Product Meta

  • rank_math_internal_links_processed: 1
  • total_sales: 0
  • product_code: PQCG-800
  • applications_tab: <p><strong>Post-Quantum Protection for Critical Enterprise Networks</strong><p>The <strong>PQCG-800</strong> provides secure connectivity for government agencies, financial institutions, and enterprise networks handling sensitive information. <strong>Hybrid PQC TLS</strong> supports long-term communication security, while <strong>PUF-based configuration protection</strong> allows only paired devices with an inserted <strong>CoreTrust Key</strong> to modify gateway settings. Devices that do not meet both requirements cannot change settings even after login. Integrated <strong>IDS/IPS</strong>, <strong>Layer 7 DPI</strong>, <strong>security logs</strong>, <strong>and scheduled signature updates</strong> help administrators detect threats and monitor security events across headquarters, branch offices, and remote sites.</p><p> </p><p><img style="display: block; margin-left: auto; margin-right: auto;" src="https://www.planet.com.sa/wp-content/uploads/2026/10/PQCG-800-3.png" alt="" width="700" height="323"></p><p> </p><p><strong>Secure Branch Connectivity with Centralized Network Management</strong></p><p>The <strong>PQCG-800</strong> combines <strong>dual 10G WAN</strong> <strong>connectivity</strong>, e<strong>nterprise cybersecurity</strong>, <strong>and centralized network management</strong> for business offices and branch networks. <strong>SD-WAN</strong>, <strong>load balancing</strong>, <strong>and automatic failover</strong> help maintain reliable access to cloud applications and business services, while integrated <strong>IDS/IPS</strong>, <strong>Layer 7 DPI</strong>, <strong>and firewall protection</strong> safeguard network traffic. With a built-in <strong>AP Controller</strong>, <strong>Captive Portal</strong>, <strong>RADIUS authentication</strong>, <strong>and DHCP server</strong>, administrators can connect external <strong>PLANET Smart APs</strong> to centrally manage employee and guest wireless access. This integrated solution simplifies branch deployment and provides consistent security policies across wired networks and connected APs.</p><p> </p><p><img style="display: block; margin-left: auto; margin-right: auto;" src="https://www.planet.com.sa/wp-content/uploads/2026/10/PQCG-800-4.png" alt="" width="700" height="448"></p></p>
  • key_features_tab: <p><strong>Highlights</strong><ul> <li><strong>PUF-based configuration protection requiring completed device pairing and an inserted CoreTrust Key</strong></li> <li><strong>Hybrid Post-Quantum TLS</strong> for long-term protection against quantum-computing threats</li> <li>Anti-SCA protection to help safeguard cryptographic keys</li> <li>Trusted platform security with Secure Boot and PUF-assisted hardware TRNG</li> <li>Advanced threat protection with IDS/IPS, Layer 7 DPI, content filtering and application visibility</li> <li>Zero Trust and identity-based access with FIDO2 Passkey, TOTP MFA, certificate authentication and ZTNA</li> <li>Multi-protocol VPN with IPSec, OpenVPN, WireGuard, GRE, PPTP and L2TP</li> <li>Dual 10G WAN interfaces with SD-WAN, load balancing, automatic failover and High Availability</li> <li>Integrated AP Controller, Captive Portal, RADIUS, CloudNMS and security monitoring</li> </ul><p> </p><p><strong>Hardware</strong></p><ul> <li>4 10/100/1000BASE-T RJ45 ports</li> <li>1 1G/2.5G/5G/10GBASE-T RJ45 port for WAN/LAN interface</li> <li>1 1G/2.5G/10GBASE-X SFP+ slot for WAN/LAN interface</li> <li>1 USB port for system configuration backup and restoration</li> <li>Reset button</li> <li>Desktop installation or rack mounting</li> </ul><p> </p><p><strong>Trusted Platform Security</strong></p><ul> <li><strong>PUF-based configuration change authorization requiring completed device pairing and an inserted CoreTrust Key</strong></li> <li><strong>Prevents configuration changes when either requirement is not met, even after connecting and logging in</strong></li> <li>Secure Boot to ensure only authenticated and trusted firmware is executed during system startup</li> <li>PUF-assisted hardware TRNG (True Random Number Generator) for secure cryptographic key generation</li> <li>Anti-Side-Channel Attack (Anti-SCA) protection to help safeguard cryptographic keys</li> <li>Security design follows EU Cyber Resilience Act (CRA) principles</li> </ul><p> </p><p><strong>Firewall & Traffic Control</strong></p><ul> <li>Stateful Packet Inspection (SPI) firewall</li> <li>MAC filtering and IP filtering</li> <li>NAT ALGs (Application Layer Gateway)</li> <li>Port forwarding and DMZ support</li> </ul><p> </p><p><strong>Advanced Threat Protection & Application Security</strong></p><ul> <li>Intrusion Detection and Prevention (IDS/IPS)</li> <li>Layer 7 Deep Packet Inspection (DPI)</li> <li>Application-level traffic visibility</li> <li>Content filtering</li> <li>DoS/DDoS mitigation</li> <li>SYN/ICMP flooding protection</li> <li>Automatic and scheduled threat signature updates</li> </ul><p> </p><p><strong>Zero Trust & ZTNA</strong></p><ul> <li>Zero Trust access control</li> <li>Identity-based access policy</li> <li>Built-in