PUF-Anchored Quantum-Resilient Cybersecurity Gateway
The PLANET PQCG-800BE is an enterprise-grade PUF-Anchored Quantum-Resilient Cybersecurity Gateway built with a PUF-based Hardware Root of Trust to strengthen device security from the hardware level. Combining hardware-rooted protection, post-quantum cryptography, IDS/IPS, Layer 7 DPI, Zero Trust authentication and multi-protocol VPN, the PQCG-800 provides comprehensive protection for enterprise and critical network environments. Its PUF-based security architecture also supports hardware-backed configuration authorization through the PLANET CoreTrust Key, helping prevent unauthorized changes to critical gateway settings even when login credentials are compromised. Powered by a quad-core processor with dual 10G interfaces and Wi-Fi 7 connectivity, it delivers high-performance secure connectivity for demanding network deployments.
PUF-Based Hardware Root of Trust and Configuration Protection
At the core of the PQCG-800BE is Physical Unclonable Function (PUF) technology, which establishes a hardware-rooted trust foundation for protecting security-critical operations. For configuration change authorization, the gateway works with the CoreTrust Key and a paired management device to provide an additional hardware-backed control layer. Only a device that has completed pairing and has the authorized CoreTrust Key inserted can modify protected gateway settings. Even if an unauthorized user gains network access or valid login credentials, configuration changes remain restricted without the required hardware authorization, helping reduce the risk of credential-based takeover and unauthorized security policy modification.

Post-Quantum Cryptography for Long-Term Data Protection
Building on its PUF-based Hardware Root of Trust, the PQCG-800BE incorporates post-quantum cryptographic technologies to strengthen communications against emerging quantum-computing threats. This quantum-resilient security architecture is designed to address risks such as “harvest now, decrypt later”, where encrypted information captured today could potentially be decrypted by future quantum computers. By combining hardware-rooted trust with post-quantum protection, the PQCG-800BE provides a stronger security foundation for long-term protection of sensitive enterprise and critical infrastructure communications.

Anti-SCA Protection and PUF-Assisted Hardware TRNG
The PQCG-800BE integrates Anti-Side-Channel Attack (Anti-SCA) protection to help safeguard cryptographic keys against leakage through side-channel attacks. A PUF-assisted Hardware True Random Number Generator (TRNG) supports secure cryptographic key generation, further strengthening the gateway’s hardware security foundation.
Advanced Threat Protection with Built-in IDS/IPS and Layer 7 Deep Packet Inspection
The PQCG-800BE integrates built-in Intrusion Detection and Prevention (IDS/IPS) with Layer 7 Deep Packet Inspection (DPI) to continuously inspect network traffic and identify malicious activities before they impact business operations. By analyzing application-layer traffic in real time, the gateway detects known threats, blocks suspicious connections, and enhances application visibility, helping organizations reduce cyber risks while maintaining reliable network communications.

Continuous Security Monitoring with Security Logs and Scheduled Signature Updates
The PQCG-800BE provides security logs, event reports, and scheduled signature updates to simplify cybersecurity management and improve threat visibility. Administrators can monitor network activities, analyze security incidents, and identify potential threats, while scheduled threat signature updates help maintain protection against newly emerging cyber attacks with reduced management effort.

Zero Trust-Protected Access with Identity-Based Authentication
The PQCG-800BE supports Zero Trust access control, FIDO2 Passkey authentication, TOTP-based MFA, and certificate-based authentication to strengthen identity verification for enterprise resources. Built-in ZTNA enables secure application-level access, helping reduce the risks of credential compromise and unauthorized access across distributed enterprise environments.

