PEPLINK UNIVERSITY  •  A WEST NETWORKS TRAINING RESOURCE (352) 316-7701  ·  SHOP PEPLINK →

What’s New in Peplink Firmware 8.6

Router Firmware 8.6.0 (July 2026), fully categorized: WireGuard remote access, SpeedFusion Boost, Multi-APN, cellular IPv6, four eSIM profiles, OneWeb, RadSec, permanent FIPS, and every fix — plus upgrade prerequisites and retired models.

Router Firmware 8.6.0 went GA on July 29, 2026. It is one of the biggest Peplink releases in years — five brand-new capabilities, roughly forty-five improvements, and well over a hundred fixes. This page breaks every one of them into plain-English categories, with links to the sections of this site that teach each topic. The official release notes are here (PDF).

Before you upgrade — read this first.

  • BR1 Pro (CAT-20), BR1 Pro 5G, BR2 Pro, and all Dome, Transit, and B One models must be on 8.5.4 before moving to 8.6.0. Upgrade in two hops, not one.
  • With FIPS enabled, IPsec preshared keys must now be at least 14 characters. Shorter keys in existing profiles will stop connecting — rotate them first.
  • 8.6 enforces modern certificate standards. DSA certificates, short RSA keys, and legacy PKCS#12 files are no longer accepted; the router falls back to a secure default certificate. Review Certificate Manager before and after the upgrade.
  • FusionSIM / RemoteSIM users: bring the SIM Injector to firmware 1.2.6.
  • PrimeCare devices need InControl enabled to receive software feature updates (bonding, smoothing, hot failover).

The headlines

  • WireGuard is now a Remote User Access option — the modern, fast, roaming-friendly VPN protocol, on every model, alongside OpenVPN, L2TP, and PPTP.
  • SpeedFusion Boost ships in mainline firmware — a per-profile throughput optimizer for lossy, high-latency bonded links. It is what makes cellular + Starlink bonds feel like fiber; we have measured close to 1.5 Gbps across bonded Starlink terminals in the field with Boost enabled.
  • Cellular grows up: Multi-APN connections, IPv6 on selected modules, 5G SA on more hardware, framed routing, and control over 5G SA carrier aggregation.
  • Four eSIM profiles per modem, plus support for the newer GSMA profile format more providers now use.
  • OneWeb joins Starlink as a first-class satellite WAN, and Starlink health and status reporting gets sharper.
  • Security posture jumps: permanent FIPS on eligible hardware, RADIUS over TLS (RadSec) for Wi-Fi, SHA2-384 for IPsec, two command-injection/exposure vulnerabilities closed, and the certificate modernization above.

SpeedFusion VPN & bonding

Taught in the SpeedFusion guide and SpeedFusion 101.

New & improved

  • SpeedFusion Boost — per-profile application-performance optimizer for bonds built on Starlink, 5G, and other loss-prone links. All models.
  • MAC address whitelisting for Layer 2 SpeedFusion tunnels, including prefix matching — control exactly which devices ride a stretched LAN.
  • “Advertise Routes to Peer” toggle for NAT-mode profiles — you can now stop a NAT-mode spoke from pushing its routes to the far side.
  • Up to 1,000 SpeedFusion peers on the Balance 1350 EC — mid-tier hardware now terminates enterprise-scale hub duty.
  • IP ToS values updated inside a tunnel are now preserved after decapsulation — QoS markings survive the trip.

Fixed

  • OSPF routes learned over SpeedFusion no longer conflict with local VLAN routes.
  • Profiles no longer stick at “Updating Routes…” after a firmware upgrade.
  • Layer 2 tunnels: ARP requests for static-route gateways are no longer dropped, and enabling Layer 2 SpeedFusion no longer breaks IP passthrough.
  • DNS resolution over SpeedFusion recovers properly after WAN restoration; intermittent Domain Lookup Policy failures resolved.
  • SpeedFusion profiles now load correctly after a High Availability master reboots with no WAN available.

SpeedFusion Connect (SFC)

Reminder: SpeedFusion (the bonding engine in your router — perpetual, no subscription) and SpeedFusion Connect (Peplink’s hosted bonding service) are different things. Everything in this section applies to the hosted SFC service only.
  • New: SFC Direct Access — the SF Connect app can now connect directly to supported routers.
  • Fixed: Direct Access sessions can reach the router’s Web Admin and LAN devices as intended.
  • Fixed: the SFC status no longer shows “Unlimited” after a data quota is actually exhausted.
  • Fixed: SFC sub-tunnels establish correctly after upgrade.