ZTNA for secure application-level access</li> <li>Zero Trust-protected VPN access</li> <li>Identity-based VPN authentication</li> </ul><p> </p><p><strong>Identity, Authentication & Access Services</strong></p><ul> <li>FIDO2 Passkey authentication</li> <li>TOTP-based multi-factor authentication (MFA/2FA)</li> <li>Certificate-based authentication</li> <li>RADIUS Server/Client</li> <li>Captive Portal for controlled employee and guest access</li> </ul><p> </p><p><strong>VPN & Secure Tunneling</strong></p><ul> <li>IPSec/Remote Server (Net-to-Net, Host-to-Net)</li> <li>GRE, PPTP Server</li> <li>L2TP Server</li> <li>SSL Server/Client (OpenVPN, compatible with VPN services such as Surfshark and NordVPN)</li> <li>WireGuard Server/Client</li> <li>Encryption methods: DES, 3DES, AES, AES-128/192/256</li> <li>Authentication methods: MD5, SHA-1, SHA-256, SHA-384, SHA-512</li> <li>Supports up to 100 concurrent SSL VPN connections*</li> </ul><p> </p><p><strong>Cryptography & Quantum Readiness</strong></p><ul> <li><strong>Hybrid Post-Quantum TLS key exchange using ML-KEM (Kyber) for protection against future quantum-computing threats</strong></li> </ul><p> </p><p><strong>Routing, SD-WAN & WAN Optimization</strong></p><ul> <li>Static route</li> <li>Dynamic route</li> <li>OSPF</li> <li>SD-WAN for multi-WAN traffic optimization</li> <li>Outbound load balancing</li> <li>NAT disable support for pure routing mode deployment</li> </ul><p> </p><p><strong>High Availability & WAN Resilience</strong></p><ul> <li>Automatic failover for dual WAN</li> <li>High Availability (HA)</li> </ul><p> </p><p><strong>Network Services</strong></p><ul> <li>Static IP/PPPoE/DHCP client for WAN</li> <li>DHCP server and NTP client for LAN</li> <li>Protocols: TCP/IP, UDP, ARP, IPv4, IPv6</li> <li>QoS, IGMP and UPnP</li> <li>MAC address clone</li> <li>DDNS: PLANET DDNS, Easy DDNS, DynDNS and No-IP</li> </ul><p> </p><p><strong>Wireless & AP Management</strong></p><ul> <li>Built-in AP Controller for centralized management of external PLANET Smart APs</li> <li>Centralized SSID, radio and security policy provisioning</li> <li>Bulk AP provisioning and firmware upgrade</li> </ul><p> </p><p><strong>System Management, Monitoring & Reporting</strong></p><ul> <li>Setup wizard</li> <li>Dashboard for system and security monitoring</li> <li>Security log viewer and event reports</li> <li>SFP-DDM (Digital Diagnostic Monitor)</li> <li>Secure management access via HTTPS; HTTP access supported</li> <li>SNMPv1, SNMPv2c and SNMPv3 management</li> <li>Auto reboot</li> <li>PLANET NMS System and Smart Discovery Utility for deployment management</li> <li>PLANET CloudNMS app for real-time monitoring</li> </ul></p>
  • specifications_tab: <table style="width:100%;" class="common_table_sky"><thead><tr><th colspan="2">Hardware Specifications</th></tr></thead><tbody><tr><td class="align-middle">Ethernet</td><td>4 10/100/1000BASE-T RJ45 Ethernet ports (Port 1 to 4)<br /> 1 1G/2.5G/5G/10GBASE-T RJ45 port (Port 5)<br /> <small><em>Supports WAN port mode or LAN port mode over software configuration</em></small></td></tr><tr><td class="align-middle">Fiber</td><td>One 1G/2.5G/10GBASE-X SFP+ port (Port 6)<br /> <small><em>Supports WAN port mode or LAN port mode over software configuration</em></small></td></tr><tr><td class="align-middle">USB Port</td><td>1 USB 2.0 port for system configuration backup and restoration</td></tr><tr><td class="align-middle">Reset Button</td><td>Reset to factory default</td></tr><tr><td class="align-middle">Thermal Fan</td><td>1</td></tr><tr><td class="align-middle">LED Indicators</td><td>System:<br />  PWR, Internet, (<font color="Green">Green</font>)<br /> Ethernet Interfaces (Port 1-4):<br />  10/100/1000 LNK/ACT (<font color="Green">Green</font>)<br /> Ethernet Interfaces (Port 5):<br />  1G/2.5G/5G/10G LNK/ACT (<font color="Green">Green</font>)<br /> Fiber Interfaces (Port 6):<br />  1G/2.5G/10G LNK/ACT (<font color="Green">Green</font>)</td></tr><tr><td class="align-middle">Installation</td><td>Desktop installation or rack mounting</td></tr><tr><td class="align-middle">Power Requirements</td><td>100~240V AC, 50/60Hz, auto-sensing</td></tr><tr><td class="align-middle">Power Consumption / Dissipation</td><td>Max. 3.3 watts/10.92BTU (Power on without any connection)<br /> Max. 11 watts/37.53BTU (Full loading)</td></tr><tr><td class="align-middle">Weight</td><td>1725g</td></tr><tr><td class="align-middle">Dimensions (W x D x H)</td><td>330.2 x 200 x 43.1mm, 1U height</td></tr><tr><td class="align-middle">Enclosure</td><td>Metal</td></tr></tbody><thead><tr><th colspan="2">Security Service</th></tr></thead><tbody><tr><td class="align-middle">Hardware Root of Trust</td><td>PUF-based hardware protection for configuration change authorization</td></tr><tr><td class="align-middle">Configuration Change Authorization</td><td>Requires completed device pairing and an inserted CoreTrust Key to modify gateway settings<br /> Devices without either requirement cannot change settings, even after connecting and logging in</td></tr><tr><td class="align-middle">Side-Channel Attack Protection</td><td>Anti-SCA protection to help safeguard cryptographic