Secure Boot for Trusted System Integrity
The PQCG-800BE incorporates Secure Boot technology to ensure that only authenticated and trusted firmware is executed during system startup. Cryptographic image signature verification establishes a Chain of Trust across boot stages, helping protect system integrity against firmware tampering.
Automatic Failover between Dual WAN
Featuring 10GBASE-T RJ45 and 10GBASE-X SFP+ WAN interfaces, the PQCG-800BE supports intelligent Dual-WAN failover to maintain Internet connectivity. When the primary WAN connection becomes unavailable, the secondary WAN interface automatically takes over, minimizing downtime for business-critical applications.
Flexible WAN Interfaces for Network Expansion
The PQCG-800BE provides flexible WAN deployment through its 10G RJ45 and 10G SFP+ interfaces, allowing administrators to choose copper or fiber connectivity according to deployment requirements. Supporting long-distance fiber transmission and high-speed Ethernet connectivity, it enables flexible network expansion for headquarters, branch offices, data centers, and industrial facilities.
Secure and Convenient Network Management
The PQCG-800BE provides HTTPS web management and SNMP management interfaces for convenient configuration and monitoring. Its built-in web interface offers an easy-to-use, platform-independent management facility, while SNMPv1, SNMPv2c, and SNMPv3 support integration with standard network management software. These management options help administrators efficiently maintain distributed network deployments.
Comprehensive Firewall and Threat Defense
The PQCG-800BE integrates Stateful Packet Inspection (SPI), IDS/IPS, Layer 7 DPI, and DoS/DDoS mitigation to provide comprehensive network protection. MAC and IP filtering help enforce traffic policies, while port forwarding and DMZ functions allow internal servers to provide services to Internet users according to configured access rules.

Multi-Protocol VPN Connectivity for Distributed Networks
The PQCG-800BE provides secure remote access and site-to-site connectivity through its comprehensive VPN suite. Supporting IPSec, OpenVPN, WireGuard, GRE, PPTP, and L2TP, it offers flexible tunneling options for branch offices, remote workers, and distributed business operations. Combined with identity-based access control, these VPN capabilities help organizations establish secure connections across public networks.

Flexible Routing with NAT Disable Capability
The PQCG-800BE supports NAT disable functionality, allowing it to operate in pure routing mode for advanced network deployment scenarios. This feature is particularly beneficial for environments requiring end-to-end IP transparency, such as enterprise backbone networks, data centers, or integration with upstream security systems. By disabling NAT, administrators can achieve greater control over traffic flow and routing policies.
Ultra-Wide Channel for High-Speed Wi-Fi 7 Connectivity
The PQCG-800BE supports up to 160 MHz channel bandwidth and delivers a peak wireless transmission rate of up to 5100 Mbps. Designed for commercial environments, it provides the speed, efficiency, and reliable performance required for bandwidth-intensive network services.

Higher Throughput with 4096-QAM
With 4096-QAM encoding, the PQCG-800BE transmits more data within each signal, increasing wireless throughput and transmission efficiency. It is ideal for high-bandwidth applications such as 4K/8K video streaming, AR/VR experiences, and real-time cloud services.

Reliable Dual-Band Wireless Connectivity
Supporting concurrent 2.4 GHz and 5 GHz wireless connectivity, the PQCG-800BE provides flexible coverage and high-speed data transmission. Its dual-band design supports reliable wireless connectivity for diverse commercial deployment requirements.

Maximizing Work Efficiency with PLANET SD-WAN Gateway
The PQCG-800BE incorporates SD-WAN (Software-Defined Wide Area Network) functionality to optimize traffic across multiple WAN links. By managing available network connections at each site, it helps improve application performance, enhance the user experience, and simplify connectivity for distributed business operations.
Integrated Wi-Fi Management for Secure and Easy Deployment
The PQCG-800BE integrates an AP Controller, Captive Portal, RADIUS authentication, and DHCP server to streamline Wi-Fi deployment for small and medium-sized businesses. These built-in services reduce the need for external servers, enabling administrators to centrally manage APs, enforce access policies, and deliver secure employee and guest Wi-Fi networks with reduced setup complexity.

Centralized Remote Control of Managed APs
Through its intuitive web-based interface, the PQCG-800BE allows centralized control of PLANET Smart APs, with simple configuration of SSIDs, radio settings, and security policies. A quick four-step setup pushes wireless profiles to multiple APs or groups at once, enabling fast rollout and reduced deployment cost.

Administrators can cluster APs of the same model for unified management, flexibly expand or remove APs, and perform bulk provisioning or firmware upgrades from a single control point. This ensures scalable and efficient Wi-Fi management.

Intelligent SFP Diagnosis Mechanism
The PQCG-800BE supports SFP-DDM (Digital Diagnostic Monitor) functionality, allowing network administrators to monitor real-time transceiver parameters such as optical output power, optical input power, temperature, laser bias current, and supply voltage. This simplifies fiber-link monitoring and troubleshooting.

