







RUTX11
This powerful LTE Cat 6 cellular router is designed for professional applications requiring reliable, fast connection and high data throughput. The RUTX11 is equipped with four Gigabit Ethernet ports, AC Wi-Fi, Bluetooth LE, and is EN 45545-2-certified, making it approved for use in passenger trains across Europe.
MOBILE MODULE
The device supports 4G LTE Cat 6 up to 300 DL / 50 UL Mbps; 3G up to 42 DL / 5.76 UL Mbps.
3GPP RELEASE
Release 12.
ESIM
Consumer type eSIM, profile download and removal operations, supporting up to seven eSIM profiles; data plans are not included. Feature availability varies by order code.
SIM SWITCH
Supports dual SIM and eSIM with automatic switching. Switch triggers include weak signal, data limit, SMS limit, roaming, no network, network denied, data connection fail, and SIM idle protection. Feature availability varies by order code.
STATUS
Status reporting includes IMSI, ICCID, operator, operator state, data connection state, network type, CA indicator, bandwidth, connected band, signal strength (RSSI, SINR, RSRP, RSRQ, EC/IO, RSCP), data sent/received, LAC, TAC, cell ID, ARFCN, UARFCN, EARFCN, MCC, and MNC.
SMS
SMS status, SMS configuration, EMAIL to SMS, SMS to EMAIL, SMS to HTTP, SMS to SMS, scheduled SMS, SMS auto-reply, SMPP.
USSD
Supports sending and reading Unstructured Supplementary Service Data messages.
BLOCK / ALLOW LIST
Operator block/allow list by country or individual operators.
MULTIPLE PDN
Supports different PDNs for multiple network access and services.
BAND MANAGEMENT
Band lock and used band status display.
SIM IDLE PROTECTION SERVICE
Configurable periodic switch to unused SIM to prevent SIM card blockage.
SIM PIN CODE MANAGEMENT
Enables setting, changing, or disabling the SIM card’s PIN.
APN
Auto APN.
BRIDGE
Direct connection (bridge) between mobile ISP and device on LAN.
PASSTHROUGH
Router assigns its mobile WAN IP address to another device on LAN.
WIRELESS
WIRELESS MODE
802.11b/g/n/ac Wave 2 (Wi-Fi 5) with data transmission rates up to 867 Mbps (Dual Band, MU-MIMO), 802.11r fast transition, Access Point (AP), Station (STA).
WI-FI SECURITY
WPA2-Enterprise: PEAP, WPA2-PSK, WPA-EAP, WPA-PSK, WPA3-SAE, WPA3-EAP, OWE; AES-CCMP, TKIP, Auto-cipher modes, client separation, EAP-TLS with PKCS#12 certificates, disable auto-reconnect, 802.11w Protected Management Frames (PMF).
SSID / ESSID
SSID stealth mode and access control based on MAC address.
WI-FI USERS
Up to 150 simultaneous connections.
WIRELESS CONNECTIVITY FEATURES
Wireless mesh (802.11s), fast roaming (802.11r), Relayd, BSS transition management (802.11v), radio resource measurement (802.11k).
WIRELESS MAC FILTER
Allowlist, blocklist.
WIRELESS QR CODE GENERATOR
Once scanned, a user automatically enters your network without inputting login information.
TRAVELMATE
Forwards Wi-Fi hotspot landing page to a connected device.
BLUETOOTH
Bluetooth 4.0; Bluetooth Low Energy (LE) for short range communication.
ETHERNET
WAN
1 x WAN port 10/100/1000 Mbps, compliant with IEEE 802.3, 802.3u, 802.3az standards, supports auto MDI/MDIX crossover.
LAN
3 x LAN ports 10/100/1000 Mbps, compliant with IEEE 802.3, 802.3u, 802.3az standards, supports auto MDI/MDIX crossover.
