
Table of Contents
Peplink released Firmware 8.6.0 Beta 1 on April 23, 2026, and it is a sizable update. This release introduces SpeedFusion Boost for better single-session TCP performance, adds RADIUS over TLS for Wi-Fi deployments, expands per-WAN bandwidth controls, improves cellular startup behavior, and resolves a long list of stability and connectivity issues that had been collecting in maintenance branches throughout the 8.5.x cycle.
This beta also marks the end of the road for a number of older hardware models. If you run legacy Balance, MAX, MediaFast, or SpeedFusion Engine units, you need to know where you stand before planning any upgrade path.
Below is a practical breakdown of what is new, what has been fixed, which devices are affected, and why we strongly recommend holding off on deploying this firmware to production routers until the general availability release arrives.
Supported Devices
Firmware 8.6.0 Beta 1 covers a broad portion of the current Peplink lineup, including:
- Balance: 20X, Two, 310 5G, 310 Fiber 5G, 310X, 305 HW2, 380 HW6, 380X, 580 HW2-3, 580X, 710 HW3, 1350 HW2, 2500, 1350 EC, 2500 EC, 5000 EC
- BR Series: BR1 Mini HW3, BR1 Mini Core HW3, BR1 Mini 5G, BR1 Mini M2M, BR1 Pro HW7, BR1 Pro 5G, BR2 Pro HW4, BR2, BR2 Micro, BR1 IP55 HW4
- Transit: Pro E HW2, Duo Pro
- Dome: HD1 Dome Pro, Pro Duo, Pro LR
- UBR: UBR Plus
- B One: B One, B One Plus, B One 5G
- MediaFast: 500, 750
- MBX, MBX Mini, SDX, SDX Pro, EPX, PDX, and FusionHub
End of Support for Legacy Hardware
Starting with Firmware 8.6.0, the following models are no longer supported and will only receive 8.5.x maintenance releases going forward:
- Balance: 30 LTE HW3, 30 Pro HW1, 210 HW4-5, 310 HW4, One HW1-3, One Core HW1
- MAX: 700 HW3-4, BR1 ENT HW1-2, HD1 Dome HW1, HD2 HW5-6, HD2 Dome HW1, HD2 IP67 HW2-5, HD2 Mini HW1-4, HD2 with MediaFast HW1-4, HD4 HW1-5, HD4 IP67 HW1, HD4 with MediaFast HW1-4, Transit HW1-3, Transit 5G HW2-3, Transit Core HW1, Transit Duo HW1-3, Transit Duo Pro E HW1, Transit Pro E HW1
- MediaFast: 200 HW1, HW3
- SpeedFusion Engine: SFE CAM HW1
If your fleet includes any of these models, plan for a hardware refresh cycle. 5Gstore carries current-generation replacements across every major Peplink product line. Contact us at https://5gstore.com/site/contact_us for guidance on equivalent or upgraded models.
Notable New Features
SpeedFusion Boost (All Models). This is the headline addition. SpeedFusion Boost is designed to improve single-session TCP performance over high-latency SpeedFusion connections. For users who run bonded links across cellular, Starlink, or mixed transport types, single-session throughput has historically been a limitation compared to multi-session traffic patterns. Boost targets exactly that.
RADIUS over TLS (RadSec). Wi-Fi AP functionality picks up RadSec support across Balance 20X, 310 Fiber 5G, most BR models, Transit, Dome, B One, UBR Plus, MBX, and PDX. RadSec is increasingly important for enterprise Wi-Fi security and for deployments where RADIUS traffic traverses untrusted networks.