PLANET CloudNMS – Cloud-Based Universal Network Management
PLANET’s CloudNMS platform and mobile app empower IT staff to remotely manage all network devices and Powered Devices (PDs) in real time. Designed for enterprises and industries, CloudNMS minimizes the need for on-site troubleshooting by providing centralized monitoring, fault detection, and instant alerts.
With CloudNMS, businesses can manage diverse network deployments more efficiently, securely, and intelligently—all from a single cloud-based platform.

Post-Quantum Protection for Critical Enterprise Networks
The PQCG-800BE provides secure connectivity for government agencies, financial institutions, and enterprise networks handling sensitive information. Hybrid PQC TLS supports long-term communication security, while PUF-based configuration protection allows only paired devices with an inserted CoreTrust Key to modify gateway settings. Devices that do not meet both requirements cannot change settings even after login. Integrated IDS/IPS, Layer 7 DPI, security logs, and scheduled signature updates help administrators detect threats and monitor security events across headquarters, branch offices, and remote sites.

Secure Wi-Fi 7 Connectivity with Centralized Network Management
The PQCG-800BE combines Wi-Fi 7 5100BE dual-band connectivity with enterprise cybersecurity and centralized network management for business offices and branch networks. With a built-in AP Controller, Captive Portal, RADIUS authentication, and DHCP server, administrators can centrally manage wireless APs and deploy employee and guest networks with separate access policies. Integrated IDS/IPS, Layer 7 DPI, and firewall protection help safeguard wired and wireless traffic, while dual 10G WAN interfaces, SD-WAN, and automatic failover provide reliable connectivity for cloud applications and daily business operations.

