Security Features

Wiki mirrorView source

Security features

In the table below you can find all the security features supported by Teltonika's devices.
CategoryFeatureDefaultPurpose/Description
DDoS ProtectionSYN Flood ProtectionOnBlocks excessive SYN requests to prevent resource exhaustion.
Ping Flood ProtectionOffMitigates ICMP (Ping) flood attacks.
SSH Attack PreventionOffBlocks excessive SSH requests.
HTTP Attack PreventionOffBlocks excessive HTTP requests.
HTTPS Attack PreventionOffBlocks excessive HTTPS requests.
Custom ConfigurationCustom RulesEmptyAllows adding custom firewall rules via iptables commands.
DMZOffAllows separating LAN-side network into separate zones with heavily restricted access.
Port Scan & TCP Attack ProtectionPort Scan PreventionOffDetects and blocks port scanning attempts.
SYN-FIN AttackOffBlocks packets with both SYN and FIN flags set.
SYN-RST AttackOffPrevents abrupt TCP session resets.
X-Mas AttackOffBlocks TCP packets with multiple unusual flags set.
FIN ScanOffBlocks FIN packets used to bypass firewalls.
NULL Flags AttackOffBlocks TCP packets with no flags set.
Access Control – RemoteSSH AccessOffDisabled by default; use only with strong passwords.
HTTP AccessOffDisabled by default; use only with strong passwords.
HTTPS AccessOffDisabled by default; use only with strong passwords.
CLI AccessOffDisabled by default; use only with strong passwords.
Access Control – LocalSSH AccessOnAllows local configuration over LAN.
HTTP AccessOnAllows local WebUI configuration over LAN.
HTTPS AccessOnAllows local WebUI configuration over LAN.
CLI AccessOnAllows local command-line configuration over LAN.
Login ProtectionSSH Login AttemptsOnBlocks IP after 10 failed attempts (default).
WebUI Login AttemptsOnBlocks IP after 10 failed attempts (default).
Configuration SecuritySMS UtilitiesAdmin passwordSMS commands require admin password.
Default Admin PasswordOnDefault password is present on the device label.
CertificatesRoot CAPreloadedDefault root certificate included; can be replaced.
Other ProtectionsUPnPNot installed / OffDisabled to prevent unauthorized port forwarding.
UART InterfaceAdmin passwordRequires password to prevent unauthorized physical access.

RUTxxx series security features

In the table below you can find all the security features supported by Teltonika's RUTxxx series devices.
CategoryFeatureDefaultPurpose/Description
DDoS ProtectionSYN Attack ProtectionOnBlocks excessive SYN requests to prevent resource exhaustion.
Ping Attack ProtectionOffMitigates ICMP (Ping) flood attacks.
SSH Attack PreventionOffBlocks excessive SSH requests.
HTTP Attack PreventionOffBlocks excessive HTTP requests.
HTTPS Attack PreventionOffBlocks excessive HTTPS requests.
Custom ConfigurationCustom RulesEmptyAllows adding custom firewall rules via iptables commands.
DMZOffAllows separating LAN-side network into separate zones with heavily restricted access.
Port Scan & TCP Attack ProtectionPort Scan PreventionOffDetects and blocks port scanning attempts.
SYN-FIN AttackOffBlocks packets with both SYN and FIN flags set.
SYN-RST AttackOffPrevents abrupt TCP session resets.
X-Mas AttackOffBlocks TCP packets with multiple unusual flags set.
FIN ScanOffBlocks FIN packets used to bypass firewalls.
NULL Flags AttackOffBlocks TCP packets with no flags set.
Access Control – RemoteSSH AccessOffDisabled by default; use only with strong passwords.
HTTP AccessOffDisabled by default; use only with strong passwords.
HTTPS AccessOffDisabled by default; use only with strong passwords.
CLI AccessOffDisabled by default; use only with strong passwords.
Access Control – LocalSSH AccessOnAllows local configuration over LAN.
HTTP AccessOnAllows local WebUI configuration over LAN.
HTTPS AccessOnAllows local WebUI configuration over LAN.
CLI AccessOnAllows local command-line configuration over LAN.
Login ProtectionSSH Login AttemptsOnBlocks IP after 10 failed attempts (default).
WebUI Login AttemptsOnBlocks IP after 10 failed attempts (default).
Configuration SecuritySMS UtilitiesAdmin passwordSMS commands require admin password.
Default Admin PasswordOnDefault password is present on the device label.
CertificatesRoot CAPreloadedDefault root certificate included; can be replaced.
Other ProtectionsUPnPNot installed / OffDisabled to prevent unauthorized port forwarding.
UART InterfaceAdmin passwordRequires password to prevent unauthorized physical access.

