







RUTX08
This robust industrial router has four Gigabit Ethernet ports, a Quad-Core CPU, and 256 MB RAM. These powerful specifications combined with core RutOS software features, such as multiple VPN services, advanced Firewall, and RMS support, make this device a superb industrial performer.
ETHERNET
WAN
1 x WAN port 10/100/1000 Mbps, compliance with IEEE 802.3, IEEE 802.3u, 802.3az standards, supports auto MDI/MDIX crossover
LAN
3 x LAN ports, 10/100/1000 Mbps, compliance with IEEE 802.3, IEEE 802.3u, 802.3az standards, supports auto MDI/MDIX crossover
NETWORK
Routing
Static routing, Dynamic routing (BGP, OSPF v2, RIP v1/v2, EIGRP, NHRP), Policy based routing
Network Protocols
TCP, UDP, IPv4, IPv6, ICMP, NTP, DNS, HTTP, HTTPS, SFTP, FTP, SMTP(S), SSL/TLS, ARP, VRRP, PPP, PPPoE, UPNP, SSH, DHCP, Telnet, SMPP, SNMP, MQTT, Wake On Lan (WOL), VXLAN
VoIP Passthrough Support
H.323 and SIP-alg protocol NAT helpers, allowing proper routing of VoIP packets
Connection Monitoring
Ping Reboot, Wget Reboot, Periodic Reboot, LCP and ICMP for link inspection
Firewall
Port forward, traffic rules, custom rules, TTL target customisation
Firewall Status Page
View all your Firewall statistics, rules, and rule counters
Port Management
View device ports, enable and disable each of them, turn auto-configuration on or off, change their transmission speed, and so on
Network Topology
Visual representation of your network, showing which devices are connected to which other devices
Hotspot
Captive portal (hotspot), internal/external Radius server, Radius MAC authentication, SMS authorisation, SSO authentication, internal/external landing page, walled garden, user scripts, URL parameters, user groups, individual user or group limitations, user management, 9 default customisable themes and optionality to upload and download customised hotspot themes
DHCP
Static and dynamic IP allocation, DHCP relay, DHCP server configuration, status, static leases: MAC with wildcards
QoS / Smart Queue Management (SQM)
Traffic priority queuing by source/destination, service, protocol or port, WMM, 802.11e
DDNS
Supported >77 service providers, others can be configured manually
DNS over HTTPS
DNS over HTTPS proxy enables secure DNS resolution by routing DNS queries over HTTPS
Network Backup
VRRP, Wired options, each of which can be used as an automatic Failover
Load Balancing
Balance Internet traffic over multiple WAN connections
SSHFS
Possibility to mount remote file system via SSH protocol
VRF Support
Initial virtual routing and forwarding (VRF) support
Traffic Management
Real-time monitoring, wireless signal charts, traffic usage history
IGMP Proxy
Possibility to relay multicast membership messages between hosts and a router, enabling multicast traffic to flow across different network segments
SECURITY
802.1x
Port-based network access control client
Authentication
Pre-shared key, digital certificates, X.509 certificates, TACACS+, Internal & External RADIUS users authentication, IP & login attempts block, time-based login blocking, built-in random password generator
Firewall
Preconfigured firewall rules can be enabled via WebUI, unlimited firewall configuration via CLI, DMZ, NAT, NAT-T, NAT64
Attack Prevention
DDOS prevention (SYN flood protection, SSH attack prevention, HTTP/HTTPS attack prevention), port scan prevention (SYN-FIN, SYN-RST, X-mas, NULL flags, FIN scan attacks)
VLAN
Port and tag-based VLAN separation
WEB Filter
Blacklist for blocking out unwanted websites, Whitelist for specifying allowed sites only
Access Control
Flexible access control of SSH, Web interface, CLI and Telnet
TPM*
Identification and authentication module, TPM 2.0 standard
Feature availability varies by order code
Certificate Manager
Certificate creation tool allows to create CA, server, client, let’s encrypt, SCEP certificates
VPN
OpenVPN