Highlights
Hardware
Wi-Fi 7 Wireless Interface
Trusted Platform Security
Firewall & Traffic Control
Advanced Threat Protection & Application Security
Zero Trust & ZTNA
Identity, Authentication & Access Services
VPN & Secure Tunneling
Cryptography & Quantum Readiness
Routing, SD-WAN & WAN Optimization
High Availability & WAN Resilience
Network Services
Wireless & AP Management
System Management, Monitoring & Reporting
| Hardware Specifications | |
|---|---|
| Ethernet | 4 10/100/1000BASE-T RJ45 Ethernet ports (Port 1 to 4) 1 1G/2.5G/5G/10GBASE-T RJ45 port (Port 5) Supports WAN port mode or LAN port mode over software configuration |
| Fiber | One 1G/2.5G/10GBASE-X SFP+ port (Port 6) Supports WAN port mode or LAN port mode over software configuration |
| USB Port | 1 USB 2.0 port for system configuration backup and restoration |
| Reset Button | Reset to factory default |
| Thermal Fan | 1 |
| LED Indicators | System: PWR, Internet, (Green) Wireless Interfaces (2.4G & 5G) LNK/ACT (Green) Ethernet Interfaces (Port 1-4): 10/100/1000 LNK/ACT (Green) Ethernet Interfaces (Port 5): 1G/2.5G/5G/10G LNK/ACT (Green) Fiber Interfaces (Port 6): 1G/2.5G/10G LNK/ACT (Green) |
| Installation | Desktop installation or rack mounting |
| Power Requirements | 100~240V AC, 50/60Hz, auto-sensing |
| Power Consumption / Dissipation | Max. 3.3 watts/10.92BTU (Power on without any connection) Max. 11 watts/37.53BTU (Full loading) |
| Weight | 1725g |
| Dimensions (W x D x H) | 330.2 x 200 x 43.1mm, 1U height |
| Enclosure | Metal |
| Wireless Specifications | |
| Wireless Standard | IEEE 802.11be (Wi-Fi 7) |
| Frequency Band | 2.4GHz and 5GHz |
| Wireless Data Rate | Up to 5100Mbps |
| 2.4GHz Data Rate | Up to approximately 689Mbps |
| 5GHz Data Rate | Up to approximately 4324Mbps |
| Channel Width | Up to 160MHz |
| Modulation | 4096-QAM (4K-QAM) |
| MIMO | Advanced MIMO technology |
| Security Service | |
| Hardware Root of Trust | PUF-based hardware protection for configuration change authorization |
| Configuration Change Authorization | Requires completed device pairing and an inserted CoreTrust Key to modify gateway settings. Devices without either requirement cannot change settings, even after connecting and logging in. |
| Side-Channel Attack Protection | Anti-SCA protection to help safeguard cryptographic keys against side-channel attacks |
| Hardware Random Number Generator | PUF-assisted hardware TRNG for secure cryptographic key generation |
| Firewall Security | Hardware TRNG for secure cryptographic key generation Stateful Packet Inspection (SPI) Security log and event reporting Automatic threat signature updates Blocks DoS/DDoS attack Role-based access policy enforcement |
| ALG (Application Layer Gateway) | SIP, RTSP, FTP, H.323, TFTP |
| NAT | Port forwarding DMZ Host UPnP NAT disable (supports routing mode) |
| Content Filtering | MAC filtering IP filtering Web filtering |
| Bandwidth Management | Outbound load balancing Failover for dual-WAN QoS (Quality of Service) |
| Zero Trust | Zero Trust access control with identity verification Multi-factor authentication via external hardware security key support |
| Intrusion Prevention System | Intrusion Detection and Prevention (IDS/IPS) Layer 7 Deep Packet Inspection (DPI) Application-level traffic visibility |
| Secure Boot | Establishes a Chain of Trust (CoT) across all boot stages via cryptographic image signature verification |
| Networking | |
| Operation Mode | Routing mode |
| Routing Protocol | Static Route, Dynamic Route (RIP), OSPF |
| VLAN | 802.1Q Tag-based, Port-based, Multi-VLAN |
| Multicast | IGMP Proxy |
| NAT Throughput | Max. 9.4Gbps |
| Outbound Load Balancing | Supported algorithms: Weight |
| Protocol | IPv4, IPv6, TCP/IP, UDP, ARP, HTTP, HTTPS, NTP, DNS, PLANET DDNS, PLANET Easy DDNS, DHCP, PPPoE, SNMPv1/v2c/v3 |
| Key Features | HA (High Availability) Captive Portal RADIUS Server/Client AP Control |
| VPN | |
| VPN Function | IPSec (Net-to-Net, Host-to-Net) IPSec Remote Server GRE PPTP Server L2TP Server SSL Server SSL Client (Open VPN, Surfshark, NordVPN, PureVPN) WireGuard VPN Server/Client |
| VPN Tunnel Capacity by Protocol | IPSec: 16 GRE: 5 PPT: 100 SSL VPN: 200 |
| VPN Throughput | L2TP (1Gbps): 145~463Mbps L2TP (10Gbps): 483~885Mbps L2TP/IPsec (1Gbps): 150~334Mbps L2TP/IPsec (10Gbps): 438~496Mbps IPsec/AES128 (1Gbps): 894~910Mbps IPsec/AES128 (10Gbps): 1,110~1,310Mbps IPsec/AES256 (1Gbps): 752~842Mbps IPsec/AES256 (10Gbps): 864~1,060Mbps WireGuard (1Gbps): 815~883Mbps WireGuard (10Gbps): 1,430~1,890Mbps |
| Encryption Methods | DES, 3DES, AES or AES-128/192/256 encryption PQC TLS (Post-Quantum Cryptography TLS) ready Supports Hybrid Post-Quantum TLS key exchange using ML-KEM (Kyber) |
| Authentication Methods | SHA-256/SHA-384/SHA-512 authentication algorithm TLS_KYBER_RSA_WITH_AES_256_GCM_SHA384 FIDO2 Passkey authentication Certificate-based authentication TOTP MFA RADIUS authentication |
| Management | |
| Basic Management Interfaces | Web browser SNMP v1, v2c PLANET Smart Discovery utility/UNI-NMS supported PLANET NMS System/CloudNMS |
| Secure Management Interfaces | SSHv2, TLSv1.3, SNMP v3 |
| System Log | System Event Log Security Log Event Report Scheduled Signature Update |
| Others | Setup wizard Dashboard System status/service Statistics Security Monitoring Dashboard Connection status Auto reboot Diagnostics |
| Standards Conformance | |
| Regulatory Compliance | CE, FCC |
| Environment Specifications | |
| Operating | Temperature: 0 ~ 50 degrees C Relative Humidity: 5 ~ 95% (non-condensing) |
| Storage | Temperature: -10 ~ 60 degrees C Relative Humidity: 5 ~ 95% (non-condensing) |
| Ordering Information | |
|---|---|
PQCG-800BE |
Dual 10G PQC-ready Cybersecurity Gateway with Wi-Fi 7 5100BE |
Dual 10G PUF-Anchored Quantum-Resilient Cybersecurity Gateway with Wi-Fi 7 5100BE