RUTXxxx series security features

In the table below you can find all the security features supported by Teltonika's RUTXxxx series devices.
CategoryFeatureDefaultPurpose/Description
DDoS ProtectionSYN Attack ProtectionOnBlocks excessive SYN requests to prevent resource exhaustion.
Ping Attack ProtectionOffMitigates ICMP (Ping) flood attacks.
SSH Attack PreventionOffBlocks excessive SSH requests.
HTTP Attack PreventionOffBlocks excessive HTTP requests.
HTTPS Attack PreventionOffBlocks excessive HTTPS requests.
Custom ConfigurationCustom RulesEmptyAllows adding custom firewall rules via iptables commands.
DMZOffAllows separating LAN-side network into separate zones with heavily restricted access.
Port Scan & TCP Attack ProtectionPort Scan PreventionOffDetects and blocks port scanning attempts.
SYN-FIN AttackOffBlocks packets with both SYN and FIN flags set.
SYN-RST AttackOffPrevents abrupt TCP session resets.
X-Mas AttackOffBlocks TCP packets with multiple unusual flags set.
FIN ScanOffBlocks FIN packets used to bypass firewalls.
NULL Flags AttackOffBlocks TCP packets with no flags set.
Access Control – RemoteSSH AccessOffDisabled by default; use only with strong passwords and appropriate firewall rules.
HTTP AccessOffDisabled by default; unencrypted traffic, avoid usage.
HTTPS AccessOffDisabled by default; use only with strong passwords and appropriate firewall rules.
CLI AccessOffDisabled by default; use only with strong passwords and appropriate firewall rules.
Access Control – LocalSSH AccessOnAllows local configuration over LAN.
HTTP AccessOnAllows local WebUI configuration over LAN. Unencrypted traffic, avoid usage.
HTTPS AccessOnAllows local WebUI configuration over LAN.
CLI AccessOnAllows local command-line configuration over LAN.
Login ProtectionSSH Login AttemptsOnBlocks IP after 10 failed attempts (default).
WebUI Login AttemptsOnBlocks IP after 10 failed attempts (default).
Configuration SecuritySMS UtilitiesAdmin passwordSMS commands require admin password.
Default Admin PasswordOnDefault password is present on the device label.
CertificatesRoot CAPreloadedDefault root certificate included; can be replaced.
Other ProtectionsUPnPNot installed / OffDisabled to prevent unauthorized port forwarding.
UART InterfaceAdmin passwordRequires password to prevent unauthorized physical access.
TPMOnEnabled by default. Securely stores cryptographic keys and other sensitive data.

