Peplink Firmware 8.6 Is Here: WireGuard, SpeedFusion Boost, and a Security Release in Disguise

On July 29, Peplink shipped Router Firmware 8.6.0. I’ve been running the release candidates across lab units for months — I wrote about RC4 back when IPv6 and the new Router API landed — and now that it’s GA I can say it plainly: this is the biggest firmware release Peplink has put out in years. Five genuinely new capabilities, around forty-five improvements, and well over a hundred fixes. If you operate a fleet, this one changes your week.
The official release notes (PDF) run forty-two pages. Here’s what actually matters, from someone who deploys this gear for a living.
WireGuard, finally
The headline for anyone with people on the road: WireGuard is now a Remote User Access option on every model. If you’ve lived with OpenVPN client rollouts and L2TP quirks, you know why this matters — WireGuard is fast, the crypto is modern, and it survives a laptop hopping from hotel Wi-Fi to a phone hotspot without dropping the tunnel. Your remote users connect to the router they already own. No extra appliance, no per-seat subscription. That’s the “own your network” philosophy applied to remote access.
SpeedFusion Boost goes mainline
Boost is a per-profile throughput optimizer for bonded links that are fast but imperfect — Starlink, 5G, anything with jitter and loss. It’s been trickling through special builds; in 8.6 it’s simply part of the firmware, on all models.
Why should you care? Because this is the piece that makes satellite-plus-cellular bonds behave. We’ve measured close to 1.5 Gbps across bonded Starlink terminals in a real deployment with Boost doing the work. Not lab numbers — salt-air, moving-platform numbers. Pair it with WAN Smoothing on a sub-tunnel and “the internet went out” quietly disappears from your ticket queue. No failover event. No failover, period — the bond just keeps working. If your disaster recovery plan still includes the word “failover,” you’re doing it wrong.
Same section of the release, easy to miss: the Balance 1350 EC now terminates up to 1,000 SpeedFusion peers. That used to be flagship-chassis territory. Mid-tier hub hardware just got a lot more interesting for anyone building hub-and-spoke at scale.
The quiet cellular revolution
8.6 is stacked with cellular work that reads like a carrier-integration wishlist:
- Multi-APN — one modem can hold multiple APN connections at once. Public-safety APN and general internet on the same SIM, simultaneously. Fleet and first-responder people have wanted this forever.
- IPv6 on cellular across a wide range of 5G and LTE modules — carriers are pushing v6-first cores, and the routers now speak it natively on the WAN that matters most.
- Four eSIM profiles per modem, plus support for the newer GSMA profile format. Carrier strategy stops being a screwdriver problem.
- 5G Standalone on more hardware, control over SA carrier aggregation, and framed routing so a carrier can route entire subnets to your router.
- Dozens of unglamorous reconnect fixes — DHCP lease renewals, carrier switching, recovery after data-connection failures. The stuff that separates “works in the demo” from “works in month eleven.”
Satellite: OneWeb joins the party
OneWeb gets first-class WAN integration in 8.6, joining Starlink. Starlink itself gets sharper too — dish status now shows up right in WAN Details, and health checks behave sensibly out of the box. If you design diverse-WAN kits like I do, a second LEO constellation with native integration is a genuinely new tool: two independent satellite paths, bonded with cellular, on one box.
There’s a security release hiding in here
If nothing above applies to you, upgrade anyway. Buried in the resolved-issues list: a CLI command-injection vulnerability, a Web Admin flaw that allowed unauthenticated access to internal binaries, patched SSH components, and CVE-2026-42945 in the web service stack. All closed in 8.6.
On the proactive side: permanent FIPS support on eligible hardware, RADIUS over TLS (RadSec) for Wi-Fi authentication, SHA2-384 for IPsec, and a firm line on certificates — DSA, short RSA keys, and legacy PKCS#12 files are no longer accepted. If you’re carrying PCI scope on Peplink gear (a lot of my customers are), this release is your friend and your homework at the same time: audit Certificate Manager before you roll it out.
Operator quality of life
The features that never make a datasheet but make the job better:
- Firewall logs now include the matching rule name. Whoever pushed for this: thank you.
- WAN status summary logs and failover event logs — when a link flaps at 3am, the event log now tells the story instead of making you reconstruct it.
- Per-WAN bandwidth limits are enforced on real traffic — honest ceilings per interface, so a saturated backup link can’t starve your voice.
- Config upload/download through the Device API with token auth — fleet configuration management you can actually script.
- Customizable SNMP trap alerts, GPS over SNMP, WAN names in the port details and API, and on the big Balance chassis the dedicated management port is finally configurable in LAN Port Settings.
- And one fix I’ll call out by name: applying changes could, in rare cases, revert a device to factory defaults. Fixed. That’s worth the upgrade window on its own.
Before you touch the upgrade button
- Mind the stepping stone. BR1 Pro (CAT-20), BR1 Pro 5G, BR2 Pro, and all Dome, Transit, and B One models must be on 8.5.4 before 8.6.0. Two hops, not one.
- FIPS shops: IPsec preshared keys must now be at least 14 characters. Rotate short keys before they stop connecting.
- Audit your certificates. Weak ones get replaced by a secure default automatically — better you replace them deliberately.
- RemoteSIM/FusionSIM users: bring the SIM Injector to firmware 1.2.6.
- Check the retirement list. 8.6 drops support for a set of veterans — older Balance One/210/310 units, several MAX HD2/HD4 and Transit generations, MediaFast 200. They keep getting 8.5.x maintenance, but the feature train has left. If your fleet includes them, that’s a planning signal, not an emergency.
My rollout pattern, unchanged for years: stage it on a lab unit, run it a week, then push fleet-wide through InControl in maintenance windows. Firmware 8.6 has been through five betas and five release candidates — it’s had more public shaking-out than most point releases — but discipline is free and downtime isn’t.
The full breakdown
I went through all forty-two pages of release notes and categorized every single feature, improvement, and fix — by topic, in plain English, with links to the guides that teach each subject. That lives on Connectivity 101, the free education site we run:
What’s New in Peplink Firmware 8.6 — every change, categorized →
And if you’re sizing hardware to take advantage of any of this — Boost-ready bonding kits, dual-satellite designs, Multi-APN fleets — talk to us. This is the platform I bet the company on, and releases like 8.6 are why.