NETWORK
ROUTING
Static routing, Dynamic routing (BGP, OSPF v2, RIP v1/v2, EIGRP, NHRP), Policy based routing.
NETWORK PROTOCOLS
TCP, UDP, IPv4, IPv6, ICMP, NTP, DNS, HTTP, HTTPS, SFTP, FTP, SMTP, SSL/TLS, ARP, VRRP, PPP, PPPoE, UPNP, SSH, DHCP, Telnet, SMPP, SNMP, MQTT, Wake On LAN (WOL), VXLAN.
VOIP PASSTHROUGH SUPPORT
H.323 and SIP-ALG protocol NAT helpers for proper VoIP packet routing.
CONNECTION MONITORING
Ping Reboot, Wget Reboot, Periodic Reboot, LCP and ICMP for link inspection.
FIREWALL
Port forward, traffic rules, custom rules, TTL target customization.
FIREWALL STATUS PAGE
View firewall statistics, rules, and rule counters.
PORT MANAGEMENT
View device ports, enable/disable ports, auto-configuration on/off, change transmission speed.
NETWORK TOPOLOGY
Visual representation showing device connections.
HOTSPOT
Captive portal, internal/external Radius server, Radius MAC authentication, SMS authorization, SSO authentication, internal/external landing page, walled garden, user scripts, URL parameters, user groups, individual/group limitations, user management, 9 default customizable themes, optional upload/download of custom hotspot themes.
DHCP
Static and dynamic IP allocation, DHCP relay, DHCP server configuration, status, static leases (MAC with wildcards).
QOS / SMART QUEUE MANAGEMENT (SQM)
Traffic priority queuing by source/destination, service, protocol, port; WMM, 802.11e.
DDNS
Supported >77 service providers; others can be configured manually.
DNS OVER HTTPS
Proxy enables secure DNS resolution via HTTPS.
NETWORK BACKUP
Wi-Fi WAN, Mobile, VRRP, Wired options for automatic failover.
LOAD BALANCING
Balances Internet traffic over multiple WAN connections.
SSHFS
Mount remote file system via SSH.
VRF SUPPORT
Initial virtual routing and forwarding (VRF) support.
TRAFFIC MANAGEMENT
Real-time monitoring, wireless signal charts, traffic usage history.
SECURITY
802.1X
Port-based network access control client.
AUTHENTICATION
Pre-shared key, digital certificates, X.509, TACACS+, internal/external RADIUS, IP & login attempts block, time-based login blocking, built-in random password generator.
FIREWALL
Preconfigured firewall rules via WebUI, unlimited configuration via CLI, DMZ, NAT, NAT-T, NAT64.
ATTACK PREVENTION
DDoS prevention (SYN flood, SSH, HTTP/HTTPS), port scan prevention (SYN-FIN, SYN-RST, X-mas, NULL, FIN scans).
VLAN
Port and tag-based VLAN separation.
MOBILE QUOTA CONTROL
Mobile data limit, customizable period, start time, warning limit, phone number.
WEB FILTER
Blacklist for blocking unwanted websites, whitelist for allowed sites only.
ACCESS CONTROL
Flexible access control of SSH, Web interface, CLI, and Telnet.
TPM
Identification and authentication module, TPM 2.0 standard. Feature availability varies by order code.
CERTIFICATE MANAGER
Create CA, server, client, Let’s Encrypt, SCEP certificates.
VPN
OPENVPN
Multiple clients and server can run simultaneously, 27 encryption methods.
OPENVPN ENCRYPTION
DES-CBC 64, RC2-CBC 128, DES-EDE-CBC 128, DES-EDE3-CBC 192, DESX-CBC 192, BF-CBC 128, RC2-40-CBC 40, CAST5-CBC 128, RC2-64-CBC 64, AES-128-CBC 128, AES-128-CFB 128, AES-128-CFB1 128, AES-128-CFB8 128, AES-128-OFB 128, AES-128-GCM 128, AES-192-CFB 192, AES-192-CFB1 192, AES-192-CFB8 192, AES-192-OFB 192, AES-192-GCM 192, AES-256-GCM 256, AES-256-CFB 256, AES-256-CFB1 256, AES-256-CFB8 256, AES-256-OFB 256, AES-256-CBC 256.
