Multi-Homing Security Gateway

o 9 inch Desktop, Iron Housing (Optional: 19 inch Rack mount)

o Embedding hardware system design

o Built-in 5x10/100/1000Mbps GbE ports(Self-define WAN/DMZ/LAN ports)

o Total maximum throughput: 300Mbps

o Support Out-bound, VPN, Server Load-balance function

o Support WAN ports Link Failover mechanism

o Support IPv4 and IPv6 dual protocols

o Support VPN security connection (IPsec/PPTP Gateway)

o Support Policy-Base Firewall and Time-scheduler control

o Support Facebook Check-in Authorization with any WiFi AP

o Support OTP(One-Time Password) for Android & iOS APP

o Support Self-define 100 User / Password or Via External POP3, LDAP

o RADIUS server Authorization

o Support Application Blocking (for IM/P2P/FTP/Tunnel/Webmail...)

o Support URL Blocking

o Support Smart QoS and P2P Bandwidth control function

o Easy display all WAN ports Statistical analysis information

o Built-in English, simple and easy to use Web UI

o Unlimited users License

o SOHO, SMB and Branch offices for network security the best solution

Product Features

Since the reliance on the Internet has proliferated with the growth of cloud services, any network interruption will cause tremendous loss and damage. Therefore, the top priority of implementing a network is to ensure a reliable Internet connection.

Accordingly, Maksat Gateway, an SPI firewall with multi-WAN interfaces, delivers stability and continuity to your network through link failover and load balancing capabilities, as well as serves as an internal firewall for advanced controls.

Besides, it comes equipped with AP controller, policy-based routing (PBR), QoS manager, Web filter, application blocker, anomaly traffic detection, full VPN connectivity (IPsec / PPTP VPN and trunking) and more, presenting you an all-in-one solution to cost-effectively simplify the management of your wired / wireless network, bandwidth and LAN users.

Full IPv6 Compatibility
Maksat Gateway is fully compatible with IPv6 addressing, the mainstream Internet protocol in the future. No additional budget is required for implementing another IPv6-based gateway simply for IPv4-to-IPv6 address translation.

Custom NIC Ports & Groups
Up to 5 GbE RJ45 ports are available for defining as LAN,WAN (4 out of 5 ports at the most), DMZ, or isolated NIC groups. The user-definable interface frees you from the limits of default NIC properties and offers flexibility to network implementation.

SPI / Internal Firewall
Based on ICSA-certified SPI firewall technology, the device can be deployed at the network perimeter to fully protect against various security threats. In addition, the NIC Teaming feature enables it to physically segment a network, adding an extra layer of protection by serving as an internal firewall to deliver advanced controls (authentication, QoS, schedule, etc.), efficaciously increasing the security of internal network.

Billing Solution
Wi-Fi billing through specific SSIDs based on random-passcode authentication, Thermal printers for Billing voucher printing and authentication portal

As for wireless client access, network policies can be applied to implement various authentication mechanisms (Captive Portal / RADIUS / LDAP / POP3), limit the user traffic, block Internet-based applications and more, fulfilling all your wireless management demands.

Web Filtering
The Web Filtering feature enables you to set restrictions on website access (using Black- / Whitelist), file transfer (using HTTP, FTP and file extension) and MIME / script type (popup window, ActiveX control, Java Applet, cookie, etc.), as well as offers you with detailed logs and statistics for diagnosis.

Anomaly Flow Detection
The device is capable of preventing packet-flooding attacks from spreading across the network, as well as notifying related personnel of such an event to promptly attend to them, ensuring others' access to the Internet

Outbound Load Balancing & Policy based Routing
Supporting up to 4 WAN ports with load balancing, can distribute outbound traffic across WAN links, due to which it delivers bandwidth aggregation and link failover capabilities, making the most of bandwidth, and yet connecting reliably. Moreover, the network traffic generated from a specific service or user can be routed through a designated WAN link based on the About Us's network policies.

Multiple Authentication Support
By supporting RADIUS, POP3 and LDAP servers, only the verified users are allowed to access the Internet services.