keys against side-channel attacks</td></tr><tr><td class="align-middle">Hardware Random Number Generator</td><td>PUF-assisted hardware TRNG for secure cryptographic key generation</td></tr><tr><td class="align-middle">Firewall Security</td><td>Hardware TRNG for secure cryptographic key generation<br /> Stateful Packet Inspection (SPI)<br /> Security log and event reporting<br /> Automatic threat signature updates<br /> Blocks DoS/DDoS attack<br /> Role-based access policy enforcement</td></tr><tr><td class="align-middle">ALG (Application Layer Gateway)</td><td>SIP, RTSP, FTP, H.323, TFTP</td></tr><tr><td class="align-middle">NAT</td><td>Port forwarding<br /> DMZ Host<br /> UPnP<br /> NAT disable (supports routing mode)</td></tr><tr><td class="align-middle">Content Filtering</td><td>MAC filtering<br /> IP filtering<br /> Web filtering</td></tr><tr><td class="align-middle">Bandwidth Management</td><td>Outbound load balancing<br /> Failover for dual-WAN<br /> QoS (Quality of Service)</td></tr><tr><td class="align-middle">Zero Trust</td><td>Zero Trust access control with identity verification<br /> Multi-factor authentication via external hardware security key support</td></tr><tr><td class="align-middle">Intrusion Prevention System</td><td>Intrusion Detection and Prevention (IDS/IPS)<br /> Layer 7 Deep Packet Inspection (DPI)<br /> Application-level traffic visibility</td></tr><tr><td class="align-middle">Secure Boot</td><td>Establishes a <b>Chain of Trust (CoT)</b> across all boot stages via cryptographic image signature verification</td></tr></tbody><thead><tr><th colspan="2">Networking</th></tr></thead><tbody><tr><td class="align-middle">Operation Mode</td><td>Routing mode</td></tr><tr><td class="align-middle">Routing Protocol</td><td>Static Route, Dynamic Route (RIP), OSPF</td></tr><tr><td class="align-middle">VLAN</td><td>802.1Q Tag-based, Port-based, Multi-VLAN</td></tr><tr><td class="align-middle">Multicast</td><td>IGMP Proxy</td></tr><tr><td class="align-middle">NAT Throughput</td><td>Max. 9.4Gbps</td></tr><tr><td class="align-middle">Outbound Load Balancing</td><td>Supported algorithms: Weight</td></tr><tr><td class="align-middle">Protocol</td><td>IPv4, IPv6, TCP/IP, UDP, ARP, HTTP, HTTPS, NTP, DNS, PLANET DDNS, PLANET Easy DDNS, DHCP, PPPoE, SNMPv1/v2c/v3</td></tr><tr><td class="align-middle">Key Features</td><td>HA (High Availability)<br /> Captive Portal<br /> RADIUS Server/Client<br /> AP Control</td></tr></tbody><thead><tr><th colspan="2">VPN</th></tr></thead><tbody><tr><td class="align-middle">VPN Function</td><td>IPSec (Net-to-Net, Host-to-Net)<br /> IPSec Remote Server<br /> GRE<br /> PPTP Server<br /> L2TP Server<br /> SSL Server<br /> SSL Client (Open VPN, Surfshark, NordVPN, PureVPN)<br /> WireGuard VPN Server/Client</td></tr><tr><td class="align-middle">VPN Tunnel Capacity by Protocol</td><td>IPSec: 16<br /> GRE: 5<br /> PPTP: 100<br /> SSL VPN: 200</td></tr><tr><td class="align-middle">VPN Throughput</td><td>L2TP (1Gbps): 145~463Mbps<br /> L2TP (10Gbps): 483~885Mbps<br /> L2TP/IPsec (1Gbps): 150~334Mbps<br /> L2TP/IPsec (10Gbps): 438~496Mbps<br /> IPsec/AES128 (1Gbps): 894~910Mbps<br /> IPsec/AES128 (10Gbps): 1,110~1,310Mbps<br /> IPsec/AES256 (1Gbps): 752~842Mbps<br /> IPsec/AES256 (10Gbps): 864~1,060Mbps<br /> WireGuard (1Gbps): 815~883Mbps<br /> WireGuard (10Gbps): 1,430~1,890Mbps</td></tr><tr><td class="align-middle">Encryption Methods</td><td>DES, 3DES, AES or AES-128/192/256 encryption<br /> PQC TLS (Post-Quantum Cryptography TLS) ready<br /> Supports Hybrid Post-Quantum TLS key exchange using ML-KEM (Kyber)</td></tr><tr><td class="align-middle">Authentication Methods</td><td>SHA-256/SHA-384/SHA-512 authentication algorithm<br /> TLS_KYBER_RSA_WITH_AES_256_GCM_SHA384<br /> FIDO2 Passkey authentication<br /> Certificate-based authentication<br /> TOTP MFA<br /> RADIUS authentication</td></tr></tbody><thead><tr><th colspan="2">Management</th></tr></thead><tbody><tr><td class="align-middle">Basic Management Interfaces</td><td>Web browser<br /> SNMP v1, v2c<br /> PLANET Smart Discovery utility/UNI-NMS supported<br /> PLANET NMS System/CloudNMS</td></tr><tr><td class="align-middle">Secure Management Interfaces</td><td>SSHv2, TLSv1.3, SNMP v3</td></tr><tr><td class="align-middle">System Log</td><td>System Event Log<br /> Security Log<br /> Event Report<br /> Scheduled Signature Update</td></tr><tr><td class="align-middle">Others</td><td>Setup wizard<br /> Dashboard<br /> System status/service<br /> Statistics<br /> Security Monitoring Dashboard<br /> Connection status<br /> Auto reboot<br /> Diagnostics</td></tr></tbody><thead><tr><th colspan="2">Standards Conformance</th></tr></thead><tbody><tr><td class="align-middle">Regulatory Compliance</td><td>CE, FCC</td></tr></tbody><thead><tr><th colspan="2">Environment Specifications</th></tr></thead><tbody><tr><td class="align-middle">Operating</td><td>Temperature: 0 ~ 50 degrees C<br /> Relative Humidity: 5 ~ 95% (non-condensing)</td></tr><tr><td class="align-middle">Storage</td><td>Temperature: -10 ~ 60 degrees C<br /> Relative Humidity: 5 ~ 95% (non-condensing)</td></tr></tbody></table>
  • ekit_post_views_count: 1

