Overview
The XVR-800 acts as a central gateway between the local network and one or two upstream links. Both 10G ports – copper and fiber – can be configured as WAN or LAN in software, so administrators can adapt the port layout to the site rather than to the hardware. The SFP+ slot accepts a wide range of transceivers, supporting multi-mode fiber from 550 m to 2 km and single-mode or WDM fiber up to 120 km, which allows the router to uplink directly to a backbone switch or monitoring center over long distances.
On the security side, the router pairs a stateful packet inspection (SPI) firewall and DoS/DDoS mitigation with Secure Boot, a built-in Hardware TRNG and ML-KEM for hybrid key exchange in TLS.
| Model | Key specifications | Best for |
|---|---|---|
| XVR-800 | Dual 10G WAN (10GBASE-T + 10G SFP+), 4 × Gigabit LAN, 9.4 Gbps NAT throughput, full VPN suite, ML-KEM hybrid TLS key exchange, Secure Boot, Hardware TRNG, AP Controller, SD-WAN | Enterprise and SMB secure WAN, multi-site VPN and centralized Wi-Fi management |
| ZT-800 | Dual 10G Zero Trust Security Gateway with 4-Port 10/100/1000T (same 10G platform as the XVR-800) | Identity-centric Zero Trust network access control |
Hardware and Interfaces
The XVR-800 provides four 10/100/1000BASE-T RJ45 LAN ports (Ports 1–4), one 1G/2.5G/5G/10GBASE-T RJ45 port (Port 5) and one 1G/2.5G/10GBASE-X SFP+ slot (Port 6). Ports 5 and 6 can each operate in WAN or LAN mode through software configuration. A USB 2.0 port handles configuration backup and restoration, and a reset button returns the unit to factory defaults.
The router ships in a metal 1U enclosure measuring 330.2 × 200 × 43.1 mm and weighing 1725 g. It can be placed on a desktop or mounted in a rack. Power is supplied by an auto-sensing 100–240V AC input at 50/60 Hz, with consumption ranging from about 3.3 W at idle to 11 W under full load. The device operates from 0 to 50 °C at 5–95% non-condensing humidity, and carries CE and FCC compliance.
| Interface / Item | Specification |
|---|---|
| Ethernet (LAN) | 4 × 10/100/1000BASE-T RJ45 (Ports 1–4) |
| Copper WAN/LAN | 1 × 1G/2.5G/5G/10GBASE-T RJ45 (Port 5, software-selectable) |
| Fiber WAN/LAN | 1 × 1G/2.5G/10GBASE-X SFP+ (Port 6, software-selectable) |
| USB | 1 × USB 2.0 (configuration backup / restore) |
| NAT throughput | Max. 9.4 Gbps |
| Power | 100–240V AC, 50/60 Hz; max. 11 W full load |
| Dimensions / weight | 330.2 × 200 × 43.1 mm, 1U; 1725 g |
Dual-WAN Resilience and Flexible 10G Uplink
With one copper and one fiber WAN interface, the XVR-800 maintains Internet connectivity through automatic failover. Administrators set the WAN priority, and when the primary link goes down the secondary interface takes over so that mission-critical services stay online. Weighted outbound load balancing distributes traffic across both links to make fuller use of available bandwidth.
Because the SFP+ slot supports transceivers for FTTx and long-distance runs, the router can be adapted to the site's distance requirements – from short multi-mode links up to 120 km single-mode or WDM spans. PLANET's SD-WAN function adds application-aware optimization across multiple WAN links, which helps improve performance and reduce operating cost for distributed sites.
Security: Secure Boot, Hardware TRNG and ML-KEM
A Secure Boot mechanism verifies that only authenticated firmware runs at startup, blocking tampered or unauthorized images at the system level. A built-in Hardware TRNG (True Random Number Generator) supplies high-entropy material for cryptographic key generation. In addition, the XVR-800 supports hybrid key exchange in TLS using ML-KEM (Kyber). This combines traditional and post-quantum key exchange methods to strengthen the long-term protection of encrypted sessions against future quantum computing threats.
For everyday network protection, the SPI firewall inspects traffic state, while DoS/DDoS mitigation blocks SYN and ICMP flooding. Content filtering covers MAC, IP and web rules, and NAT ALGs support SIP, RTSP, FTP, H.323 and TFTP. Virtual server and DMZ functions let internal servers publish services to Internet users without exposing the wider network.
