Skip to content

Router Settings

Open a device in the cloud portal to change the router settings that are safe to manage remotely. This page overlaps with the router’s local Web UI, but it is not a one-for-one copy: cloud changes are reviewed, sent as jobs, and require the router to be online; local changes are made on-site and apply directly to the router in front of you.

Animated walkthrough of the router settings page showing the left settings menu, Review and apply button, and firmware update action.
Router changes start in the left settings menu and are sent only after you review and apply them.
TaskCloud portalLocal Web UI
WiFi, guest WiFi, and upstream WiFiGuided fields on Router SettingsWireless and Services pages for on-site setup
WAN, LAN, DHCP, failover, Ethernet port roles, and VLANsGuided fields on Router Settings; sent as a jobNetwork - LAN and related Network/Routing pages; local VLAN and port-role apply is transactional (commit, reload, and device-side readback) and rolls back on mutation, commit, reload, or readback failure
Secondary APN policyCapability-gated fields under Cellular; sent and tracked as a jobNetwork - Cellular for on-site configuration, start, stop, and live status
DNS, hostname, and timezoneDevice name, time & DNSSystem - General
Port forwardingGuided inbound port rulesRouting - Port Forwarding
Passthrough, cellular DMZ, or WAN bridgePassthrough / bridge; reviewed and sent as a high-risk jobNetwork - Passthrough / Bridge
Firewall rulesRead-only visibility; use port forwarding for customer-editable inbound rulesRead-only firewall view
Remote WebUI over a private APNRemote WebUI access on a device or in a config profileServices - Remote WebUI
VPN tunnelsGuided WireGuard and IPsec sectionsWireGuard and IPsec pages for on-site changes
Firmware updatePick an approved cloud firmware option or approved upload when availableUpload a file or use a firmware URL on-site

Some support and API workflows are intentionally not general cloud form fields. Firmware update from an arbitrary URL and checksum is local Web UI or cloud API/support-led only; SMS, modem diagnostics, and similar low-level cellular tools should only be used when Telisky Support directs you. Secondary APN controls appear only for compatible RC500 firmware and modems.

SettingWhat it controls
WiFi networksWiFi names, passwords, bands, channels, transmit power, and guest WiFi
Internet connectionWired Ethernet internet, cellular, upstream WiFi, and the order connections fail over
Cellular backupActive SIM, APN, roaming, and carrier options for cellular
Secondary APN policyOne additional management/private APN, write-only credentials, IP family, and selected destination prefixes; ordinary traffic keeps using the primary default route
Upstream WiFiUse another WiFi network as an internet uplink
Managed meshSecure RC500-to-RC500 mesh backhaul, button pairing, peer status, and uplink sharing

Use Secondary APN policy only when your carrier or Telisky deployment plan supplies a second APN and the exact destination prefixes that belong on it. The portal validates the APN, credentials, IP family, and CIDR prefixes before creating the job.

Starting or stopping the secondary APN can briefly interrupt cellular service while the router changes modem ownership. Keep the job page open until it succeeds, then confirm the router is still online. The device rolls back to native single-APN mode if it cannot preserve the primary connection. APN usernames and passwords are write-only and do not appear in telemetry, job results, or settings read-back.

For the on-site procedure and status meanings, see Cellular & SIM.

SettingWhat it controls
Local networkThe router’s local address, DHCP range, lease time, DNS, Ethernet port roles (LAN Ports 1–4), custom LAN and guest VLAN IDs, and one optional tagged network
Connected devicesA live list of devices on the router, with their addresses and signal
Reserved IP addressesKeep important devices on the same local address
Inbound port rulesForward inbound ports to a device behind the router
FirewallA read-only view of the router’s firewall rules

Port roles, LAN VLAN, guest VLAN, and tagged network

Section titled “Port roles, LAN VLAN, guest VLAN, and tagged network”

Use the guided Local network fields when a site needs specific LAN or guest VLAN IDs, or one optional tagged network for equipment that expects a specific VLAN tag. The same capability is available on-site under Network - LAN in the Ethernet Port Roles and Tagged VLAN cards. Use those guided controls rather than editing low-level network files by hand.