RUTMxxx series security features

In the table below you can find all the security features supported by Teltonika's RUTMxxx series devices.
CategoryFeatureDefaultPurpose/Description
DDoS ProtectionSYN Attack ProtectionOnBlocks excessive SYN requests to prevent resource exhaustion.
Ping Attack ProtectionOffMitigates ICMP (Ping) flood attacks.
SSH Attack PreventionOffBlocks excessive SSH requests.
HTTP Attack PreventionOffBlocks excessive HTTP requests.
HTTPS Attack PreventionOffBlocks excessive HTTPS requests.
Custom ConfigurationCustom RulesEmptyAllows adding custom firewall rules via iptables commands.
DMZOffAllows separating LAN-side network into separate zones with heavily restricted access.
Port Scan & TCP Attack ProtectionPort Scan PreventionOffDetects and blocks port scanning attempts.
SYN-FIN AttackOffBlocks packets with both SYN and FIN flags set.
SYN-RST AttackOffPrevents abrupt TCP session resets.
X-Mas AttackOffBlocks TCP packets with multiple unusual flags set.
FIN ScanOffBlocks FIN packets used to bypass firewalls.
NULL Flags AttackOffBlocks TCP packets with no flags set.
Access Control – RemoteSSH AccessOffDisabled by default; use only with strong passwords.
HTTP AccessOffDisabled by default; use only with strong passwords.
HTTPS AccessOffDisabled by default; use only with strong passwords.
CLI AccessOffDisabled by default; use only with strong passwords.
Access Control – LocalSSH AccessOnAllows local configuration over LAN.
HTTP AccessOnAllows local WebUI configuration over LAN.
HTTPS AccessOnAllows local WebUI configuration over LAN.
CLI AccessOnAllows local command-line configuration over LAN.
Login ProtectionSSH Login AttemptsOnBlocks IP after 10 failed attempts (default).
WebUI Login AttemptsOnBlocks IP after 10 failed attempts (default).
Configuration SecuritySMS UtilitiesAdmin passwordSMS commands require admin password.
Default Admin PasswordOnDefault password is present on the device label.
CertificatesRoot CAPreloadedDefault root certificate included; can be replaced.
Other ProtectionsUPnPNot installed / OffDisabled to prevent unauthorized port forwarding.
UART InterfaceAdmin passwordRequires password to prevent unauthorized physical access.
TPMOnEnabled by default. Securely stores cryptographic keys and other sensitive data.

RUTCxxx series security features

CategoryFeatureDefaultPurpose/Description
DDoS ProtectionSYN Attack ProtectionOnBlocks excessive SYN requests to prevent resource exhaustion.
Ping Attack ProtectionOffMitigates ICMP (Ping) flood attacks.
SSH Attack PreventionOffBlocks excessive SSH requests.
HTTP Attack PreventionOffBlocks excessive HTTP requests.
HTTPS Attack PreventionOffBlocks excessive HTTPS requests.
Custom ConfigurationCustom RulesEmptyAllows adding custom firewall rules via iptables commands.
DMZOffAllows separating LAN-side network into separate zones with heavily restricted access.
Port Scan & TCP Attack ProtectionPort Scan PreventionOffDetects and blocks port scanning attempts.
SYN-FIN AttackOffBlocks packets with both SYN and FIN flags set.
SYN-RST AttackOffPrevents abrupt TCP session resets.
X-Mas AttackOffBlocks TCP packets with multiple unusual flags set.
FIN ScanOffBlocks FIN packets used to bypass firewalls.
NULL Flags AttackOffBlocks TCP packets with no flags set.
Access Control – RemoteSSH AccessOffDisabled by default; use only with strong passwords.
HTTP AccessOffDisabled by default; use only with strong passwords.
HTTPS AccessOffDisabled by default; use only with strong passwords.
CLI AccessOffDisabled by default; use only with strong passwords.
Access Control – LocalSSH AccessOnAllows local configuration over LAN.
HTTP AccessOnAllows local WebUI configuration over LAN.
HTTPS AccessOnAllows local WebUI configuration over LAN.
CLI AccessOnAllows local command-line configuration over LAN.
Login ProtectionSSH Login AttemptsOnBlocks IP after 10 failed attempts (default).
WebUI Login AttemptsOnBlocks IP after 10 failed attempts (default).
Configuration SecuritySMS UtilitiesAdmin passwordSMS commands require admin password.
Default Admin PasswordOnDefault password is present on the device label.
CertificatesRoot CAPreloadedDefault root certificate included; can be replaced.
Other ProtectionsUPnPNot installed / OffDisabled to prevent unauthorized port forwarding.
UART InterfaceAdmin passwordRequires password to prevent unauthorized physical access.