Dual 10G PUF-Anchored Quantum-Resilient Cybersecurity Gateway with 4-Port 10/100/1000T

» PQCG-800

PUF-Anchored Quantum-Resilient Cybersecurity Gateway

The PLANET PQCG-800 is an enterprise-grade PUF-Anchored Quantum-Resilient Cybersecurity Gateway built with a PUF-based Hardware Root of Trust to strengthen device security from the hardware level. Combining hardware-rooted protection, post-quantum cryptography, IDS/IPS, Layer 7 DPI, Zero Trust authentication and multi-protocol VPN, the PQCG-800 provides comprehensive protection for enterprise and critical network environments. Its PUF-based security architecture also supports hardware-backed configuration authorization through the PLANET CoreTrust Key, helping prevent unauthorized changes to critical gateway settings even when login credentials are compromised. Powered by a quad-core processor with dual 10G interfaces, it delivers high-performance secure connectivity for demanding network deployments.

 

PUF-Based Hardware Root of Trust and Configuration Protection

At the core of the PQCG-800 is Physical Unclonable Function (PUF) technology, which establishes a hardware-rooted trust foundation for protecting security-critical operations. For configuration change authorization, the gateway works with the CoreTrust Key and a paired management device to provide an additional hardware-backed control layer. Only a device that has completed pairing and has the authorized CoreTrust Key inserted can modify protected gateway settings. Even if an unauthorized user gains network access or valid login credentials, configuration changes remain restricted without the required hardware authorization, helping reduce the risk of credential-based takeover and unauthorized security policy modification.