IPSEC
XFRM, IKEv1, IKEv2, 14 encryption methods (3DES, DES, AES128, AES192, AES256, AES128GCM8, AES192GCM8, AES256GCM8, AES128GCM12, AES192GCM12, AES256GCM12, AES128GCM16, AES192GCM16, AES256GCM16).
GRE
GRE tunnel, GRE tunnel over IPsec support.
PPTP, L2TP
Client/Server instances can run simultaneously, L2TPv3, L2TP over IPsec support.
STUNNEL
Adds TLS encryption to existing clients/servers without code changes.
DMVPN
Scalable IPsec VPNs, Phase 2 & 3, Dual Hub support.
SSTP
SSTP client instance support.
ZEROTIER
ZeroTier VPN client support.
WIREGUARD
WireGuard VPN client and server support.
TINС
Tinc offers encryption, authentication, and compression; client/server support.
TAILSCALE
Encrypted point-to-point connections using WireGuard protocol.
OPC UA
Supported modes: Client, Server. Supported connection types: TCP.
MODBUS
Supported modes: Server, Client. Supported connection types: TCP, USB. Custom registers: MODBUS TCP custom register block requests. Supported data formats: 8-bit INT/UINT, 16-bit INT/UINT, 32-bit float/INT/UINT (ABCD, DCBA, CDAB, BADC), HEX, ASCII.
DATA TO SERVER
Protocols: HTTP(S), MQTT, Azure MQTT. Extract parameters from multiple sources and send to a single server; supports custom LUA scripting.
MQTT GATEWAY
Modbus MQTT Gateway: send commands and receive data from MODBUS Server via MQTT broker.
DNP3
Supported modes: Station, Outstation. Supported connection: TCP, USB.
DLMS/COSEM
DLMS support for utility meter data exchange. Supported modes: Client. Supported connection types: TCP, USB.
API
Teltonika Networks Web API (beta) support. Documentation: https://developers.teltonika-networks.com
MONITORING & MANAGEMENT
WEB UI
HTTP/HTTPS, status, configuration, FW update, CLI, troubleshoot, multiple event log servers, firmware update notifications, event log, system log, kernel log, Internet status.
FOTA
Firmware update from server, automatic notification.
SSH
SSH (v1, v2).
SMS
SMS status, SMS configuration.
CALL
Reboot, Status, Mobile data on/off, Output on/off, answer/hang-up with timer, Wi-Fi on/off.
TR-069
OpenACS, EasyCwmp, ACSLite, tGem, LibreACS, GenieACS, FreeACS, LibCWMP, Friendly tech, AVSystem.
MQTT
MQTT Broker, MQTT publisher.
SNMP
SNMP (v1, v2, v3), SNMP Trap, brute force protection.
JSON-RPC
Management API over HTTP/HTTPS.
RMS
Teltonika Remote Management System (RMS).
IOT PLATFORMS
ThingWorx, Cumulocity – Cloud of Things, Azure IoT Hub, AWS IoT Core.
SYSTEM CHARACTERISTICS
CPU: Quad-core ARM Cortex A7, 717 MHz. RAM: 256 MB DDR3. FLASH: 256 MB SPI Flash.
FIRMWARE / CONFIGURATION
WEB UI: Update FW from file, check FW on server, configuration profiles, configuration backup. FOTA: Update FW. RMS: Update FW/configuration for multiple devices. Keep settings: Update FW without losing configuration. Factory reset: Restores all system settings to default.
FIRMWARE CUSTOMISATION
OS: RutOS (OpenWrt based Linux). Supported languages: Busybox shell, Lua, C, C++, Python, Java in Package manager. Development tools: SDK package with build environment. GPL customization: Create custom branded firmware and web application. Package manager: Install additional software.
