TP-Link Omada Gigabit VPN Router
PRODUCT DESCRIPTION
TP-Link Omada Gigabit VPN Router (ER605) - 5 Years Local Warranty
The ER605 is the entry point to Omada's gateway line: five Gigabit ports, three of them WAN/LAN configurable, in a 158 mm case drawing under a watt of standby. It is the right gateway for a small office, a retail unit or a branch that needs VPN and multi-WAN failover rather than deep packet inspection — the ER7206 is the step up when session count or inspection throughput matters.
Five Gigabit Ports With Three Configurable as WAN
The ER605 provides 1 fixed Gigabit WAN port, 1 fixed Gigabit LAN port and 3 changeable Gigabit WAN/LAN ports. That layout is the reason small sites choose it: a single-circuit office can use one WAN and four LAN ports today, and a site that later adds a second broadband line for failover simply reassigns a port rather than replacing the gateway. All ports run over standard Cat5e or Cat6 to 100 m.
Multi-WAN Load Balancing and Link Backup
Load balancing on the ER605 covers intelligent load balance, application-optimised routing, link backup with timing and failover modes, and online detection. In practice that means a Singapore business can run a fibre service and a second line from a different provider, spread traffic across both, and have the gateway move sessions automatically when one circuit drops — the single most valuable feature at this price point for a site that cannot afford downtime.
Twenty IPsec Tunnels for Site-to-Site and Remote Access
The ER605 supports 20 IPsec VPN tunnels in LAN-to-LAN or client-to-LAN mode, with main and aggressive negotiation, DES through AES256 encryption, IKEv1/v2, MD5 and SHA1 authentication, NAT traversal, dead peer detection and perfect forward secrecy. IPsec throughput is 41.5 Mbps. Alongside IPsec sit a PPTP server with 10 clients across 16 tunnels, an L2TP server with L2TP over IPSec, and an OpenVPN server with 10 clients across 16 OpenVPN tunnels.
Bandwidth Control, Session Limits and Access Control
Guarantee and limited bandwidth can be applied per IP or per port, and per-IP session limits stop one device exhausting the 25,000-session table — a real problem on a small gateway when a single machine starts a large peer-to-peer transfer. Access control filters by IP, port, protocol and domain name; security covers an SPI firewall, VPN pass-through, ALG for FTP, H.323, PPTP, SIP and IPsec, and DoS and ping-of-death defences.
Captive Portal and Hotspot Authentication
Web authentication offers no authentication, simple password, hotspot with local user, voucher, SMS or RADIUS, external RADIUS server, external portal server and Facebook options. Under an Omada controller the captive portal is configured centrally alongside the access points, so a small café or clinic gets a branded guest network without buying separate hotspot software.
Silent, Palm-Sized and Under 6 W
The ER605 measures 158 × 101 × 25 mm and runs from an external 9V/0.85A DC adapter, so it fits in a shallow cupboard or on a shelf and is completely silent. It is adopted by an Omada Cloud-Based Controller, a hardware controller such as the OC200 or OC300, or the Omada Software Controller, which is what enables the Omada app, cloud access and Zero-Touch Provisioning; on its own it remains a fully configurable router via its web interface.
Ideal For
Singapore businesses, schools, hotels and managed-service providers building on Omada, and IT teams that want a gateway they can adopt, monitor and update centrally rather than box by box. Supplied by SourceIT with local Singapore warranty, GST invoice and project pricing on request.
ER605 Datasheet — Technical Specifications
General
| Model | ER605 |
| Official Product Name | Omada Gigabit VPN Router |
| Brand | TP-Link Omada |
| Warranty | 5 Years Local Warranty (Singapore) |
Specifications
| Interface | 1× Fixed Gigabit WAN Port, 1× Fixed Gigabit LAN Port, 3× Changeable Gigabit WAN/LAN Ports |
| Standards and Protocols | IEEE 802.3, 802.3u, 802.3ab, 802.3x, 802.1q; TCP/IP, DHCP, ICMP, NAT, PPPoE, NTP, HTTP, HTTPS, DNS, IPSec, PPTP, L2TP, OpenVPN, SNMP |
| Network Media | 10BASE-T: Cat3/4/5 (Max 100 m); 100BASE-TX: Cat5/5e (Max 100 m); 1000BASE-T: Cat5/5e/6 (Max 100 m) |
| Flash | SPI 16 MB |
| DRAM | 128 MB |
| Concurrent Sessions | 25,000 |
| IPsec VPN Throughput | 41.5 Mbps |
| 66 Byte Packet Forwarding Rate | Upload 1,308,139 pps / Download 1,308,140 pps |
| 1,518 Byte Packet Forwarding Rate | Upload 81,067 pps / Download 81,063 pps |
| IPsec VPN | 20 tunnels, LAN-to-LAN and Client-to-LAN, main and aggressive mode, DES/3DES/AES128/AES192/AES256, IKEv1/v2, MD5 and SHA1, NAT-T, DPD, PFS |