Multiple clients and a server can run simultaneously, 27 encryption methods
OpenVPN Encryption
DES-CBC 64, RC2-CBC 128, DES-EDE-CBC 128, DES-EDE3-CBC 192, DESX-CBC 192, BF-CBC 128, RC2-40-CBC 40, CAST5-CBC 128, RC2-64-CBC 64, AES-128-CBC 128, AES-128-CFB 128, AES-128-CFB1 128, AES-128-CFB8 128, AES-128-OFB 128, AES-128-GCM 128, AES-192-CFB 192, AES-192-CFB1 192, AES-192-CFB8 192, AES-192-OFB 192, AES-192-CBC 192, AES-192-GCM 192, AES-256-GCM 256, AES-256-CFB 256, AES-256-CFB1 256, AES-256-CFB8 256, AES-256-OFB 256, AES-256-CBC 256
IPsec
XFRM, IKEv1, IKEv2, with 14 encryption methods for IPsec (3DES, DES, AES128, AES192, AES256, AES128GCM8, AES192GCM8, AES256GCM8, AES128GCM12, AES192GCM12, AES256GCM12, AES128GCM16, AES192GCM16, AES256GCM16)
GRE
GRE tunnel, GRE tunnel over IPsec support
PPTP, L2TP
Client/Server instances can run simultaneously, L2TPv3, L2TP over IPsec support
Stunnel
Proxy designed to add TLS encryption functionality to existing clients and servers without any changes in the program’s code
DMVPN
Method of building scalable IPsec VPNs, Phase 2 and Phase 3 and Dual Hub support
SSTP
SSTP client instance support
ZeroTier
ZeroTier VPN client support
WireGuard
WireGuard VPN client and server support
Tinc
Tinc offers encryption, authentication and compression in its tunnels. Client and server support
Tailscale
Tailscale offers speed, stability, and simplicity over traditional VPNs. Encrypted point-to-point connections using the open source WireGuard protocol
OPC UA
Supported Modes – Client, Server
Supported Connection Types – TCP
MODBUS
Supported Modes – Server, Client
Supported Connection Types – TCP, USB
Custom Registers – MODBUS TCP custom register block requests, which read/write to a file inside the router, and can be used to extend MODBUS TCP Client functionality
Supported Data Formats – 8-bit: INT, UINT; 16-bit: INT, UINT (MSB or LSB first); 32-bit: float, INT, UINT (ABCD (big-endian), DCBA (little-endian), CDAB, BADC), HEX, ASCII
DATA TO SERVER
Protocol – HTTP(S), MQTT, Azure MQTT
Data to Server – Extract parameters from multiple sources and different protocols, and send them all to a single server; Custom LUA scripting, allowing scripts to utilize the router’s Data to server feature
MQTT Gateway – Modbus MQTT Gateway allows sending commands and receiving data from MODBUS Server through MQTT broker
DNP3
Supported Modes – Station, Outstation
Supported Connection – TCP, USB
DLMS/COSEM
DLMS Support – DLMS – standard protocol for utility meter data exchange
Supported Modes – Client
Supported Connection Types – TCP, USB
API
Teltonika Networks Web API (beta) support. Expand your device’s possibilities by using a set of configurable API endpoints to retrieve or change data. For more information, please refer to this documentation: https://developers.teltonika-networks.com
MONITORING & MANAGEMENT
WEB UI
HTTP/HTTPS, status, configuration, FW update, CLI, troubleshoot, multiple event log servers, firmware update availability notifications, event log, system log, kernel log, Internet status
FOTA
Firmware update from server, automatic notification
SSH
SSH (v1, v2)
TR-069
OpenACS, EasyCwmp, ACSLite, tGem, LibreACS, GenieACS, FreeACS, LibCWMP, Friendly tech, AVSystem
MQTT
MQTT Broker, MQTT publisher
SNMP
SNMP (v1, v2, v3), SNMP Trap, Brute force protection
JSON-RPC
Management API over HTTP/HTTPS
RMS
Teltonika Remote Management System (RMS)
IoT PLATFORMS
ThingWorx – Allows monitoring of WAN Type, WAN IP
Cumulocity – Cloud of Things – Allows monitoring of Device Model, Revision and Serial Number, WAN Type and IP. Has reboot and firmware upgrade actions
Azure IoT Hub – Can be configured with Data to Server to send all the available parameters to the cloud. Has Direct method support which allows executing RutOS API calls on the IoT Hub. Also supports Plug and Play integration with Device Provisioning Service for zero-touch device provisioning