 

PQCG 800 1

 

Post-Quantum Cryptography for Long-Term Data Protection

Building on its PUF-based Hardware Root of Trust, the PQCG-800 incorporates post-quantum cryptographic technologies to strengthen communications against emerging quantum-computing threats. This quantum-resilient security architecture is designed to address risks such as “harvest now, decrypt later”, where encrypted information captured today could potentially be decrypted by future quantum computers. By combining hardware-rooted trust with post-quantum protection, the PQCG-800 provides a stronger security foundation for long-term protection of sensitive enterprise and critical infrastructure communications.

 

PQCG 800 2

 

Anti-SCA Protection and PUF-Assisted Hardware TRNG

The PQCG-800 integrates Anti-Side-Channel Attack (Anti-SCA) protection to help safeguard cryptographic keys against leakage through side-channel attacks. A PUF-assisted Hardware True Random Number Generator (TRNG) supports secure cryptographic key generation, further strengthening the gateway’s hardware security foundation.

 

Advanced Threat Protection with Built-in IDS/IPS and Layer 7 Deep Packet Inspection

The PQCG-800 integrates built-in Intrusion Detection and Prevention (IDS/IPS) with Layer 7 Deep Packet Inspection (DPI) to continuously inspect network traffic and identify malicious activities before they impact business operations. By analyzing application-layer traffic in real time, the gateway detects known threats, blocks suspicious connections, and enhances application visibility, helping organizations reduce cyber risks while maintaining reliable network communications.

 

CSG 800 11

 

Continuous Security Monitoring with Security Logs and Scheduled Signature Updates

The PQCG-800 provides security logs, event reports, and scheduled signature updates to simplify cybersecurity management and improve threat visibility. Administrators can monitor network activities, analyze security incidents, and identify potential threats, while scheduled threat signature updates help maintain protection against newly emerging cyber attacks with reduced management effort.

 

related pd CSG 800 2

 

Zero Trust-Protected Access with Identity-Based Authentication

The PQCG-800 supports Zero Trust access control, FIDO2 Passkey authentication, TOTP-based MFA, and certificate-based authentication to strengthen identity verification for enterprise resources. Built-in ZTNA enables secure application-level access, helping reduce the risks of credential compromise and unauthorized access across distributed enterprise environments.

 

ZT 800 1

 

Secure Boot for Trusted System Integrity

The PQCG-800 incorporates Secure Boot technology to ensure that only authenticated and trusted firmware is executed during system startup. Cryptographic image signature verification establishes a Chain of Trust across boot stages, helping protect system integrity against firmware tampering.

 

Automatic Failover between Dual WAN

Featuring 10GBASE-T RJ45 and 10GBASE-X SFP+ WAN interfaces, the PQCG-800 supports intelligent Dual-WAN failover to maintain Internet connectivity. When the primary WAN connection becomes unavailable, the secondary WAN interface automatically takes over, minimizing downtime for business-critical applications.

 

Flexible WAN Interfaces for Network Expansion

The PQCG-800 provides flexible WAN deployment through its 10G RJ45 and 10G SFP+ interfaces, allowing administrators to choose copper or fiber connectivity according to deployment requirements. Supporting long-distance fiber transmission and high-speed Ethernet connectivity, it enables flexible network expansion for headquarters, branch offices, data centers, and industrial facilities.

 

Secure and Convenient Network Management

The PQCG-800 provides HTTPS web management and SNMP management interfaces for convenient configuration and monitoring. Its built-in web interface offers an easy-to-use, platform-independent management facility, while SNMPv1, SNMPv2c, and SNMPv3 support integration with standard network management software. These management options help administrators efficiently maintain distributed network deployments.

 

Comprehensive Firewall and Threat Defense

The PQCG-800 integrates Stateful Packet Inspection (SPI), IDS/IPS, Layer 7 DPI, and DoS/DDoS mitigation to provide comprehensive network protection. MAC and IP filtering help enforce traffic policies, while port forwarding and DMZ functions allow internal servers to provide services to Internet users according to configured access rules.

 

XVR 800 4

 

Multi-Protocol VPN Connectivity for Distributed Networks

The PQCG-800 provides secure remote access and site-to-site connectivity through its comprehensive VPN suite. Supporting IPSec, OpenVPN, WireGuard, GRE, PPTP, and L2TP, it offers flexible tunneling options for branch offices, remote workers, and distributed business operations. Combined with identity-based access control, these VPN capabilities help organizations establish secure connections across public networks.

 

XVR 800 3

 

Flexible Routing with NAT Disable Capability

The PQCG-800 supports NAT disable functionality, allowing it to operate in pure routing mode for advanced network deployment scenarios. This feature is particularly beneficial for environments requiring end-to-end IP transparency, such as enterprise backbone networks, data centers, or integration with upstream security systems. By disabling NAT, administrators can achieve greater control over traffic flow and routing policies.

