The ATRM50 is a rugged 5G router built for transportation, featuring 4 x M12 Gigabit Ethernet ports and M12 power input for durable, secure connections. It delivers ultra-high cellular speeds up to 3.4 Gbps and supports dual SIM with eSIM™ for seamless failover. Certified to EN 45545-2 and EN 50155 standards, the ATRM50 is engineered to meet the rigorous safety and reliability requirements of railway systems—while also being a strong fit for other demanding transportation environments.
Release 16
Supports sending and reading Unstructured Supplementary Service Data messages
Operator block/allow list (by country or separate operators)
Band lock, Used band status display
Auto APN
Direct connection (bridge) between mobile ISP and device on LAN
Router assigns its mobile WAN IP address to another device on LAN
Framed routing: support an IP network behind 5G UE
SSID stealth mode and access control based on MAC address
Up to 150 simultaneous connections
Allowlist, blocklist
Static routing, Dynamic routing (BGP, OSPF v2, RIP v1/v2, EIGRP, NHRP), Policy based routing
Ping Reboot, Wget Reboot, Periodic Reboot, LCP and ICMP for link inspection
View device ports, enable and disable each of them, turn auto-configuration on or off, change their transmission speed, and so on
Visual representation of your network, showing which devices are connected to which other devices
Captive portal (hotspot), internal/external Radius server, Radius MAC authentication, SMS authorisation, SSO authentication, internal/external landing page, walled garden, user scripts, URL parameters, user groups, individual user or group limitations, user management, 9 default customisable themes and optionality to upload and download customised hotspot themes
Supported >77 service providers, others can be configured manually
DNS over HTTPS proxy enables secure DNS resolution by routing DNS queries over HTTPS
Initial virtual routing and forwarding (VRF) support
Real-time monitoring, wireless signal charts, traffic usage history
Preconfigured firewall rules can be enabled via WebUI, unlimited firewall configuration via CLI, DMZ, NAT, NAT-T, NAT64
DDOS prevention (SYN flood protection, SSH attack prevention, HTTP/HTTPS attack prevention), port scan prevention (SYN-FIN, SYN-RST, X-mas, NULL flags, FIN scan attacks)
Port and tag-based VLAN separation
Blacklist for blocking out unwanted websites, Whitelist for specifying allowed sites only
Identification and authentication module, TPM 2.0 standard
Let's Encrypt and SCEP certificate generation methods
Multiple clients and a server can run simultaneously, 27 encryption methods
DES-CBC 64, RC2-CBC 128, DES-EDE-CBC 128, DES-EDE3-CBC 192, DESX-CBC 192,
BF-CBC 128, RC2-40-CBC 40, CAST5-CBC 128, RC2-64-CBC 64, AES-128-CBC 128, AES-128-CFB 128, AES-128-CFB1 128, AES-128-CFB8 128, AES-128-OFB 128, AES-128-GCM 128, AES-192-CFB 192, AES-192-CFB1 192, AES-192-CFB8 192, AES-192-OFB 192, AES-192-CBC 192, AES-192-GCM 192, AES-256-GCM 256, AES-256-CFB 256, AES-256-CFB1 256, AES-256-CFB8 256, AES-256-OFB 256, AES-256-CBC 256
XFRM, IKEv1, IKEv2, with 14 encryption methods for IPsec (3DES, DES, AES128, AES192, AES256, AES128GCM8, AES192GCM8, AES256GCM8, AES128GCM12, AES192GCM12, AES256GCM12, AES128GCM16, AES192GCM16, AES256GCM16)
GRE tunnel, GRE tunnel over IPsec support
Client/Server instances can run simultaneously, L2TPv3, L2TP over IPsec support
Proxy designed to add TLS encryption functionality to existing clients and servers without any changes in the program’s code
SSTP client instance support
ZeroTier VPN client support
WireGuard VPN client and server support
Tinc offers encryption, authentication and compression in it's tunnels. Client and server support.
Client, Server
TCP
Allows sending commands and receiving data from MODBUS Server through MQTT broker
Station, Outstation
TCP, USB
DLMS – standard protocol for utility meter data exchange
Firmware update from server, automatic notification
SSH (v1, v2)
SMS status, SMS configuration
OpenACS, EasyCwmp, ACSLite, tGem, LibreACS, GenieACS, FreeACS, LibCWMP, Friendly tech, AVSystem
MQTT Broker, MQTT publisher
SNMP (v1, v2, v3), SNMP Trap, Brute force protection
Management API over HTTP/HTTPS
Teltonika Remote Management System (RMS)
Allows monitoring of: Device Model, Revision and Serial Number, WAN Type and IP, Mobile Cell ID, ICCID, IMEI, Connection Type, Operator, Signal Strength. Has reboot and firmware upgrade actions
Can be configured with Data to Server to send all the available parameters to the cloud. Has Direct method support which allows to execute RutOS API calls on the IoT Hub. Also has Plug and Play integration with Device Provisioning Service that allows zero-touch device provisioning to IoT Hubs
Utility to interact with the AWS cloud platform. Jobs Support: Call the device's API using AWS Jobs functionality
Update FW from file, check FW on server, configuration profiles, configuration backup
Update FW
Update FW/configuration for multiple devices at once
Update FW without losing current configuration
RutOS (OpenWrt based Linux OS)
Busybox shell, Lua, C, C++, and Python, Java in Package manager
SDK package with build environment provided
You can create your own custom, branded firmware and web page application by changing colours, logos, and other elements in our firmware to fit your or your clients’ needs
USB 2.0
Samba share, USB-to-serial
Possibility to connect external HDD, flash drive, additional modem, printer, USB-serial adapter
FAT, FAT32, exFAT, NTFS (read-only), ext2, ext3, ext4
2 x Inputs for Ignition Detection and Low Battery
Email, RMS, SMS
Allows to set certain I/O conditions to initiate event
9 – 50 VDC, reverse polarity protection, Overvoltage protection (70V), Surge protection >69 VDC 10us max
Idle: < 5.5 W, Max: < 16 W
4 x M12 X code 8-pin female ports, 10/100/1000 Mbps
1 x M12 A code 4-pin male connector
Reboot/User default reset/Factory reset button
1 x Grounding screw