Remote User Access & IPsec

Background: WAN, VPN & Cloud.

  • New: WireGuard as a Remote User Access VPN option on all models — modern crypto, fast handshakes, survives network changes gracefully.
  • IPsec Phase 2 adds SHA2-384 authentication.
  • The UI now warns when an IPsec / Remote User Access preshared key is shorter than 14 characters (mandatory under FIPS).
  • Fixed: OpenVPN Remote User Access no longer loses its Source Network Address setting when VLAN settings change.
  • Fixed: IPsec profiles show a certificate summary instead of dumping raw certificate content; IPsec status checks no longer hang the device.

Cellular & 5G

Taught across WAN Settings and the multi-carrier comparison.

Improved

  • Multi-APN connections on 5GN-class modules — one modem, multiple APNs at once (think: separate public-safety and internet APNs on the same SIM).
  • IPv6 on cellular for a wide range of 5G and LTE modules.
  • 5G Standalone (SA) support for 5GD modules, and a control to enable/disable 5G SA carrier aggregation on 5GK/5GN modules.
  • Framed routing on 5GK/5GN — the carrier can route whole subnets to the router.
  • Cellular MTU handling now honors the network-provided MTU when it is lower than the configured value.
  • Configurable 5G signal-strength thresholds, a one-click erase-all-SMS action, and support for SMS control messages from SIM-provider portals.
  • DHCP relay and routing behind the mobile station in IP-forwarding mode (5GN).
  • Faster cellular WAN startup after boot (redundant carrier-selection steps removed).
  • 5GN modules can take firmware with RED DA support and better 5G SA compatibility; LTEA-US modules are recoverable through support.cgi; a new CLI command shows cellular status across modem types.
  • BR1 Mini 5G gains Ethernet port status monitoring.

Fixed

  • Reconnect reliability: DHCP lease renewals, reconnection after data-connection failures, reconnection after switching manually selected carriers, and delays after changing network modes.
  • Carrier-specific: Yettel Bulgaria and A1 Bulgaria connections, Orange France (5GD, IPv4-only mode), Rakuten Mobile carrier profile, Verizon profile switching on LTEA-Q, Celona networks (IPv4 data settings).
  • Private networks: CBRS disconnects resolved by disabling IMS when not needed.
  • SIM handling: wrong-SIM selection when detection hardware was unavailable, missing event logs and better SIM failover when a SIM can’t be read, tower scans now run with a locked SIM PIN, SMS sending on LTE-E.
  • Module stability: FN990 health-check crash in 5G mode, modem commands failing during eSIM/diagnostic activity, 5GH missing mode information, 5GN reverting to automatic RAT mode, cellular firmware upgrades on LTEA-B/LTEA-Q and on BR-series modules, modem-monitoring crashes on BR2 devices.
  • Cosmetic-but-important: SINR shown only when valid, operator passwords masked in the UI, and a long delay refreshing WAN Restriction rules removed.

eSIM & RemoteSIM

Improved

  • Up to four eSIM profiles per cellular module.
  • Support for the newer GSMA eSIM profile format used by more providers.
  • BYO eSIM details now display in Synergy mode; Peplink eSIM carrier names are clearer.

Fixed

  • RemoteSIM: connects with PIN-enabled SIMs, survives cellular reconnects and USB controller resets, discovery responses route correctly under high-priority outbound policies, client no longer stops unexpectedly, and BR1 Mini 5G recovers RemoteSIM after PoE toggles.
  • eSIM: BYO settings no longer vanish with non-Webbing SIMs, device information reports correctly to carriers, monthly/billing usage history restored, SIM failover can reach Peplink eSIM even when cloud access is down, and the status now reads “No Peplink eSIM Data” when data is exhausted.

Satellite WANs — Starlink & OneWeb

  • New: OneWeb integration — the second LEO constellation gets first-class WAN treatment.
  • Starlink status information now appears in WAN Details.
  • Starlink health checks use 8.8.8.8 / 1.1.1.1 sensibly when DNS-based checking is selected or no host is configured.
  • Fixed: Starlink WAN status disappearing when a Data Pool limit was reached; a vWAN configured for Starlink staying recognized after reboots and dish updates; detection no longer falls back to a conflicting local address.

Wi-Fi & AP management

Taught in Wi-Fi, AP & Switch.