Key Improvements
The improvements list is long. Here are the ones that matter most for real deployments:
- Per-WAN bandwidth limiting so each WAN interface can be rate-limited independently, with QoS enforcement on actual traffic
- One-click SMS erase on SIMs across Balance, BR, Transit, B One 5G/Plus, UBR Plus, MBX, PDX, SDX, and EPX families
- Configurable 5G signal strength thresholds on supported cellular modems
- Improved Cellular WAN startup time after boot on 5GN devices
- Jumbo Frame support on BR1/2 Pro, Transit Duo Pro, Pro E, Dome Pro variants, and B One family
- LACP support on Balance 580X HW2
- Starlink WAN health check now uses 8.8.8.8 and 1.1.1.1 as default destinations when the first two DNS servers are selected
- Automated Docker container and image removal on devices with Edge Compute
- Automatic Ethernet detection on USB modem ports across Balance, BR2 Pro, B One, MediaFast, and MBX/SDX platforms
- DHCP relay and routing behind the mobile station on supported 5GN cellular in IP forwarding mode
- Edge Compute on B One Series when PrimeCare is active
- GPS information export through SNMP across all models
- Static routes that resolve through a domain name across all models
- WAN failover event logs for entering and exiting backup state
- WAN names in Status > Ethernet Port Details and the API for easier port identification
- Up to 1000 SpeedFusion peers on Balance 1350 EC
- Up to 40 Synergy WAN connections on select Synergy Controller models
- PPSK names in the wireless client list so admins can see which passphrase each client used
- Firewall log entries with the matching rule name for faster troubleshooting
- Improved OpenVPN detection in DPI, including traffic on non-standard ports
- IDS and DoS protection logging for blocked sessions
There is also a security-related change worth calling out. After upgrading, legacy certificates and keys such as DSA, RSA keys smaller than 2048 bits, and older PKCS#12 bundles will no longer be supported. Administrators should review their Certificate Manager configuration before upgrading and reissue or replace anything that falls below modern cryptographic standards.
Resolved Issues Highlights
This release resolves a very large number of issues accumulated during the 8.5.x cycle. A few that stand out:
- Multiple BR2 stability fixes including modem monitoring crashes, freezes, and a LAN/WAN interface crash under sustained packet flooding
- Balance 580X HW2 stability fix for devices restarting unexpectedly
- Cellular WAN reconnection after data connection failures
- Starlink detection fix to avoid conflicting local addresses and prolonged detection outages
- Starlink management-only mode when an overage restriction is detected
- RemoteSIM connection drop fixes on BR1 Mini 5G and cellular reconnect scenarios
- eSIM failover improvements when cloud access is unavailable
- DNS resolution over SpeedFusion no longer stops working after WAN connectivity is restored
- IPsec status check fix that previously could cause a device to become unresponsive
- Captive portal fix where the portal might not appear and Internet access was unavailable
- Switch Controller fixes for PVID changes and port settings reverting after reboot
- FIPS license activation is now enabled on eligible devices with an active care plan (excluding certain SKUs)
Known Issues
Peplink has flagged a handful of known issues in this beta. Two of them deserve particular attention:
- High Availability “Resume Master Role Upon Recovery” may not work as expected on all models except FusionHub
- Synergy Mode deployments that use a switch between the Synergy Controller and Synergized Device may be affected by changes to how Synergy WAN is carried over physical Ethernet Synergy Links (reference 36500)
Older known issues also remain: LAN clients in ports 1 or 2 may fail to obtain an IP with Multiple IP Passthrough WAN support, Docker containers cannot run on devices without an active DHCP server, and YouTube blocking may not work when YouTube traffic uses QUIC.
A Word of Caution on Production Use
This is a beta release, and it should be treated as one. The Beta 1 label exists precisely because Peplink expects to find and fix additional issues before general availability. A few reasons to hold off:
- Known issues in critical subsystems. The HA failback behavior and Synergy Mode changes are not minor. If you depend on High Availability pairs or Synergy deployments, this beta could introduce behavior that you will not notice until failover happens, at which point you are troubleshooting a production outage.
- Certificate handling changes. The removal of support for legacy certificates and keys after upgrade is a breaking change for some environments. If you have not audited your Certificate Manager recently, an upgrade could take down IPsec tunnels, VPN profiles, or captive portal SSL without warning.
