Omada Multi-Gigabit VPN Gateway
- 2× 2.5 Gbps RJ45 ports (1× WAN, 1× WAN/LAN)
- 5× Gigabit WAN/LAN ports (1× SFP, 4× RJ45)
- Load Balancing on up to 6 WAN ports‡ increases the utilization rate of multi-line broadband
- 1× USB port (Supports USB storage, and LTE backup with LTE dongle)
- High-security SSL/ IPSec / GRE§ / WireGuard / PPTP / L2TP VPN & OpenVPN
- Centralized cloud management via the web or the Omada app*
- DoS/DDoS protection, IP/MAC/URL filtering, DPI, and IPS/IDS for enhanced security
- Rackmount, Desktop, or Wall Mount
-
2× 2.5Gbps RJ45 Ports
(1× WAN, 1× LAN) -
5× Gigabit WAN/LAN Ports
(1× SFP, 4× RJ45) -
Load Balancing on
up to 6 WAN Ports -
Desktop, Rack Mount,
or Wall Mount -
Centralized Cloud
Management* -
SSL/ IPSec / GRE§ /
WireGuard / PPTP / L2TP VPN
& OpenVPN -
Multi-Net
DHCP -
DPI & IPS/IDS
Maximize the Potential of Your Multi-gigabit Broadband with Dual 2.5 Gbps Ports
Up to 6 WAN Ports & One USB WAN for Mobile Broadband
USB storage, and LTE
backup with LTE dongle)
WAN/LAN ports
WAN/LAN ports
Software Defined Networking (SDN) with Cloud Access
Remotely manage your access points, switches, and gateways across multiple sites all from a single interface.
Mount AP
Plate AP
Controller
Controller
Controller
Outdoor Bridge
Outdoor Bridge
High-Security and High-Performance VPN
SSL/ IPSec / GRE / WireGuard / PPTP / L2TP VPN & OpenVPN easily build secure VPN tunnels for secure Internet browsing, communication between different branches, or enabling remote work or study from home.
-
DPI (Deep Packet Inspection)
Easily specify internet access rights and strategies via DPI (Deep Packet Inspection), IP/MAC/URL Filtering and Access Control List (ACL).
-
IDS/IPS
The integrated IDS/IPS engine bolsters threat detection and defense. Additionally, there is an embedded, regularly updated signature database for attack prevention.
-
DoS/DDoS Protection
Automatically detects and blocks Denial of Service (DoS) attacks such as TCP/UDP/ICMP Flooding, Ping of Death, and other related threats.


| SECURITY | |
|---|---|
| Access Control | Source/Destination IP Based Access Control |
| DNS Proxy | DNSSEC, DoH, and DoT |
| Filtering | • Web Group Filtering§ • URL Categoroies and URLs Filtering • Web Security§ |
| ARP Inspection | • Sending GARP Packets§• ARP Scanning§• IP-MAC Binding§ |
| Attack Defense | • TCP/UDP/ICMP Flood Defense• Block TCP Scan (Stealth FIN/Xmas/Null)• Block Ping from WAN |
| HARDWARE FEATURES | |
|---|---|
| Standards and Protocols | • IEEE 802.3, IEEE802.3u, IEEE802.3ab, IEEE802.3z, IEEE 802.3x, IEEE 802.1q, IEEE802.3bz• TCP/IP, DHCP, ICMP, NAT, PPPoE, NTP, HTTP, HTTPS, DNS, IPSec, PPTP, L2TP, OpenVPN, SNMP, WireGuard VPN |
| Interface | • 1× 2.5G RJ45 WAN Port• 1× 2.5G RJ45 WAN/LAN Port• 1× Gigabit SFP WAN/LAN Port• 4× Gigabit RJ45 WAN/LAN Ports• 1× USB 2.0 Port (Supports USB storage, and LTE backup with LTE dongle) |