New & improved

  • RADIUS over TLS (RadSec) — encrypted transport for Wi-Fi RADIUS authentication, a requirement showing up in more enterprise and PCI environments.
  • PPSK names in the wireless client list — see which passphrase each client used.
  • Advertise metered connection in beacon frames; enable/disable specific data rates per radio; tri-band external and integrated APs supported in AP Controller; Wi-Fi APs on Synergized devices manageable through AP Controller.
  • Wi-Fi WAN roaming hands off with fewer interruptions.

Fixed

  • Clients stuck connected at 0 Mbps on weak signal; radios failing to start with auto channel width on certain channels; 32-character SSIDs displaying wrong in usage reports; Wi-Fi WAN latency display; MBX Mini Wi-Fi LEDs.
  • WPA2/WPA3 Personal is now the default SSID security mode on supported APs.

Known issue: Air Monitor does not work on selected Wi-Fi AP devices in this release.

Routing & outbound policy

Taught in Routing and Outbound Policy.

Improved

  • BGP: import default routes, import routes only from a specified origin ASN, and redistribute BGP default routes into OSPF.
  • Static routes that resolve through a domain name — route to a name, not a brittle IP.
  • Virtual Network Mapping for inter-VLAN traffic, including virtual IPs that overlap VLAN subnets — a real tool for mergers and IP-conflict surgery.

Fixed

  • SaaS traffic classification in Connection Sessions now matches SaaS-based outbound rules; hostnames resolving to many addresses are recorded correctly.
  • DNS: CNAME records with underscores accepted, DNS-over-HTTPS works with Quad9, no more port-unreachable failures during boot, multicast relay uses the right source MAC.

Security, FIPS & certificates

Related: PCI-DSS hardening.

  • Permanent FIPS support on eligible devices.
  • Certificate modernization: weak certificates and keys (DSA, short RSA, legacy PKCS#12) are rejected; outdated certificates trigger an automatic fall-back to a secure default certificate. Audit Certificate Manager.
  • RADIUS authentication for Web Admin gains NAS-Identifier support.
  • Vulnerabilities closed: a CLI command-injection flaw, a Web Admin flaw allowing unauthenticated access to internal binaries, multiple SSH/CLI component vulnerabilities, and CVE-2026-42945 in web service components. This list alone justifies the upgrade.
  • Fixed: InControl Remote Web Admin now works in FIPS mode.

Firewall, DPI & content control

Taught in Firewall & Access Rules.

Improved

  • Firewall log entries now carry the matching rule name — auditing just got humane.
  • Serial interfaces can be governed by Local Service Firewall rules.
  • Sessions blocked by IDS and DoS protection are now logged; OpenVPN detection in DPI catches non-standard ports.

Fixed

  • Amazon Video blocking no longer breaks Amazon shopping; intermittent Web Blocking misses resolved; DNS-inspection stability issue fixed; Yandex Alice traffic classified correctly.
  • Captive portal: no-show portal (with no internet) fixed; per-client data usage correct when one MAC appears on multiple VLANs.

Known issue: YouTube blocking may not catch QUIC traffic.

QoS & traffic control

Related recipe: QoS for VoIP.

  • Per-WAN bandwidth limiting — configured upload/download caps are now enforced on real traffic per interface.
  • IEEE 802.1p CoS values supported on VLAN-tagged and virtual VLAN WANs.
  • Fixed: a QoS stability issue and a Web UI freeze when changing WAN bandwidth settings.

Synergy Mode

Complete Synergy Mode setup guide →

  • New transport mode setting (Performance vs Compatibility) for Synergy WANs; up to 40 Synergy WAN connections on selected models; a secure fallback TLS certificate keeps older peers connecting.
  • Fixed: WAN counts on the device display, WAN mapping/status after config changes (no reboot needed), link drops during Speedtest or saturation, VLAN-WAN mapping on module-based models, BYO eSIM visibility, and Synergized traffic being dropped by Weighted Balance policies when all selected WANs were down.

FusionHub

Related: SpeedFusion under the hood.

  • SSH and CLI access for token and authentication management.
  • SpeedFusion Route Isolation support.
  • Graceful shutdown/reboot handling on Proxmox.
  • Fixed: hitting the maximum concurrent session ceiling, and unresponsiveness over time when using SpeedFusion with VRF.

Edge Compute & Docker

Taught in Edge Compute.

  • Edge Compute arrives on B One / B One Plus (with active PrimeCare).
  • Automated Docker container and image removal actions.
  • Fixed: containers consuming excessive CPU, image pulls failing with very long registry passwords, and the ContentHub file manager not loading files.