 

Maximizing Work Efficiency with PLANET SD-WAN Gateway

The PQCG-800 incorporates SD-WAN (Software-Defined Wide Area Network) functionality to optimize traffic across multiple WAN links. By managing available network connections at each site, it helps improve application performance, enhance the user experience, and simplify connectivity for distributed business operations.

 

Integrated AP Management for Secure and Easy Deployment

The PQCG-800 integrates an AP Controller, Captive Portal, RADIUS authentication, and DHCP server to streamline network deployment for small and medium-sized businesses. By connecting external PLANET Smart APs, administrators can centrally manage wireless access, enforce access policies, and deliver secure employee and guest networks. These built-in services reduce the need for external servers and simplify deployment.

 

edm2 XVR 800 1

 

Centralized Remote Control of Managed APs

Through its intuitive web-based interface, the PQCG-800 allows centralized control of PLANET Smart APs, with simple configuration of SSIDs, radio settings, and security policies. A quick four-step setup pushes wireless profiles to multiple APs or groups at once, enabling fast rollout and reduced deployment cost.

 

XVR 800 2

 

Administrators can cluster APs of the same model for unified management, flexibly expand or remove APs, and perform bulk provisioning or firmware upgrades from a single control point. This ensures scalable and efficient Wi-Fi management.

 

WGR 500 4PV v1.1 8

 

Intelligent SFP Diagnosis Mechanism

The PQCG-800 supports SFP-DDM (Digital Diagnostic Monitor) functionality, allowing network administrators to monitor real-time transceiver parameters such as optical output power, optical input power, temperature, laser bias current, and supply voltage. This simplifies fiber-link monitoring and troubleshooting.

 

Common Intelligent SFP SFP+ Diagnosis Mechanism

 

PLANET CloudNMS – Cloud-Based Universal Network Management

PLANET’s CloudNMS platform and mobile app empower IT staff to remotely manage all network devices and Powered Devices (PDs) in real time. Designed for enterprises and industries, CloudNMS minimizes the need for on-site troubleshooting by providing centralized monitoring, fault detection, and instant alerts. 

With CloudNMS, businesses can manage diverse network deployments more efficiently, securely, and intelligently—all from a single cloud-based platform.

 

CloudNMS APP 5

Post-Quantum Protection for Critical Enterprise Networks

The PQCG-800 provides secure connectivity for government agencies, financial institutions, and enterprise networks handling sensitive information. Hybrid PQC TLS supports long-term communication security, while PUF-based configuration protection allows only paired devices with an inserted CoreTrust Key to modify gateway settings. Devices that do not meet both requirements cannot change settings even after login. Integrated IDS/IPS, Layer 7 DPI, security logs, and scheduled signature updates help administrators detect threats and monitor security events across headquarters, branch offices, and remote sites.

 

 

Secure Branch Connectivity with Centralized Network Management

The PQCG-800 combines dual 10G WAN connectivity, enterprise cybersecurity, and centralized network management for business offices and branch networks. SD-WAN, load balancing, and automatic failover help maintain reliable access to cloud applications and business services, while integrated IDS/IPS, Layer 7 DPI, and firewall protection safeguard network traffic. With a built-in AP Controller, Captive Portal, RADIUS authentication, and DHCP server, administrators can connect external PLANET Smart APs to centrally manage employee and guest wireless access. This integrated solution simplifies branch deployment and provides consistent security policies across wired networks and connected APs.

 

Highlights

  • PUF-based configuration protection requiring completed device pairing and an inserted CoreTrust Key
  • Hybrid Post-Quantum TLS for long-term protection against quantum-computing threats
  • Anti-SCA protection to help safeguard cryptographic keys
  • Trusted platform security with Secure Boot and PUF-assisted hardware TRNG
  • Advanced threat protection with IDS/IPS, Layer 7 DPI, content filtering and application visibility
  • Zero Trust and identity-based access with FIDO2 Passkey, TOTP MFA, certificate authentication and ZTNA
  • Multi-protocol VPN with IPSec, OpenVPN, WireGuard, GRE, PPTP and L2TP
  • Dual 10G WAN interfaces with SD-WAN, load balancing, automatic failover and High Availability
  • Integrated AP Controller, Captive Portal, RADIUS, CloudNMS and security monitoring

 

Hardware

  • 4 10/100/1000BASE-T RJ45 ports
  • 1 1G/2.5G/5G/10GBASE-T RJ45 port for WAN/LAN interface
  • 1 1G/2.5G/10GBASE-X SFP+ slot for WAN/LAN interface
  • 1 USB port for system configuration backup and restoration
  • Reset button
  • Desktop installation or rack mounting

 