  • Guest VLAN ID, Ethernet port roles, and the optional tagged network live under Local network. Guest WiFi (SSID, password, enable) remains under WiFi networks.
  • Set custom LAN VLAN and guest VLAN IDs only when your wiring plan requires them. IDs must be canonical whole numbers from 1 through 4094, and they must not match each other; the portal rejects a duplicate or non-canonical ID.
  • Access roles apply to LAN Ports 1–4 only. Only Port 4 may use the WAN role, and at least one port must remain on the LAN role. The dedicated WAN Port is not part of the access-role list.
  • The optional tagged network is a single extra IEEE 802.1Q tag on selected LAN Ethernet ports—layer-2 membership only—not multi-VLAN trunk support, and not a third RC500 network with its own IP address, routing, or DHCP. Choose ports that currently show a normal LAN role (LAN Ports 1–3, or LAN/WAN Port 4 while it is still a LAN port). The tagged network ID, like LAN and guest IDs, must be a canonical whole number from 1 through 4094 and cannot reuse the LAN or guest VLAN ID.
  • Cloud changes are queued jobs. Keep the job open until it reports success from confirmed device readback and apply. A submitted form alone is not proof that the router is running the new VLAN plan.

For the on-site field meanings and eligibility details, see RC500 Network - Ethernet port roles and guest VLAN.

This section moves selected LAN ports away from the normal LAN. Choose the mode that matches the downstream equipment:

  • Routed NAT creates a private client subnet behind the preferred uplink. Normal failover can still provide a fallback path.
  • Cellular DMZ sends all unsolicited IPv4 traffic for one static carrier address to exactly one private client. It is 1:1 NAT, not a layer-2 cellular bridge. The plan must provide a static public IPv4 address; CGNAT does not work for inbound access.
  • WAN bridge transparently bridges either the dedicated WAN Port or LAN/WAN Port 4 to selected LAN client ports. The selected wired uplink is unavailable as a normal routed uplink while the bridge is active.

The review shows the affected ports, client network, and DHCP settings. Preserve MDM remains required, but the router still needs an independent active management uplink. The cloud job applies an automatic five-minute safety timer, polls the router’s apply status, and confirms it automatically; treat the change as complete only when the job reports Succeeded. See RC500 Network - Passthrough and bridge modes for requirements and Local Web UI recovery guidance.

SettingWhat it controls
IPsec tunnelA site-to-site connection to a customer firewall or collector
WireGuard tunnelA WireGuard VPN profile and peer

Remote WebUI access is disabled by default. Enable it only when a private-APN or customer network routes management traffic to the RC500’s cellular interface.

  • Enter every permitted source as an explicit canonical IPv4 CIDR from /16 through /32. A host uses /32; 0.0.0.0/0, broad prefixes, malformed addresses, and addresses with host bits set are rejected.
  • The generated firewall rule accepts only TCP 443 on the cellular interface currently reported by cellular0. It does not open HTTP 80, SSH, or other ports.
  • The RC500 cannot prove that traffic crossed IPsec. It trusts only the cellular ingress interface and the source CIDRs you configured. Do not use an RFC1918 range merely because it looks private.
  • Apply the setting directly to one device, through a config profile to a group or the exact selected organization, or through a staged rollout. Organization targeting does not include child organizations.

The HTTPS listener still requires the router’s local WebUI credentials. Disable the setting after the maintenance window when persistent access is not required.

SettingWhat it controls
GPS forwardingSend live location to a CAD, AVL, or telemetry collector
Low data reportingReduce reporting traffic for small cellular plans
Device name, time & DNSHostname, timezone, and upstream DNS settings
Local Web UI credentialsThe username and password for the router’s local Web UI

Router settings affect a live device, and some of them affect how it connects.

  • Changes can interrupt connectivity - especially internet, cellular, DNS, VLAN, Ethernet port-role, and VPN settings.
  • For a critical router, apply one section at a time and confirm the device is still reachable before moving on.
  • Passthrough, bridge, and VLAN/port-role changes can move an Ethernet port out of the normal LAN or clear a tagged network that depended on that port. Keep an independent management path and wait for the apply job to report Succeeded before relying on the new path.
  • Every cloud change becomes a job you can track; if a setting does not take effect, see Config Did Not Apply.