Known issue: Docker containers require an active DHCP server on the device.

Platform, management & monitoring

Taught across System, Status, and Console & Management Ports.

Improved

  • Dedicated Management Port is now configurable in LAN Port Settings on Balance 2500 / 1350 EC / 2500 EC / 5000 EC — the break-glass port can finally be governed properly.
  • Device API: upload and download configuration files with token-based authentication — real config management automation.
  • SNMP: customizable trap alerts for device health and cellular events, plus GPS export through SNMP.
  • Logs that explain themselves: WAN status summary logs, WAN failover enter/exit-backup events, and WAN names in Ethernet Port Details and the API.
  • IPv6 SLAAC/DHCPv6 connection modes for Ethernet WAN; one included Virtual WAN on VLAN for eligible models with an active Care plan; jumbo frames on selected models; LACP on Balance 580X HW2; automatic Ethernet detection on all USB modem ports; GPIO-triggered factory reset; InTouch monitoring of USB serial adapters; raw TCP from the CLI to Ethernet-to-Serial servers; a refreshed front-panel display in the Web UI.

Fixed

  • Applying changes could revert a device to factory defaults — fixed (and worth the upgrade by itself).
  • Firmware upgrades now fail loudly with an error when storage is insufficient, and no longer log a phantom “Powered Off” event.
  • High Availability: “Resume Master Role Upon Recovery” honored (including no-WAN environments), config sync interval reduced to 2 minutes, HA LAN admin IP tracks LAN IP changes.
  • InControl connectivity: device status updates correctly, agent connection stability improved, WAN up/down events report the right priority, and WAN IP changes during DHCP renewal hit the event log.
  • IPv6: passthrough toggles no longer need a reboot; LAN clients get connectivity immediately after SLAAC/DHCPv6 addressing.
  • Switch Controller: PVID changes apply properly and port settings survive controller reboots.
  • GPS: corrupted RMC output after week rollover fixed; invalid samples no longer skew stationary-interval forwarding.
  • Hardware-specific: Balance 580X HW2 unexpected restarts and interface mapping, BR2-family crash under sustained packet flooding, USB WAN on USB 3.0 ports, USB WAN settings surviving reboot, MediaFast proxy/cache service restarts, drop-in mode WAN-subnet host detection.
  • Status truthfulness: offline LAN clients no longer show online; CLI ping/arping show correct interface names; general packet-processing and stability fixes.

Known issue: with multiple-IP passthrough WAN, LAN clients on ports 1–2 may fail to obtain an IP.

Retired in 8.6 — check your fleet

These models stop at 8.5.x (they still receive 8.5.x maintenance releases, but no 8.6 features):

  • Balance: 30 LTE, 30 Pro HW1, 210 HW4-5, 310 HW4, One HW1-3, One Core HW1
  • MAX: 700 HW3-4, BR1 ENT HW1-2, HD1 Dome HW1, HD2 HW5-6, HD2 Dome, HD2 IP67 HW2-5, HD2 Mini HW1-4, HD2/HD4 with MediaFast HW1-4, HD4 HW1-5, HD4 IP67 HW1, Transit HW1-3, Transit 5G HW2-3, Transit Core, Transit Duo HW1-3, Transit Duo Pro E HW1, Transit Pro E HW1
  • MediaFast: 200 HW1/HW3  ·  SpeedFusion Engine: SFE CAM HW1

Running one of these? That’s not an emergency — it’s a planning signal. Find the current model that replaces it, or talk to an expert.

Field take

Most firmware releases are maintenance. This one changes what the platform is: WireGuard for your road warriors, Boost for your satellite bonds, Multi-APN and four eSIMs for your carrier strategy, and a security cleanup that closes real holes. Stage it on a lab unit, mind the 8.5.4 stepping-stone, then roll it fleet-wide through InControl.

Webinar: Firmware 8.6.0 — Boost, OneWeb, FIPS

Explore Peplink Firmware 8.6.0 features including SpeedFusion Boost, OneWeb support, RadSec, FIPS, eSIM updates, and AP Controller tools.

Watch: Webinar: Firmware 8.6.0 — Boost, OneWeb, FIPS · Peplink University

From Peplink University with Professor P.

From the archive: what was new in Firmware 8.3.0

*Fair Usage Policy Applies after SFCP allowance has been exceeded.

Watch: From the archive: what was new in Firmware 8.3.0 · Peplink University

From Peplink University with Professor P.

Watch: related training videos