Comprehensive VPN Suite and Throughput
The XVR-800 carries a broad VPN stack: IPSec (Net-to-Net and Host-to-Net) with an IPSec Remote Server, GRE, PPTP Server, L2TP Server, SSL Server/Client (OpenVPN, compatible with services such as Surfshark, NordVPN and PureVPN) and WireGuard Server/Client. Encryption options include DES, 3DES and AES up to AES-256, with MD5, SHA-1, SHA-256, SHA-384 and SHA-512 authentication. This range lets a single device serve site-to-site tunnels, remote workers and lightweight high-speed connections from the same platform.
According to the specification, tunnel capacity reaches 16 IPSec, 5 GRE, 100 PPTP and up to 200 SSL VPN tunnels. WireGuard provides the highest published VPN throughput over the 10G interface, followed by IPSec/AES128 and IPSec/AES256. The table below lists the throughput ranges published by PLANET.
| VPN mode | Throughput (1G interface) | Throughput (10G interface) |
|---|---|---|
| WireGuard | 815–883 Mbps | 1,430–1,890 Mbps |
| IPSec / AES128 | 894–910 Mbps | 1,110–1,310 Mbps |
| IPSec / AES256 | 752–842 Mbps | 864–1,060 Mbps |
| L2TP | 145–463 Mbps | 483–885 Mbps |
| L2TP / IPSec | 150–334 Mbps | 438–496 Mbps |
Integrated Wi-Fi and Network Management
The router integrates an AP Controller, Captive Portal, RADIUS authentication and a DHCP server, so administrators can roll out secure employee and guest Wi-Fi without adding external servers. Through the web interface, PLANET Smart APs are managed centrally: SSIDs, radio settings and security policies are configured in a short four-step process, and profiles can be pushed to multiple APs or groups at once. APs of the same model can be clustered for unified management, bulk provisioning and firmware upgrades from a single control point.
Routing covers static routes, RIPv1/v2 and OSPFv2, and a NAT-disable option lets the device run in pure routing mode for end-to-end IP transparency in backbone or data-center scenarios. The XVR-800 is managed over a web browser, SSHv2, TLSv1.3 and SNMP v1/v2c/v3, and integrates with PLANET's Smart Discovery utility, UNI-NMS, NMS System and the CloudNMS app for centralized monitoring. An SFP-DDM function reports real-time transceiver parameters such as optical power, temperature, bias current and supply voltage.
Deployment Scenarios
Multi-site enterprise VPN
Secure interconnection between headquarters, branch offices and remote workers using IPSec, SSL/OpenVPN and WireGuard, with dual 10G WAN for data-intensive traffic.
SMB Wi-Fi with central control
Built-in AP Controller, Captive Portal, RADIUS and DHCP deliver managed employee and guest Wi-Fi without additional servers.
Always-on WAN uptime
Dual-WAN automatic failover, weighted load balancing and High Availability keep mission-critical links running when a primary connection fails.
Long-distance fiber uplink
The SFP+ slot supports transceivers for FTTx and spans up to 120 km, allowing direct uplink to backbone switches or monitoring centers.
Pure routing / backbone
NAT-disable mode provides end-to-end IP transparency for enterprise backbones, data centers or integration with upstream security systems.
Hybrid TLS key exchange with ML-KEM
Secure Boot, Hardware TRNG and hybrid key exchange in TLS using ML-KEM (Kyber) strengthen the long-term protection of encrypted sessions against future quantum computing threats.
Featured Products
- XVR-800 – Enterprise Dual 10G VPN Security Router with 4-Port 10/100/1000T; dual 10G WAN (copper + SFP+), 9.4 Gbps NAT throughput, full VPN suite (IPSec/SSL/WireGuard/GRE/PPTP/L2TP), ML-KEM hybrid TLS key exchange, Secure Boot, Hardware TRNG, AP Controller, SD-WAN, up to 200 SSL VPN tunnels.
- ZT-800 – Dual 10G Zero Trust Security Gateway with 4-Port 10/100/1000T; shares the XVR-800 hardware platform and adds a dedicated Zero Trust access-control layer.