TRBxxx series security features

In the table below you can find all the security features supported by Teltonika's TRBxxx series devices.
CategoryFeatureDefaultPurpose/Description
DDoS ProtectionSYN Attack ProtectionOnBlocks excessive SYN requests to prevent resource exhaustion.
Ping Attack ProtectionOffMitigates ICMP (Ping) flood attacks.
SSH Attack PreventionOffBlocks excessive SSH requests.
HTTP Attack PreventionOffBlocks excessive HTTP requests.
HTTPS Attack PreventionOffBlocks excessive HTTPS requests.
Custom ConfigurationCustom RulesEmptyAllows adding custom firewall rules via iptables commands.
DMZOffAllows separating LAN-side network into separate zones with heavily restricted access.
Port Scan & TCP Attack ProtectionPort Scan PreventionOffDetects and blocks port scanning attempts.
SYN-FIN AttackOffBlocks packets with both SYN and FIN flags set.
SYN-RST AttackOffPrevents abrupt TCP session resets.
X-Mas AttackOffBlocks TCP packets with multiple unusual flags set.
FIN ScanOffBlocks FIN packets used to bypass firewalls.
NULL Flags AttackOffBlocks TCP packets with no flags set.
Access Control – RemoteSSH AccessOffDisabled by default; use only with strong passwords.
HTTP AccessOffDisabled by default; use only with strong passwords.
HTTPS AccessOffDisabled by default; use only with strong passwords.
CLI AccessOffDisabled by default; use only with strong passwords.
Access Control – LocalSSH AccessOnAllows local configuration over LAN.
HTTP AccessOnAllows local WebUI configuration over LAN.
HTTPS AccessOnAllows local WebUI configuration over LAN.
CLI AccessOnAllows local command-line configuration over LAN.
Login ProtectionSSH Login AttemptsOnBlocks IP after 10 failed attempts (default).
WebUI Login AttemptsOnBlocks IP after 10 failed attempts (default).
Configuration SecuritySMS UtilitiesAdmin passwordSMS commands require admin password.
Default Admin PasswordOnDefault password is present on the device label.
CertificatesRoot CAPreloadedDefault root certificate included; can be replaced.
Other ProtectionsUPnPNot installed / OffDisabled to prevent unauthorized port forwarding.
UART InterfaceAdmin passwordRequires password to prevent unauthorized physical access.

TSWxxx series security features

In the table below you can find all the security features supported by Teltonika's TSWxxx series devices.
CategoryFeatureDefaultPurpose/Description
DDoS ProtectionSYN Attack ProtectionOnBlocks excessive SYN requests to prevent resource exhaustion.
Ping Attack ProtectionOffMitigates ICMP (Ping) flood attacks.
SSH Attack PreventionOffBlocks excessive SSH requests.
HTTP Attack PreventionOffBlocks excessive HTTP requests.
HTTPS Attack PreventionOffBlocks excessive HTTPS requests.
Custom ConfigurationCustom RulesEmptyAllows adding custom firewall rules via iptables commands.
DMZOffAllows separating LAN-side network into separate zones with heavily restricted access.
Port Scan & TCP Attack ProtectionPort Scan PreventionOffDetects and blocks port scanning attempts.
SYN-FIN AttackOffBlocks packets with both SYN and FIN flags set.
SYN-RST AttackOffPrevents abrupt TCP session resets.
X-Mas AttackOffBlocks TCP packets with multiple unusual flags set.
FIN ScanOffBlocks FIN packets used to bypass firewalls.
NULL Flags AttackOffBlocks TCP packets with no flags set.
Access Control – RemoteSSH AccessOffDisabled by default; use only with strong passwords.
HTTP AccessOffDisabled by default; use only with strong passwords.
HTTPS AccessOffDisabled by default; use only with strong passwords.
CLI AccessOffDisabled by default; use only with strong passwords.
Access Control – LocalSSH AccessOnAllows local configuration over LAN.
HTTP AccessOnAllows local WebUI configuration over LAN.
HTTPS AccessOnAllows local WebUI configuration over LAN.
CLI AccessOnAllows local command-line configuration over LAN.
Login ProtectionSSH Login AttemptsOnBlocks IP after 10 failed attempts (default).
WebUI Login AttemptsOnBlocks IP after 10 failed attempts (default).
Configuration SecuritySMS UtilitiesAdmin passwordSMS commands require admin password.
Default Admin PasswordOnDefault password is present on the device label.
CertificatesRoot CAPreloadedDefault root certificate included; can be replaced.
Other ProtectionsUPnPNot installed / OffDisabled to prevent unauthorized port forwarding.
UART InterfaceAdmin passwordRequires password to prevent unauthorized physical access.