- Large changeset scope. With dozens of new features, improvements, and fixes pulled in from many maintenance branches, the cumulative surface area for regressions is significant. Betas often uncover interaction bugs that only show up at scale.
- No InControl rollback safety net for software features. PrimeCare devices require InControl to be enabled for SpeedFusion Bonding, Smoothing, and Hot Failover software features to update. If something goes wrong in that pipeline, recovery can take longer than on a stable release.
Our recommendation: test 8.6.0 Beta 1 only on a lab unit or a non-critical spare device. Do not deploy it to routers that sit in front of revenue-generating traffic, emergency services, vehicle fleets, maritime deployments, or customer-facing Wi-Fi. Wait for the general availability release, and even then, stagger your rollout.
If you need newer features today that are already available in 8.5.x patch releases (and many of the fixes in this beta are), talk to us about getting on the right patch branch instead of moving to beta.
5Gstore Take
Peplink‘s 8.6.0 Beta 1 is a genuinely impressive consolidation of work from the 8.5.x cycle, and the new SpeedFusion Boost feature is the kind of improvement that could meaningfully change single-session performance for bonded cellular and Starlink deployments. We are looking forward to the GA release.
That said, production networks are not the place to find beta bugs. At 5Gstore, we see firsthand how a single unexpected firmware behavior can cascade through a fleet of vehicles, vessels, or field sites. If you are running a critical Peplink deployment and want help planning a firmware strategy, qualifying the beta on spare hardware, or sourcing replacements for the newly unsupported legacy models, get in touch with our team. We stock current-generation hardware from Peplink, Cradlepoint, Teltonika, Semtech, Inseego, Digi, and Katalyst, and we can help you build a rollout plan that does not gamble with uptime.
For the full release notes, see Peplink’s official documentation or check our 5Gstore Peplink product catalog for current models that support this firmware.
FAQ
Q: Can I install 8.6.0 Beta 1 on my production router? A: We do not recommend it. This is a beta release with known issues in High Availability failback behavior and Synergy Mode deployments. Use a lab or spare device instead, and wait for the general availability release before rolling to production.
Q: My Balance One or HD2 is not on the supported list. What are my options? A: These legacy models will continue to receive 8.5.x maintenance releases but will not get 8.6.0 features or future major firmware updates. If your deployment depends on newer capabilities, plan a hardware refresh. Contact 5Gstore for equivalent or upgraded current-generation models.
Q: What is SpeedFusion Boost and who benefits from it? A: SpeedFusion Boost is a new capability designed to improve single-session TCP performance over high-latency SpeedFusion connections. It is most useful for deployments that rely on bonded cellular, Starlink, or mixed-transport SpeedFusion tunnels where a single TCP session (such as a file transfer or video stream) previously could not take full advantage of aggregated bandwidth.
Q: Does the certificate change affect my existing deployment? A: Possibly. After upgrading to 8.6.0, DSA keys, RSA keys smaller than 2048 bits, and older PKCS#12 bundles will no longer be supported. Review your Certificate Manager configuration before upgrading. If you rely on IPsec, VPN profiles, or captive portals using legacy certificates, reissue them with modern cryptographic standards first.
Q: What is RadSec and do I need it? A: RadSec is RADIUS over TLS. It encrypts RADIUS authentication traffic between your Peplink AP and RADIUS server, which matters when that traffic crosses untrusted networks or the public Internet. If you run enterprise Wi-Fi with 802.1X authentication across distributed sites, RadSec is worth enabling. Home users and small office deployments typically will not need it.
Q: Will the HA known issue affect my failover pair? A: It might. The “Resume Master Role Upon Recovery” setting may not work as expected in this beta across all models except FusionHub. If your HA pair is configured to have a specific unit always resume master role after recovery, that behavior may not be reliable on 8.6.0 Beta 1. This is another reason to wait for GA.

