Product Details

The EDR-G9004-VPN-2MGTXSFP-T is a four-port industrial secure router that puts firewall, NAT, VPN, and routing functions in a single hardened device. It is designed to sit between control networks and the rest of the enterprise, or at remote sites connecting back over public networks. There it acts as an electronic security perimeter around PLCs, RTUs, HMIs, and SCADA systems.

Traditional IT firewalls only see ports and IP addresses. The EDR-G9004 goes further and reads the contents of OT protocols through Deep Packet Inspection. Engineers can allow or block specific function codes and commands, not just whole connections. For example, a rule can allow reads from a PLC and block writes. Stateful inspection works in routed mode or in transparent (bridge) mode, so the router can be added to an existing flat network without re-addressing devices.

For remote access, the router supports up to 250 IPsec VPN tunnels with AES-256 encryption, plus L2TP. Dual WAN interfaces and VRRP provide failover. The two copper ports include Gen3 LAN Bypass: if the router loses power or fails, traffic keeps passing between those ports so critical communication is not cut off. With an optional license, the unit adds an industrial IPS that blocks known attack patterns and provides virtual patching for legacy equipment that can't be taken offline for updates.

The -T model is rated for -40 to 75°C. It has a metal IP40 housing, redundant 12/24/48 VDC power inputs, and certifications for substations, rail, maritime, traffic control, and hazardous locations. Moxa developed the platform to IEC 62443-4-2 with Secure Boot.

Why Choose the Moxa EDR-G9004?

  • Firewall, VPN, NAT, and router in one DIN-rail device
  • Deep Packet Inspection for Modbus TCP/UDP, DNP3, IEC 60870-5-104, IEC 61850 MMS, EtherNet/IP, OPC UA, Siemens S7, and more
  • Gen3 LAN Bypass keeps traffic flowing if the unit fails or loses power
  • Up to 250 concurrent IPsec VPN tunnels for secure remote access
  • Up to 2 Gbps firewall throughput
  • Optional IPS license adds threat prevention and virtual patching
  • Developed according to IEC 62443-4-2 with Secure Boot
  • Wide-temperature operation from -40 to 75°C with a 5-year Moxa warranty

Who Should Deploy This Technology?

This router suits organizations that need a real security boundary between OT and IT but don't have the budget or staff for an enterprise firewall stack. Examples include municipal water and wastewater systems, electric co-ops and substations, oil and gas sites, and manufacturers running PLC-based production lines. It works well at remote or unmanned sites that need secure VPN connectivity back to a central control room. It is also a good fit for flat control networks that need segmentation without re-architecting, thanks to transparent bridge mode.

What Other Options Should Be Considered When Deploying This Technology?

Pair the EDR-G9004 with a network TAP or data diode to give an OT monitoring or IDS platform a passive copy of traffic. You get enforcement at the perimeter and visibility inside it. For sites managing several Moxa routers, Moxa's MXsecurity software centralizes policy management and security visibility, and it is also how IPS licensing is delivered. SFP modules are sold separately, so plan fiber optics if you're using the combo ports for long-distance links. Moxa's WK-40-01 wall-mount kit is available if DIN-rail mounting isn't an option.

FAQs

Q: Are there other versions of this router available?
A: Yes. The EDR-G9004 Series includes a standard-temperature model (-10 to 60°C) and conformal-coated versions (-CT and -CT-T) for corrosive or high-humidity environments. Moxa also offers higher port-count routers. OT Cyber Direct can provide a custom quote to meet your needs. Contact us at Sales@OTCyberDirect.com or call 1-508-289-1195.

Q: Is the Intrusion Prevention System included?
A: The firewall, VPN, NAT, and Deep Packet Inspection features are included. The IPS requires a separate subscription license, available per device or through MXsecurity. We can quote licensing along with the hardware.

Q: Are SFP modules included?
A: No. SFP modules are purchased separately. The combo ports support 1G and 2.5G SFP modules for multi-mode or single-mode fiber runs.

Q: Is this router difficult to set up?
A: No. A setup wizard walks you through building a DMZ in a few steps. Object-based firewall rules make it simple to define and reuse IP groups, services, and industrial protocol policies.

Q: What support is available for this equipment?
A: OT Cyber Direct provides first-level installation and troubleshooting support. Moxa provides second- and third-level support for more complex networking issues. The unit carries a 5-year Moxa warranty.

Q: Do you ship outside of the United States?
A: No, but we can refer you to the Moxa team for help purchasing outside the U.S.

Summary

The EDR-G9004-VPN-2MGTXSFP-T is a four-port industrial secure router that puts firewall, NAT, VPN, and routing functions in a single hardened device. It is designed to sit between control networks and the rest of the enterprise, or at remote sites connecting back over public networks. There it acts as an electronic security perimeter around PLCs, RTUs, HMIs, and SCADA systems.

Traditional IT firewalls only see ports and IP addresses. The EDR-G9004 goes further and reads the contents of OT protocols through Deep Packet Inspection. Engineers can allow or block specific function codes and commands, not just whole connections. For example, a rule can allow reads from a PLC and block writes. Stateful inspection works in routed mode or in transparent (bridge) mode, so the router can be added to an existing flat network without re-addressing devices.

For remote access, the router supports up to 250 IPsec VPN tunnels with AES-256 encryption, plus L2TP. Dual WAN interfaces and VRRP provide failover. The two copper ports include Gen3 LAN Bypass: if the router loses power or fails, traffic keeps passing between those ports so critical communication is not cut off. With an optional license, the unit adds an industrial IPS that blocks known attack patterns and provides virtual patching for legacy equipment that can't be taken offline for updates.

The -T model is rated for -40 to 75°C. It has a metal IP40 housing, redundant 12/24/48 VDC power inputs, and certifications for substations, rail, maritime, traffic control, and hazardous locations. Moxa developed the platform to IEC 62443-4-2 with Secure Boot.

OT Cyber Direct

Translation missing: en.products.product.sku:EDR-G9004-VPN-2MGTXSFTP-T

MOXA EDR-G9004-VPN-2MGTXSFTP-T Industrial Secure Router

Regular price
$2,300.00
Sale price
$2,300.00
Regular price

Why we endorse this product:
Why we endorse this product:
Router, Industrial Firewall, VPN in one cost effective appliance
Simple to Deploy Network Address Translation (NAT) for segmentation
Optional IDS/IPS for network monitoring

Product Specs

  • 2x Gigabit RJ45 ports (Gen3 LAN Bypass) + 2x Gigabit copper/SFP combo ports (1G/2.5G SFP)
  • Firewall throughput up to 2 Gbps; IPsec VPN up to 800 Mbps; up to 250 VPN tunnels
  • Redundant 12/24/48 VDC inputs (9.6–60 VDC operating range)
  • -40 to 75°C operating temperature; metal IP40 housing; DIN-rail or wall mount
  • Certifications: IEC 61850-3, IEEE 1613, EN 50121-4, NEMA TS2, DNV, Class I Div 2, ATEX, IECEx
  • 45 x 135 x 105 mm; 800 g (1.76 lb)
  • 5-year warranty

Don't see what you're looking for?

Give us a call at  (508) 289-1195

Resources for MOXA EDR-G9004-VPN-2MGTXSFTP-T Industrial Secure Router