Trusted Platform Security

  • PUF-based configuration change authorization requiring completed device pairing and an inserted CoreTrust Key
  • Prevents configuration changes when either requirement is not met, even after connecting and logging in
  • Secure Boot to ensure only authenticated and trusted firmware is executed during system startup
  • PUF-assisted hardware TRNG (True Random Number Generator) for secure cryptographic key generation
  • Anti-Side-Channel Attack (Anti-SCA) protection to help safeguard cryptographic keys
  • Security design follows EU Cyber Resilience Act (CRA) principles

 

Firewall & Traffic Control

  • Stateful Packet Inspection (SPI) firewall
  • MAC filtering and IP filtering
  • NAT ALGs (Application Layer Gateway)
  • Port forwarding and DMZ support

 

Advanced Threat Protection & Application Security

  • Intrusion Detection and Prevention (IDS/IPS)
  • Layer 7 Deep Packet Inspection (DPI)
  • Application-level traffic visibility
  • Content filtering
  • DoS/DDoS mitigation
  • SYN/ICMP flooding protection
  • Automatic and scheduled threat signature updates

 

Zero Trust & ZTNA

  • Zero Trust access control
  • Identity-based access policy
  • Built-in ZTNA for secure application-level access
  • Zero Trust-protected VPN access
  • Identity-based VPN authentication

 

Identity, Authentication & Access Services

  • FIDO2 Passkey authentication
  • TOTP-based multi-factor authentication (MFA/2FA)
  • Certificate-based authentication
  • RADIUS Server/Client
  • Captive Portal for controlled employee and guest access

 

VPN & Secure Tunneling

  • IPSec/Remote Server (Net-to-Net, Host-to-Net)
  • GRE, PPTP Server
  • L2TP Server
  • SSL Server/Client (OpenVPN, compatible with VPN services such as Surfshark and NordVPN)
  • WireGuard Server/Client
  • Encryption methods: DES, 3DES, AES, AES-128/192/256
  • Authentication methods: MD5, SHA-1, SHA-256, SHA-384, SHA-512
  • Supports up to 100 concurrent SSL VPN connections*

 

Cryptography & Quantum Readiness

  • Hybrid Post-Quantum TLS key exchange using ML-KEM (Kyber) for protection against future quantum-computing threats

 

Routing, SD-WAN & WAN Optimization

  • Static route
  • Dynamic route
  • OSPF
  • SD-WAN for multi-WAN traffic optimization
  • Outbound load balancing
  • NAT disable support for pure routing mode deployment

 

High Availability & WAN Resilience

  • Automatic failover for dual WAN
  • High Availability (HA)

 

Network Services

  • Static IP/PPPoE/DHCP client for WAN
  • DHCP server and NTP client for LAN
  • Protocols: TCP/IP, UDP, ARP, IPv4, IPv6
  • QoS, IGMP and UPnP
  • MAC address clone
  • DDNS: PLANET DDNS, Easy DDNS, DynDNS and No-IP

 

Wireless & AP Management

  • Built-in AP Controller for centralized management of external PLANET Smart APs
  • Centralized SSID, radio and security policy provisioning
  • Bulk AP provisioning and firmware upgrade

 

System Management, Monitoring & Reporting

  • Setup wizard
  • Dashboard for system and security monitoring
  • Security log viewer and event reports
  • SFP-DDM (Digital Diagnostic Monitor)
  • Secure management access via HTTPS; HTTP access supported
  • SNMPv1, SNMPv2c and SNMPv3 management
  • Auto reboot
  • PLANET NMS System and Smart Discovery Utility for deployment management
  • PLANET CloudNMS app for real-time monitoring