LOCATION TRACKING
GNSS: GPS, GLONASS, BeiDou, Galileo, QZSS. Coordinates via WebUI, SMS, TAVL, RMS. NMEA 0183. NTRIP protocol. Server software: TAVL, RMS. Geofencing: Multiple configurable zones.
USB
USB 2.0, Samba share, USB-to-serial. External devices: HDD, flash, modem, printer, USB-serial adapter. Storage formats: FAT, FAT32, exFAT, NTFS (read-only), ext2, ext3, ext4.
INPUT / OUTPUT
Input: 1 x Digital Input, 0–6 V low, 8–30 V high. Output: 1 x Digital Output, Open collector, max 30 V, 300 mA. Events: Email, RMS, SMS. I/O juggler: Configure I/O events.
POWER
Connector: 4-pin industrial DC. Voltage: 9–50 VDC, reverse polarity, surge protection; 24–36 VDC railway version. PoE: LAN1 port, 9–50 VDC, Mode B. Power consumption: 16 W max.
PHYSICAL INTERFACES
Ethernet: 4 x RJ45 10/100/1000 Mbps. I/O: 1 x DI, 1 x DO on 4-pin power. Status LEDs: 4 x WAN type, 2 x Mobile type, 5 x Mobile strength, 8 x LAN, 1 x Power, 2 x 2.4G/5G Wi-Fi. SIM: 2 x Mini SIM slots. Antennas: 2 x SMA Mobile, 2 x RP-SMA Wi-Fi, 1 x RP-SMA Bluetooth, 1 x SMA GNSS. USB: 1 x USB A. Reset: Reboot/User default/Factory reset. Other: 1 x Grounding screw.
PHYSICAL SPECIFICATION
Casing: Aluminium housing. Dimensions: 115 x 44.2 x 95.1 mm. Weight: 456 g. Mounting: DIN rail, wall, flat surface (requires kit).
OPERATING ENVIRONMENT
Temperature: -40 °C to 75 °C. Humidity: 10–90% non-condensing. IP Rating: IP30.
REGULATORY & TYPE APPROVALS
Regulatory: CE, UKCA, FCC, EAC, UCRF, CITC, ICASA, ANRT, FCC, IC, PTCRB, RCM, IMDA, SIRIM, NTC, E-mark, Railway, UL/CSA Safety, CB, IC (ISED), RCM. Operator: AT&T, Verizon, T-Mobile, Deutsche Telekom AG. Vehicle: ECE R10 (E-mark).
EMC EMISSIONS & IMMUNITY
Standards: CE/UKCA, FCC/ISED(IC), RCM. ESD: EN 61000-4-2:2009. Radiated immunity: EN IEC 61000-4-3:2006 + A1:2008 + A2:2010, EN IEC 61000-4-3:2020. EFT: EN 61000-4-4:2012. Surge immunity: EN 61000-4-5:2014 + A1:2017. CS: EN 61000-4-6:2014. DIP: EN 61000-4-11:2004, 2020.
RF
Standards: CE/UKCA, RCM, FCC, IC (ISED). Wi-Fi 2.4/5 GHz standards: FCC, IC.
RF EXPOSURE
Standards: FCC, IC (ISED).
SAFETY
Standards: CE, CB, RCM.
High-Performance Industrial Cellular Routers
Carrier-grade throughput and low-latency routing for enterprise IoT, M2M telematics and critical connectivity.
Industrial-Grade Reliability & Durability
Rugged hardware and tested tolerance to extreme temperature, vibration and electrical noise for continuous operation.
Seamless Failover & Multi-WAN Connectivity
Dual SIM/eSIM, Ethernet redundancy and smart routing ensure uninterrupted service and automatic carrier failover.
Enterprise Security & Managed Network Support
Hardened firmware, VPN/MPLS support and professional managed services to protect data and simplify deployments.