September 15, 2026 How Industrial Routers Can Protect Legacy Devices from Unwanted Internet Connections

An engineer had a batch of devices with known vulnerabilities. They needed to reach other machines on the local network and a specific license server, but were not allowed to connect to any other internet address. Mainstream consumer routers offer little beyond app-based parental controls, and per-device (MAC address) IP whitelists simply are not part of that feature set. Add gigabit Ethernet, four devices, no Wi-Fi required, and a tight budget, and the list of candidates shrinks fast. This kind of requirement is even more common on factory floors, and it usually ends up on the firewall features of an industrial cellular router.

Translated into plant language, the device profile gets more specific: PLC, CNC systems, and industrial PC that have been running for a decade or more. The operating systems are old, antivirus software cannot be installed, and taking the line down for patching is rarely an option—yet data collection and remote maintenance still demand that these machines stay online. Once such a device is infected with malware, it will often reach out on its own to an external command-and-control server. The device itself has no way to block that. That leaves exactly one place to intervene: the network exit these devices share. Taking the industrial cellular router USR-G816 from PUSR as an example, three things can be done at this exit.

First: a per-device outbound whitelist

The G816 firewall provides traffic rules configuration. Each rule covers source MAC, source IP, source port, destination IP, destination port, and an action—Drop, Accept, or Reject—and the rule can be applied only to hosts matching a specified MAC address. Mapping this back to the request above: create one rule for the device's MAC with destination "any" and action Drop, then add a second rule with destination set to the license server address and action Accept. Access to other machines on the local network stays untouched; the only path to the outside is the one explicitly allowed. The firewall page itself offers whitelist, blacklist, port forwarding, and access restriction entries, and rules are added right in the browser.

Two details make this workable in practice. The specification sheet lists filtering by IP, MAC, and domain, so a device that talks to a fixed set of hostnames can be controlled by domain as well, and address translation (NAT) plus DMZ options sit on the same page for cases where a single service genuinely has to be exposed. And because rules match on MAC first, a static IP is not a prerequisite—the filter follows the device, not the address it happens to hold this week.

Second: pull remote access into a tunnel

The whitelist governs where devices go. The other side of the question is who gets in. When field devices need remote maintenance, opening a public port on the router is the most common mistake. The G816 supports OpenVPN, IPSec, PPTP, L2TP, and GRE; its enhanced OpenVPN implementation can act as a client connected to three different servers simultaneously, or serve as an OpenVPN server itself. Maintenance terminals come in through the tunnel, and the device addresses never appear on the public internet. On the inbound side, SYN-Flood protection is built in, so a flood of half-open connections aimed at the router gets dropped before it touches the devices behind it. Outbound guarded by a whitelist, inbound funneled through a tunnel—both directions now have a boundary.

Third: make abnormal traffic visible

The most visible symptom of an infected device is outbound traffic that no one scheduled. The G816 supports three categories of real-time alarms—device offline, weak signal, and traffic overrun—pushed by email or SMS, with repeated pushes so a missed notice does not mean a missed event. Once the whitelist has cut off unauthorized outbound paths, the alarm log becomes the evidence for confirming whether a device has been trying to reach out. A device that repeatedly trips the traffic alarm while its whitelist allows only one destination is telling the network team something, and the log timestamps make that finding shareable in a maintenance report.

Specs to line up during selection

Ports and speed: the 5g cellular router G816 offers one 10/100/1000 Mbps WAN port (switchable to LAN) plus three gigabit LAN ports. Four devices connect directly—no extra switch needed.

Environmental fit: metal housing, 9–36 V DC wide-range power with reverse polarity protection, −35 to 75 °C operating range, surge/EFT/ESD protection at level 3 EMC, a hardware watchdog, and DIN-rail or wall mounting for long-term installation inside a control cabinet. One RS232/RS485 serial port with Modbus TCP/RTU conversion brings serial devices onto the network as well.

Uplink depends on the site: where 5G coverage exists, use 5G—the G816 supports SA/NSA, dual-SIM single standby, and 4G fallback, with automatic WAN failover when a wired link is primary. Where 4G is enough, the USR-G806w is the more compact option: Qualcomm solution, one WAN plus two LAN ports (configurable as three LAN), 104 × 102 × 28 mm, the full VPN protocol suite, dual hardware/software watchdogs, −20 to 70 °C, DIN-rail or wall mounting.

Management effort also counts. Both models connect to the PUSR remote management platform, where firewall and VPN parameters are adjusted, devices are rebooted, and firmware is upgraded without a site visit—an industrial cellular router deployed at fifty sites is configured once, not fifty times.

The method itself is not complicated: deny all outbound traffic by default, allow each device by MAC only the destinations it needs, move remote access into a VPN, and let traffic alarms catch what slips through. With those four configurations in place, a legacy device that cannot be upgraded or hardened is boxed into a well-defined boundary inside the network. The role of an industrial cellular router at this point is not to improve the device's own security—it is to hold the network layer on behalf of equipment that cannot protect itself.

REQUEST A QUOTE
Industrial loT Gateways Ranked First in China by Online Sales for Seven Consecutive Years **Data from China's Industrial IoT Gateways Market Research in 2023 by Frost & Sullivan
Subscribe
Copyright © Jinan USR IOT Technology Limited All Rights Reserved. / Sitemap / Privacy Policy
Reliable products and services around you !
Subscribe
Copyright © Jinan USR IOT Technology Limited All Rights Reserved. / Sitemap / Privacy Policy