SYSTEM CHARACTERISTICS
CPU – Quad-core ARM Cortex A7, 717 MHz
RAM – 256 MB, DDR3
FLASH Storage – 256 MB, SPI Flash
FIRMWARE / CONFIGURATION
WEB UI – Update FW from file, check FW on server, configuration profiles, configuration backup
FOTA – Update FW
RMS – Update FW/configuration for multiple devices at once
Keep Settings – Update FW without losing current configuration
Factory Settings Reset – A full factory reset restores all system settings, including the IP address, PIN, and user data to default configuration
FIRMWARE CUSTOMISATION
Operating System – RutOS (OpenWrt based Linux OS)
Supported Languages – Busybox shell, Lua, C, C++
Development Tools – SDK package with build environment provided
GPL Customization – Create custom branded firmware and web page application by changing colours, logos, and other elements
Package Manager – Service used to install additional software on the device
USB
Data Rate – USB 2.0
Applications – Samba share, USB-to-serial
External Devices – Possibility to connect external HDD, flash drive, additional modem, printer, USB-serial adapter
Storage Formats – FAT, FAT32, exFAT, NTFS (read-only), ext2, ext3, ext4
INPUT / OUTPUT
Input – 1 x Digital Input, 0 – 6 V detected as logic low, 8 – 30 V detected as logic high
Output – 1 x Digital Output, Open collector output, max output 30 V, 300 mA
Events – Email, RMS
I/O Juggler – Allows to set certain I/O conditions to initiate event
POWER
Connector – 4-pin industrial DC power socket
Input Voltage Range – 9 – 50 VDC, reverse polarity protection, voltage surge/transient protection
PoE (Passive) – Possibility to power up through LAN1 port, not compatible with IEEE802.3af, 802.3at and 802.3bt standards, Mode B, 9 – 50 VDC
Power Consumption – 6 W Max
PHYSICAL INTERFACES
Ethernet – 4 x RJ45 ports, 10/100/1000 Mbps
I/O’s – 1 x Digital Input, 1 x Digital Output on 4-pin power connector
Status LEDs – 8 x LAN status LEDs, 1 x Power LED
Power – 1 x 4-pin power connector
USB – 1 x USB A port for external devices
Reset – Reboot/User default reset/Factory reset button
Other – 1 x Grounding screw
PHYSICAL SPECIFICATION
Casing Material – Aluminium housing
Dimensions (W x H x D) – 115 x 32.2 x 95.2 mm
Weight – 345 g
Mounting Options – DIN rail, wall mount, flat surface (all require additional kit)
OPERATING ENVIRONMENT
Operating Temperature – -40 °C to 75 °C
Operating Humidity – 10% to 90% non-condensing
Ingress Protection Rating – IP30
REGULATORY & TYPE APPROVALS
Regulatory – CE, UKCA, FCC, EAC, UCRF, CITC, ANRT, NOM, UL/CSA Safety, CB, IC (ISED), RCM
EMC EMISSIONS & IMMUNITY
Standards
CE/UKCA: EN 55032:2015 + A11:2020 + A1:2020, EN 55035:2017 + A11:2020, EN IEC 61000-3-2:2019 + A1:2021 + A2:2024, EN 61000-3-3:2013 + A1:2019 + A2:2021
FCC/ISED(IC): 47 CFR Part 15 Subpart B, ICES-003: Issue 7 (October 2020)
RCM: AS/NZS CISPR 32:2015 + A1
ESD – EN 61000-4-2:2009
Radiated Immunity – EN IEC 61000-4-3:2006 + A1:2008 + A2:2010, EN IEC 61000-4-3:2020
EFT – EN 61000-4-4:2012
Surge Immunity (AC Mains Power Port) – EN 61000-4-5: 2014 + A1:2017
Surge Immunity (AC Power Line) – EN 61000-4-5:2014
CS – EN 61000-4-6:2014
DIP – EN 61000-4-11:2004, EN 61000-4-11:2020
SAFETY
Standards – CE: EN IEC 62368-1:2020 + A11:2020, CB: IEC 62368-1:2018, RCM: AS/NZS 62368.1:2022
High-Performance Industrial Cellular Routers
Carrier-grade throughput and low-latency routing for enterprise IoT, M2M telematics and critical connectivity.
Industrial-Grade Reliability & Durability
Rugged hardware and tested tolerance to extreme temperature, vibration and electrical noise for continuous operation.
Seamless Failover & Multi-WAN Connectivity
Dual SIM/eSIM, Ethernet redundancy and smart routing ensure uninterrupted service and automatic carrier failover.
Enterprise Security & Managed Network Support
Hardened firmware, VPN/MPLS support and professional managed services to protect data and simplify deployments.