Manual

hEX PoE (RB960PGS)

Five gigabit ports of which four supply power, plus an SFP cage: the wired router that feeds your cameras.

The hEX PoE (product code RB960PGS) is the hEX with power on its ports. Five gigabit ports, an SFP cage, no Wi-Fi, and PoE-out on four of the five ethernet ports. That makes it an obvious choice for a set of cameras, a few ceiling access points or an IP phone on every desk, without a row of injectors in the cabinet.

If you do not need power on the ports, look at the plain hEX or the hEX S. If you want Wi-Fi in the same box, a hAP model suits you better; this is a router, not an access point.

The ports

  • ether1: gigabit, the default WAN port. No PoE-out on this one.
  • ether2 through ether5: four gigabit ports, all four with PoE-out. These are your powering LAN ports.
  • sfp1: one 1 Gbit SFP cage, for fibre or a hop to a switch.

Because there are four powering ports, the PoE-out per port field in the Bridge and ports section offers four choices, each with auto-on, forced-on or off. Set a port to off when something is plugged in that must not get power over the cable, and use forced-on only when you know exactly what is on that cable. What there is to know about voltage, cabling and budget is in PoE-out and Cabling and PoE in practice.

The SFP cage counts as an ordinary wired port: you can put it in the bridge, use it as a trunk or declare it a second WAN. See Bridge and ports and Multiple WAN connections.

No Wi-Fi

There are no radios in this device. The Wi-Fi step in the wizard therefore does not appear, and the roles that need a radio, Access point, CAP, Wi-Fi repeater and Wireless CPE, are greyed out with the message that there is no Wi-Fi radio. LTE / 5G router is greyed out too: no modem.

If you want Wi-Fi, it comes from access points on the PoE ports. That is the nice part of this model: the access point gets power and data over one cable. Do a setup like that in one go through Multiple devices, or let this router manage the Wi-Fi with the Router + CAPsMAN role. See CAPsMAN.

VLANs cost throughput here

This model is listed with hw_vlan: switch-menu. Its switch chip keeps the VLAN table under /interface ethernet switch, not in the bridge. The configurator writes bridge VLAN filtering and says at the same time that hardware offload goes off: VLAN traffic is then forwarded by the CPU instead of the switch chip.

On a gigabit model that is noticeable. It matters especially in a camera setup, because camera streams on their own VLAN are exactly the traffic that never stops. With a lot of cameras, consider a switch between the cameras and this router, and let the VLAN table live on that switch. See VLANs, Recipe: a camera system and Speed checks.

What it is good at, and where it runs out

Good at: routing a gigabit line with NAT, firewall, DHCP, a DNS cache and IPv6, and powering four devices along the way. With FastTrack on in the firewall, most traffic goes around the CPU.

It runs out where traffic has to go through the CPU: with VPN tunnels, which are encrypted in software here, with a queue tree for QoS, and with VLANs for the reason above. The catalogue records 128 MB of memory and the MIPSBE architecture. At 128 MB this model falls outside the small-board note, which the configurator only gives at 64 MB and below. The licence level and the switch chip are not in our catalogue for this model, so this page does not state them.

Which roles fit

  • Home router: internet, one network, firewall, IPv6, without a Wi-Fi step.
  • Office router with VLANs: six wired ports is enough for a WAN, some desks and a trunk, with the switch-chip caveat.
  • Router + CAPsMAN: routing and managing the Wi-Fi of the access points it powers at the same time.
  • VPN gateway: for instance as a WireGuard endpoint at a second site. See WireGuard.
  • Hotspot and Harden only (baseline): both available.

The quickest route to a working configuration

  1. Pick One device and search for RB960, so you get the hEX PoE and not the hEX or the hEX S.
  2. Pick Home router for one network, or Office router with VLANs if cameras, desks and guests have to stay apart.
  3. Fill in your internet connection, optionally through a provider preset.
  4. Go to Bridge and ports and set the PoE mode for each port that has something on it.
  5. Set an admin password, reset the device and paste the script. See Using the script.

The whole route for an office with VLANs is in Example: an office.

What trips people up

  • Expecting PoE on ether1. The WAN port does not supply power. The four powering ports are ether2 through ether5.
  • Using forced-on and hoping. That puts voltage on the cable without checking whether the thing on the other end can take it. Use auto-on unless you know the device.
  • Going over the PoE budget. Powering four devices is not the same as powering four devices at full draw. Work it out before you plug everything in.
  • Switching VLANs on and then missing the throughput. That is the switch chip. Read the paragraph above.
  • An empty SFP cage. Without a matching module sfp1 never comes up. Check with /interface ethernet print.

Want to try it right away? Open the configurator