| Network Media | • 10BASE-T: UTP category 3, 4, 5 cable (Max 100 m) EIA/TIA-568 100Ω STP (Max 100 m)• 100BASE-TX: UTP category 5, 5e cable (Max 100 m) EIA/TIA-568 100Ω STP (Max 100 m)• 1000BASE-T: UTP category 5, 5e, 6 cable (Max 100 m)• 2500BASE-T: UTP category 5, 5e, 6 cable (Max 100 m) |
| Fan Quantity | Fanless |
| Button | Reset Button |
| Power Supply | 12V/1.5A Adapter |
| Flash | 128MB NAND |
| DRAM | 1 GB DDR4 |
| LED | PWR, SYS, SFP, USB, WAN (Speed, Link/Act), LAN (Speed, Link/Act) |
| Dimensions ( W x D x H ) | 8.9 × 5.2 × 1.4 in (226 × 131 × 35 mm) |
| Protection | 4 kV surge protection |
| Enclosure | Steel |
| Mounting | Desktop/Wall/Rackmount |
| Max. Power Consumption | 14.2 W (with USB2.0 connected)7.1 W (without USB2.0 connected) |
| PERFORMANCE | |
|---|---|
| IPS Throughput | TCP: 208 Mbps UDP: 161 Mbps |
| DPI Throughput | TCP: 1823 Mbps UDP: 1272 Mbps |
| WireGuard VPN Throughput | 343 Mbps |
| Concurrent Session | 500,000 |
| New Sessions /Second | 6,000 |
| NAT (Static IP) | 2365.17 Mbps / 2364.45 Mbps |
| NAT(DHCP) | 2364.45 Mbps / 2366.04 Mbps |
| NAT(PPPoE) | 2347.14 Mbps / 2348.29 Mbps |
| NAT (L2TP) | 1308.86 Mbps / 974.10 Mbps |
| NAT (PPTP) | 1236.27 Mbps / 1280.99 Mbps |
| IPsec VPN Throughput | • ESP-SHA1-AES256: 673.3 Mbps• ESP-SHA256-AES256: 650.2 Mbps• ESP-SHA384-AES256: 629.3 Mbps• ESP-SHA512-AES256: 633.8 Mbps |
| L2TP VPN Throughput | • Unencrypted: 1243.7 Mbps• Encrypted: 561.0 Mbps |
| SSL VPN Throughput | 132.24 Mbps |
| 66 Byte Packet Forwarding Rate | Upload: 1832.69 Mbps Download: 1741.84 Mbps |
| 1,518 Byte Packet forwarding rate | Upload: 2461.18 Mbps Download: 2457.32 Mbps |
| BASIC FUNCTIONS | |
|---|---|
| WAN Connection Type | • IPv4_Static IP• IPv4_Dynamic IP• IPv4_PPPOE• IPv4_L2TP• IPv4_PPTP• IPv6_PPP• IPv6_DHCPv6• IPv6_Static IP• IPv6_6to4• IPv6_Pass-Through• Mobile Broadband: 4G/3G modem for backup via USB port |
| MAC Clone | Modify WAN/LAN MAC Address§ |
| DHCP | • DHCP Server • DHCPv6 PD Server§ • DHCP Options Customization • DHCP Address Reservation • Multi-IP Interfaces • Multi-Net DHCP |
| Stateful ACL | √ |
| Quality of Service | √ |
| Bridge VLAN | √ |
| mDNS Repeater | √ |
| IPv6 | StaticIP / SLAAC / DHCPv6 / PPPoE / 6to4Tunnel / PassThrough / Non-Address mode |
| VLAN | 802.1Q VLAN |
| IPTV | IGMP v2/v3 Proxy, Custom Mode, Bridge Mode |
| Advanced Features | |
|---|---|
| Advanced Routing | • Static Routing • Policy Routing • RIP§ • OSPF§ |
| Bandwidth Control | • IP/Port-based Bandwidth Control• Guarantee & Limited Bandwidth |
| Load Balance | • Intelligent Load Balance • Application Optimized Routing • Link Backup (Timing§, Failover) • Online Detection |
| NAT | • One-to-One NAT • Multi-Net NAT • Virtual Server • Port Forwarding • Port Triggering§ • NAT-DMZ • FTP/H.323/SIP/IPSec/PPTP ALG • UPnP • Disable NAT |
| Session Limit | IP-based Session Limit |
| VPN | |
|---|---|
| GRE | √ (Only in Standalone Mode) |
| SD-WAN | √ (Only in Controller Mode) |
| SSL VPN | SSL VPN Server 60 SSL VPN Tunnels |