| PPTP VPN | PPTP VPN Server, 10 PPTP VPN clients, 16 tunnels, MPPE encryption |
| L2TP VPN | L2TP VPN Server, 10 L2TP VPN clients, 16 tunnels, L2TP over IPSec |
| OpenVPN | OpenVPN Server, 10 OpenVPN clients, 16 OpenVPN tunnels |
| Security | SPI firewall, VPN pass-through, FTP/H.323/PPTP/SIP/IPsec ALG, DoS defence, ping of death, local management |
| Access Control | IP / port / protocol / domain name filtering; source and destination IP based access control |
| Filtering | Web group filtering, URL filtering, web security |
| ARP Inspection | Sending GARP packets, ARP scanning, IP-MAC binding |
| Attack Defense | TCP/UDP/ICMP flood defence, block TCP scan (Stealth FIN/Xmas/Null), block ping from WAN |
| Advanced Routing | Static routing, policy routing |
| Bandwidth Control | IP/port-based bandwidth control, guarantee and limited bandwidth |
| Load Balance | Intelligent load balance, application optimised routing, link backup (timing, failover), online detection |
| NAT Features | One-to-One NAT, Multi-Net NAT, port forwarding, port triggering, NAT-DMZ, FTP/H.323/SIP/IPSec/PPTP ALG, UPnP |
| Session Limit | IP-based session limit |
| DHCP | DHCP Server/Client, DHCP address reservation, multi-net DHCP, multi-IP interfaces |
| WAN Connection Types | Static/dynamic IP, PPPoE, PPTP, L2TP |
| IPv6 | Supported |
| VLAN / IPTV | 802.1Q VLAN; IGMP v2/v3 proxy |
| Web Authentication | No authentication, simple password, hotspot (local user / voucher / SMS / RADIUS), external RADIUS server, external portal server, Facebook |
| Centralized Management | Omada Cloud-Based Controller, Omada Hardware Controller (OC300 / OC200), Omada Software Controller |
| Zero-Touch Provisioning | Yes (Omada Cloud-Based Controller required) |
| Maintenance | Time setting, diagnostics, firmware upgrade, factory defaults/reboot, backup and restore, system log, remote management, statistics, controller settings, SNMP |
| Power Supply | External 9V/0.85A DC adapter |
| Dimensions (W x D x H) | 6.2 × 4.0 × 1.0 in (158 × 101 × 25 mm) |
| LED | PWR, SYS, WAN, LAN |
| Operating Temperature | 0 °C to 40 °C (32 °F to 104 °F) |
| Storage Temperature | -40 °C to 70 °C (-40 °F to 158 °F) |
| Operating Humidity | 10% to 90% RH non-condensing |
| Storage Humidity | 5% to 90% RH non-condensing |
| Certification | CE, FCC, RoHS |
Compatibility & Software Support
The ER605 is part of the Omada ecosystem: gateways, switches and access points are managed together from one controller, under one set of policies, with one view of the network. Cloud and app features listed below require the device to be adopted into an Omada Controller.
| Omada SDN Controller | Supported — adopt and manage centrally from the Omada Software Controller, Hardware Controller or Cloud-Based Controller |
| Omada App | Supported — remote management from iOS and Android |
| Omada Cloud Access | Supported — no licence fee for cloud management |
| Standalone Mode | Supported — the device can also be configured on its own via its web interface |
Package Contents & Ordering Information
What’s in the Box
| Package Contents | Gigabit VPN Router ER605, Power Adapter, RJ45 Ethernet Cable, Quick Installation Guide |
Ordering Information
| Model | ER605 |
| Brand | TP-Link Omada |
| Local Warranty | 5 Years (Singapore) |
Datasheet & Downloads
Frequently Asked Questions — ER605
Does the ER605 need an Omada Controller?
No. The ER605 runs standalone through its own web interface. Adopting it into an Omada Software, Hardware or Cloud-Based Controller is what unlocks central configuration, monitoring, firmware management and cloud/app access across every Omada device on site — at no licence cost.
When should I choose the ER7206 over the ER605?
When you need more than 25,000 concurrent sessions, a fibre SFP handover into the gateway, deep packet inspection with IPS and IDS, OSPF or RIP routing, or more than 20 IPsec tunnels. For a small office with one or two internet circuits and a handful of VPN users, the ER605 is sized correctly.
What warranty does SourceIT provide?
Five years local Singapore warranty. Every ER605 sold by SourceIT comes with a GST invoice.
Is stock held locally?
SourceIT holds fast-moving Omada lines in Singapore. Anything not in local stock is brought in on indent — ask us for the current lead time before committing to a project date.
Can SourceIT quote this for a project or tender?
Yes. Send the bill of materials and we will quote the whole Omada build — controller, gateway, switching, access points and optics — with local warranty and support.