IPsec / PPTP VPN Capability
With the built-in IPsec/PPTP VPN support, provides you a fast, reliable and safe private connection. It features VPN trunking to deliver link failover and bandwidth aggregation capabilities to VPN tunnels, greatly increasing the speed and stability of your Internet connection. This can be used to reduce the ownership cost of network infrastructure by replacing the expensive leased line with multiple low-cost DSL links, as well as to ensure the continuity of mission-critical services.

Moreover, it also can effectively boost the security of VPN connectivity using its advanced controls, such as privileges, authentication and QoS.

Flexible Bandwidth Management
Adds flexibility to bandwidth management not only by delivering guaranteed or maximum bandwidth along with prioritized access, but also by limiting the individual QoS or traffic quota. Besides, the bandwidth-intensive applications (e.g., P2P) can be regulated to prevent bandwidth from being exhausted by minorities.

Business Promotion via Facebook Page
By combining Wi-Fi authentication with Facebook page checkin, the free Wi-Fi service can be provided to customers who simply check in to your business location on Facebook. This combination of Wi-Fi service and Facebook Page check-in can not only attract customers, but also grow your business exposure. When customers check in to use your Wi Fi service, their friends can see your Facebook page in their News Feed, which gets your Facebook page to spread virally, allowing you to reach out to potential customers and increasing profits for your business.

One-Time Password Authentication
An unpredictable and unrepeatable password can be generated at each login, offering your network a two-factor authentication protection.

Internet-based Application Blocking
The use of instant messaging ,peer-to-peer sharing, multimedia streaming, web-based email service, online gaming, VPN tunneling and remote controlling can be effortlessly blocked by their packet signatures.

Product Benefits


Full IPv6 compatibility

Custom network interfaces and groups

Unified network management

LAN security mechanisms

Flexible bandwidth management

Manageable VPN with link failover and bandwidth aggregation capabilities

High security authentication mechanisms

Policy-based routing

Internet-based application blocking

Session persistence capability (for online banking & gaming)

Business Promotion via Facebook

Fanless design


Saves the budget for an IPv6-based gateway simply for IPv4-to-IPv6 address translation.

Enables you to assign up to 4 ports as WAN interfaces and team up NIC ports as needed as well as offer protection by serving as a physical internal firewall.

Provides an effortless network management through a unified user interface.

Secures LAN networks with anomaly flow detection.

Adds flexibility to bandwidth management by applying settings of guaranteed/ maximum bandwidth, priority, traffic quota and P2P QoS.

Securely tunnels network connections using PPTP/ IPSec VPN along with trunking capability, bandwidth aggregation and policy-based management.

Greatly increases the network security by using a two-factor authentication.

Allows in- / outbound traffic to be routed based on network polices.

Restrains the use of Internet-based applications such as IM clients, P2P software, etc.

Avoids online banking or gaming service interruption by maintaining the same IP throughout a session.

Combines free Wi-Fi service and Facebook check- in to promote your business on Facebook.

The fanless design delivers a silent operation to SMBs, especially those without computer facilities.

Third-Party Product

Either fully or partially (Web filtering, application blocking, policy-based routing, etc.) incompatible with IPv6 addressing.

Either fixed to factory default or incapable of multi- WAN load balancing.

Merely a firewall equipped with simple security mechanisms and cluttered management interfaces; operation requires a separate configuration for each feature.

No protection against DoS attack initiated from within the network.

Lacks flexibility in bandwidth management due to the only option being maximum bandwidth.

Network security is at risk due to the lack of link failover, bandwidth aggregation and advanced controls.

Network security is at risk due to sole reliance on user credentials for authentication.

The IP routing mechanisms are neither disclosed nor manageable.

Less effective in blocking the use of Internet- based applications by port number.

No solution available for online banking or gaming service interruption due to IP inconsistency.

Requires other ways to promote your business via social networking sites.

The noises from the fan require it to be operated in the computer facilities.

Download PDF


  • E-13, BLOCK No. B1
  • New Delhi 110044, INDIA


  • 1212~1215, DLF TOWER (B)
  • JASOLA, New Delhi 110025,