Hardware Specifications
Ethernet4 10/100/1000BASE-T RJ45 Ethernet ports (Port 1 to 4)
1 1G/2.5G/5G/10GBASE-T RJ45 port (Port 5)
Supports WAN port mode or LAN port mode over software configuration
FiberOne 1G/2.5G/10GBASE-X SFP+ port (Port 6)
Supports WAN port mode or LAN port mode over software configuration
USB Port1 USB 2.0 port for system configuration backup and restoration
Reset ButtonReset to factory default
Thermal Fan1
LED IndicatorsSystem:
 PWR, Internet, (Green)
Ethernet Interfaces (Port 1-4):
 10/100/1000 LNK/ACT (Green)
Ethernet Interfaces (Port 5):
 1G/2.5G/5G/10G LNK/ACT (Green)
Fiber Interfaces (Port 6):
 1G/2.5G/10G LNK/ACT (Green)
InstallationDesktop installation or rack mounting
Power Requirements100~240V AC, 50/60Hz, auto-sensing
Power Consumption / DissipationMax. 3.3 watts/10.92BTU (Power on without any connection)
Max. 11 watts/37.53BTU (Full loading)
Weight1725g
Dimensions (W x D x H)330.2 x 200 x 43.1mm, 1U height
EnclosureMetal
Security Service
Hardware Root of TrustPUF-based hardware protection for configuration change authorization
Configuration Change AuthorizationRequires completed device pairing and an inserted CoreTrust Key to modify gateway settings
Devices without either requirement cannot change settings, even after connecting and logging in
Side-Channel Attack ProtectionAnti-SCA protection to help safeguard cryptographic keys against side-channel attacks
Hardware Random Number GeneratorPUF-assisted hardware TRNG for secure cryptographic key generation
Firewall SecurityHardware TRNG for secure cryptographic key generation
Stateful Packet Inspection (SPI)
Security log and event reporting
Automatic threat signature updates
Blocks DoS/DDoS attack
Role-based access policy enforcement
ALG (Application Layer Gateway)SIP, RTSP, FTP, H.323, TFTP
NATPort forwarding
DMZ Host
UPnP
NAT disable (supports routing mode)
Content FilteringMAC filtering
IP filtering
Web filtering
Bandwidth ManagementOutbound load balancing
Failover for dual-WAN
QoS (Quality of Service)
Zero TrustZero Trust access control with identity verification
Multi-factor authentication via external hardware security key support
Intrusion Prevention SystemIntrusion Detection and Prevention (IDS/IPS)
Layer 7 Deep Packet Inspection (DPI)
Application-level traffic visibility
Secure BootEstablishes a Chain of Trust (CoT) across all boot stages via cryptographic image signature verification
Networking
Operation ModeRouting mode
Routing ProtocolStatic Route, Dynamic Route (RIP), OSPF
VLAN802.1Q Tag-based, Port-based, Multi-VLAN
MulticastIGMP Proxy
NAT ThroughputMax. 9.4Gbps
Outbound Load BalancingSupported algorithms: Weight
ProtocolIPv4, IPv6, TCP/IP, UDP, ARP, HTTP, HTTPS, NTP, DNS, PLANET DDNS, PLANET Easy DDNS, DHCP, PPPoE, SNMPv1/v2c/v3
Key FeaturesHA (High Availability)
Captive Portal
RADIUS Server/Client
AP Control
VPN
VPN FunctionIPSec (Net-to-Net, Host-to-Net)
IPSec Remote Server
GRE
PPTP Server
L2TP Server
SSL Server
SSL Client (Open VPN, Surfshark, NordVPN, PureVPN)
WireGuard VPN Server/Client
VPN Tunnel Capacity by ProtocolIPSec: 16
GRE: 5
PPTP: 100
SSL VPN: 200
VPN ThroughputL2TP (1Gbps): 145~463Mbps
L2TP (10Gbps): 483~885Mbps
L2TP/IPsec (1Gbps): 150~334Mbps
L2TP/IPsec (10Gbps): 438~496Mbps
IPsec/AES128 (1Gbps): 894~910Mbps
IPsec/AES128 (10Gbps): 1,110~1,310Mbps
IPsec/AES256 (1Gbps): 752~842Mbps
IPsec/AES256 (10Gbps): 864~1,060Mbps
WireGuard (1Gbps): 815~883Mbps
WireGuard (10Gbps): 1,430~1,890Mbps
Encryption MethodsDES, 3DES, AES or AES-128/192/256 encryption
PQC TLS (Post-Quantum Cryptography TLS) ready
Supports Hybrid Post-Quantum TLS key exchange using ML-KEM (Kyber)
Authentication MethodsSHA-256/SHA-384/SHA-512 authentication algorithm
TLS_KYBER_RSA_WITH_AES_256_GCM_SHA384
FIDO2 Passkey authentication
Certificate-based authentication
TOTP MFA
RADIUS authentication
Management
Basic Management InterfacesWeb browser
SNMP v1, v2c
PLANET Smart Discovery utility/UNI-NMS supported
PLANET NMS System/CloudNMS
Secure Management InterfacesSSHv2, TLSv1.3, SNMP v3
System LogSystem Event Log
Security Log
Event Report
Scheduled Signature Update
OthersSetup wizard
Dashboard
System status/service
Statistics
Security Monitoring Dashboard
Connection status
Auto reboot
Diagnostics
Standards Conformance
Regulatory ComplianceCE, FCC
Environment Specifications
OperatingTemperature: 0 ~ 50 degrees C
Relative Humidity: 5 ~ 95% (non-condensing)
StorageTemperature: -10 ~ 60 degrees C
Relative Humidity: 5 ~ 95% (non-condensing)

Ordering Information

PQCG-800

Dual 10G PUF-Anchored Quantum-Resilient Cybersecurity Gateway with 4-Port 10/100/1000T

✉

Join Our Newsletter

Get the latest news, offers and updates from PLANET Technology straight to your inbox.

We respect your privacy. Unsubscribe anytime.

Subscribe to PLANET e Newsletter

Receive the latest product information and company news!