 Gigabit WAN port 4 Gigabit LAN/WAN ports 1 USB 3.0 Port (supporting USB Storage and USB LTE Modems) |
| Network Cabling | • 10BASE-T: UTP category 3, 4, 5 cable (up to 100 m) EIA/TIA-568 100Ω STP cable (up to 100 m) • 100BASE-TX: UTP category 5, 5e cable (up to 100 m) EIA/TIA-568 100Ω STP cable (up to 100 m) • 1000BASE-T: UTP category 5, 5e, 6 cable (up to 100 m) |
| Fan Quantity | Fanless |
| Buttons | Reset Button |
| Power Supply | 100-240V AC, 50/60Hz |
| Flash Memory | 128 MB NAND |
| DRAM Memory | 512 MB DDR4 |
| LEDs | PWR, SYS, SFP, USB, WAN(1000M Link/Act, 100/10M Link/Act), WAN/LAN (1000M Link/Act, 100/10M Link/Act) |
| Dimensions (W x D x H) | 294 × 140 × 44 mm (11.6 × 5.5 × 1.7 inches) |
| Protection | 4 kV Surge Protection |
| Casing | Steel |
| Mounting | Rack-mountable Desktop mountable |
| Max. Power Consumption | 7.5 W (with USB 3.0 device connected) 4.5 W (without USB 3.0 device connected) |
| Performance | |
| IPS Throughput | TCP: 229 Mbps UDP: 188 Mbps |
| DPI Throughput | TCP: 933 Mbps UDP: 927 Mbps |
| GRE | Unencrypted: 611.9 Mbps Encrypted: 325.0 Mbps |
| WireGuard VPN | 341.3 Mbps |
| Concurrent Sessions | 150,000 |
| New Sessions Per Second | 5,300 |
| NAT (Static IP) | 945.3 Mbps / 940.5 Mbps |
| NAT(DHCP) | 939.6 Mbps / 940.9 Mbps |
| NAT(PPPoE) | 943.6 Mbps / 940.9 Mbps |
| NAT (L2TP) | 880.1 Mbps / 859.0 Mbps |
| NAT (PPTP) | 855.0 Mbps / 907.2 Mbps |
| IPsec VPN Throughput | ESP-SHA1-AES256: 617.1 Mbps ESP-SHA256-AES256: 592.8 Mbps ESP-SHA384-AES256: 592.4 Mbps ESP-SHA512-AES256: 604.5 Mbps |
| OpenVPN | 139.1 Mbps |
| L2TP VPN Throughput | Unencrypted: 977.4 Mbps Encrypted: 334.6 Mbps |
| PPTP VPN Throughput | Unencrypted: 1064.1 Mbps Encrypted: 206.8 Mbps |
| SSL VPN Throughput | 131.6 Mbps |
| Packet Forwarding Rate 66 Bytes | 1,453,489 pps / 1,453,488 pps |
| Packet Forwarding Rate 1,518 Bytes | 81,279 pps / 81,275 pps |
| Basic Functions | |
| WAN Connection Type | Static IP Dynamic IP PPPoE (MRU configuration support) PPTP L2TP |
| MAC Address Clone | WAN/LAN MAC Address Change (LAN MAC Address can only be modified in Standalone Mode) |
| DHCP | DHCP Server DHCPv6 PD Server (Standalone Mode Only) DHCP Option Customization DHCP Address Reservation Multi-IP Interfaces Multi-Net DHCP |
| IPv6 | Static IP SLAAC DHCPv6 PPPoE 6to4 Tunnel Pass-Through Non-Address Mode |
| VLAN | 802.1Q VLAN |
| IPTV | IGMP v2/v3 Proxy Custom Mode Bridge Mode |
| Advanced Functions | |
| Advanced Routing | Static Routing Policy Routing RIP (Available in Standalone Mode) OSPF (Available in Standalone Mode) |
| Bandwidth Control | IP-based Bandwidth Control |
| Load Balance | Intelligent Load Balancing Application Optimized Routing Link Backup (Timing, Failover) Online Detection |
| NAT | One-to-One NAT Multi-Net NAT Port Forwarding Port Triggering§ NAT-DMZ FTP/H.323/SIP/IPSec/PPTP ALG UPnP |
| Session Limit | IP-based Session Limit |
| VPN | |
| GRE | Standalone Mode Only |
| SD-WAN | √ (Only in Controller Mode) |
| SSL VPN | 50 Tunnels |
| IPsec VPN | 100 IPsec VPN Tunnels LAN-to-LAN, Client-to-LAN 2 Negotiation Modes - Main/Aggressive Encryption DES, 3DES, AES128, AES192, AES256 IPsec Failover IKEv1/v2 Authentication MD5, SHA1, SHA2-384, and SHA2-512 NAT Traversal (NAT-T) Dead Peer Detection (DPD) Perfect Forward Secrecy (PFS) |
| PPTP VPN | PPTP VPN Server PPTP VPN Client (10)** 50 Tunnels PPTP with MPPE Encryption |
| L2TP VPN | L2TP VPN Server L2TP VPN Client (10)** 50 Tunnels L2TP over IPSec |
| OpenVPN | OpenVPN Server OpenVPN Client (5)** 55 OpenVPN Tunnels "Certificate + Account" Mode Full Mode |
| WireGuard VPN | 20 Tunnels |
| Authentication | |
| Network Authentication | No Authentication Simple Password* Hotspot(Local User / Voucher* / SMS* / Radius*) External Radius Server External Portal Server* LDAP§ |
| Management | |
| Omada App | Yes. Requires the use of an Omada Hardware Controller, Omada Cloud-Based Controller, or Omada Software Controller. |
| Centralized Management | Omada Cloud-Based Controller Omada Hardware Controller Omada Software Controller |
| Cloud Access | Yes. Requires the use of an Omada Hardware Controller, Omada Cloud-Based Controller, or Omada Software Controller. |
| Services | Dynamic DNS (Dyndns, No-IP, Peanuthull, Comexe, Custom DDNS) |
| Support | Web Management Interface Remote Management Configuration Export and Import SNMP v1/v2c/v3 Diagnostics: Ping and Traceroute (Standalone Mode Only) NTP Synchronization (Standalone Mode Only) Port Mirroring CLI (Standalone Mode Only) Syslog Support |
| Zero-Touch Provisioning (ZTP) | Yes. Requires the use of the Omada Cloud-Based Controller. |
| Management Panel Functions | Automatic Device Discovery Intelligent Network Health Monitoring Abnormal Event Warnings Unified Configuration Process Restart Schedule Customized Network Login Page |
| Others | |
| Package Contents | ER706WP-4G Power Adapter Quick Installation Guide |
| System Requirements | Microsoft Windows 98SE, NT, 2000, XP, Vista™, 7, 8, 8.1, 10, 11 MAC OS NetWare UNIX Linux |
| Operating Environment | Operating Temperature: 0–40 ℃ (32–104 ℉) Storage Temperature: -40–70 ℃ (-40–158 ℉) Operating Humidity: 10–90%, non-condensing Storage Humidity: 5–90% non-condensing |