| IPsec VPN | • 100 IPSec VPN Tunnels• LAN-to-LAN, Client-to-LAN• Main, Aggressive Negotiation Mode• DES, 3DES, SHA1, AES128, AES192, AES256 Encryption Algorithm• IKEv1/v2• MD5, SHA1, SHA2-384 and SHA2-512 Authentication Algorithm• NAT Traversal (NAT-T)• Dead Peer Detection (DPD)• Perfect Forward Secrecy (PFS) |
| PPTP VPN | • PPTP VPN Server • PPTP VPN Clients (12)** • 60 Tunnels (Shared with L2TP) • PPTP with MPPE Encryption |
| L2TP VPN | • L2TP VPN Server • L2TP VPN Clients (12)** • 60 Tunnels (Shared with PPTP) • L2TP over IPSec |
| OpenVPN | • OpenVPN Server • OpenVPN Clients (6)** • 66 OpenVPN Tunnels |
| WireGuard VPN | √ |
| AUTHENTICATION | |
|---|---|
| Web Authentication | • No Authentication • Simple Password# • Hotspot (Local User/Voucher#/SMS#/Radius#) • External Radius Server • External Portal Server# • LDAP# |
| Management Features | |
|---|---|
| Omada App | Yes. Requires the use of Omada Hardware Controller, Omada Cloud-Based Controller, or Omada Software Controller. |
| Centralized Management | • Omada Cloud-Based Controller• Omada Hardware Controller• Omada Software Controller |
| Cloud Access | Yes. Requires the use of Omada Hardware Controller, Omada Cloud-Based Controller, or Omada Software Controller. |
| Service | Dynamic DNS (Dyndns, No-IP, Peanuthull, Comexe) |
| Maintenance | • Web Management Interface • Remote Management • Export & Import Configuration • SNMP v1/v2c/v3 • Diagnostics (Ping & Traceroute)§ • NTP Synchronize§ • Port Mirroring • CLI (only in Standalone Mode) • Syslog Support |
| Zero-Touch Provisioning | Yes. Requires the use of Omada Cloud-Based Controller. |
| Management Features | • Automatic Device Discovery • Intelligent Network Monitoring • Abnormal Event Warnings • Unified Configuration • Reboot Schedule • Captive Portal Configuration |
| OTHERS | |
|---|---|
| Certification | CE, FCC, RoHS |
| Package Content | • ER707-M2• Power Adapter• Quick Installation Guide• Rackmount Kit |
| System Requirements | Microsoft Windows 98SE, NT, 2000, XP, Vista™ or Windows 7/8/8.1/10, MAC OS, NetWare, UNIX or Linux |
| Environment | • Operating Temperature: 0–40 ℃ (32–104 ℉);• Storage Temperature: -40–70 ℃ (-40–158 ℉)• Operating Humidity: 10–90% RH non-condensing• Storage Humidity: 5–90% non-condensing |
*These functions require the use of an Omada Hardware Controller, Software Controller, or Cloud-Based Controller. Zero-Touch Provisioning requires the use of Omada Cloud-Based Controller. Go to https://www.tp-link.com/en/omada-cloud-based-controller/product-list/ tofind all the models supported by the Omada Cloud-Based Controller.
**For PPTP VPN and L2TP VPN, ER707-M2 can connect with up to 12 VPN servers. For OpenVPN, ER707-M2 can connect with up to 6 VPN servers
† LAN MAC Address can be modified only in Standalone Mode.
‡At least one port needs to function as a LAN port.
§ These functions are supported only in Standalone Mode.
For the complete compatibility list of 4G/3G modem, go to https://www.tp-link.com/omada-router/compatibility/
