Release Date:

May 1, 2026

 

New Features and Enhancements:

 

Firmware version 3.0.0.105 is the first firmware release for the PR460X to integrate SASE (Secure Access Service Edge) security capabilities powered by the Exium cloud platform. Enabling SASE security on the router provisions two categories of features: capabilities that run directly on the router, and capabilities that become accessible via the Exium cloud portal.

 

Note: Enabling SASE security activates multiple security services on the router, including features such as Intrusion Detection (IDS), Web Filtering, and SD-WAN. As a result, increased CPU and memory utilization is expected compared to operation with SASE disabled. Network throughput might also be reduced depending on traffic volume and enabled security services. This is expected behavior when security services are active.

 

On-Device Security Features:

The following security modules are embedded in the firmware and run directly on the PR460X router. They are automatically activated when SASE security is enabled from the Insight portal.

 

·         IDS — Intrusion Detection System:

IDS monitors network traffic for potential threats and suspicious activity, generating alerts for further investigation. This includes traffic between the LAN and WAN (inbound and outbound), as well as inter-VLAN traffic routed through the router.
Note: Traffic within the same subnet (switched locally) is not inspected.

Detection rule sets are managed and updated automatically by the Exium cloud:

o   Real-time inspection of LAN-to-WAN, WAN-to-LAN, and inter-VLAN traffic routed through the router.

o   Threat detection rule sets are configurable from Exium cloud.

o   IDS Dashboard with alerts and events on Exium security portal.

o   This feature is enabled when SASE security is activated on the device.

 

·         Web Filtering:

Domain and URL filtering is a cornerstone of web and SaaS security. By implementing comprehensive Web filtering policies and controls, organizations can mitigate risks, protect sensitive data, ensure regulatory compliance, and promote a security-conscious culture. In an evolving threat landscape, robust Web filtering is essential for safeguarding digital assets and maintaining a resilient security posture.

DNS-based web filtering is built into firmware. When SASE security is enabled, the web filtering engine intercepts all DNS queries from connected clients, blocking access to domains that match configured filter lists. No configuration is required on individual client devices.

o   DNS-level filtering is applied to all clients connected to the router.

o   Blocks access to malicious domains, phishing sites, and configured content categories.

o   Filter lists are managed and updated automatically via the Exium portal.

o   When a client accesses a blocked domain, an Exium-branded (or optionally administrator defined) block page is displayed.

 

·         SD-WAN — Software-Defined WAN:

SD-WAN establishes encrypted site-to-site Secured mesh tunnels between multiple PR460X routers across different sites, enabling policy-driven traffic steering across WAN links for improved connectivity resilience and performance in multi-site deployments.

o   Encrypted site-to-site SD-WAN tunnels between PR460X deployed sites.

o   Traffic steering across multiple WAN interfaces with Dual WAN failover support.

o   Conflict detection and validation between SD-WAN and IPSec site-to-site VPN tunnels.

 

Exium Cloud Security Portal Features:

The following features are accessible via the Exium cloud portal when SASE security is enabled on the PR460X. These features are not embedded in the firmware but are part of the overall SASE security solution delivered with this release.

·         ZTNA — Zero Trust Network Access:

Zero Trust Network Access provides identity-based, per-device access control for users connecting to network resources. Users install the Exium agent on their device to authenticate — protected resources access is controlled based on device identity and verification using the Exium agent.

o   Supported on Windows, macOS, Android, and iOS client devices.

o   Access policies are configured and enforced via the Exium cloud portal.

 

·         Admin console

o   View Web and SaaS Dashboards, blocked threats, and status of devices.

o   Onboard users and devices.

o   Configure Zero Trust policies.

o   View connectivity status for users, gateways, and devices.

 

Insight Cloud Management Integration:

SASE security can be enabled and monitored via the NETGEAR Insight cloud portal. Administrators can manage SASE directly from Insight

·         Enable or disable SASE security for the device from the Insight web portal.

·         Onboard the PR460X to Insight and activate SASE security in a single flow.

·         The current SASE security status (On/Off) is displayed on the router local GUI Dashboard as a read-only indicator. SASE security can only be enabled or disabled via the Insight portal.

 

To configure SASE on a PR460X Pro Router using Insight: 

  1. Log in to Insight and select the organization required.
  2. Go to Security Center and click Enable SASE Security. A 90-day trial period is enabled.
  3. Go to a Location containing a PR460X.
  4. Double-click on the PR460X.
  5. Click the Settings button.
  6. Go to the Security tab.
  7. Click the Enable SASE Security button.

 

Security Fixes:

This firmware addresses security vulnerabilities. For more information about security vulnerabilities, visit https://www.netgear.com/about/security.

Bug Fixes:

This firmware addresses the following customer-reported issues:

 

Known Issues:

This firmware contains the following known issues:

·         Clients may lose internet connectivity after a router reboot with SASE security enabled. When this occurs, the router internet LED shows amber and DNS resolution fails for all connected clients, while direct IP address connectivity remains functional. This issue has been observed in rare cases.

Workaround: Restart the router to restore internet connectivity.

·         After downgrading from firmware version 3.0.0.x to a previous firmware version (2.7.x) and then upgrading back to 3.0.0.105, SASE security may show as Enabled in the Insight portal but the Exium Cyber Gateway (CGW) remains Disconnected. In this state, SASE security features are not active despite the UI indicating otherwise.

Workaround: Toggle security for the router to sync the security status. In Insight, navigate to the router, disable security under router settings, wait a few moments, and then re-enable it. If the issue persists, contact NETGEAR support.

·         After moving a device between different organizations, a temporary mismatch may occur where the Insight portal shows security as enabled, while the Exium Cloud portal displays the device as disconnected.

Workaround: Before moving a device between organizations, disable security for the router and delete the device from the current organization. Then proceed with adding it to the new organization. If the issue persists, contact NETGEAR support.

·         In a Dual WAN configuration, after the primary WAN interface goes down, the SD-WAN tunnel may show as established but no traffic passes through. This may occur when failing over to a DHCP-based WAN interface, where the tunnel handshake does not fully complete.

·         SNMP traps are not received when SASE security is enabled. SNMP polling operations (GET, GET subtree, WALK) continue to work correctly.

Workaround: Configure your network monitoring system to use SNMP polling (GET/WALK) instead of traps to monitor the router while SASE is enabled. SNMP polling functions correctly when SASE is active.

·         Web filtering is not functioning when a client browser has Secure DNS (DNS-over-HTTPS / DoH) enabled. Clients using browser-level DoH can bypass the router's web filtering policies.

Workaround: Disable Secure DNS / DNS-over-HTTPS in the client browser settings to ensure web filtering operates correctly. When a browser uses its own encrypted DNS, DNS queries bypass the router's filtering engine.

·         The Intrusion Detection System (IDS) does not generate alerts when the LAN is configured using public IP address space. This behavior indicates a limitation in how traffic is classified and processed under this configuration, which can affect alert generation. WAN-to-LAN IDS inspection may not work properly if the WAN-side client uses a private IP subnet.

Workaround: Configure the LAN side to use private IP address ranges to ensure traffic is properly inspected by the IDS and alerts are generated as expected. If the issue persists, contact NETGEAR support.

·         IPSec Tunnel Not Created in Insight When Subnet Overlaps with SD-WAN: When configuring an IPSec Site-to-Site tunnel from the NETGEAR Insight portal, if the specified IPSec subnet overlaps with any VLAN subnet used by routers in the same SD-WAN location, the configuration is rejected by the router firmware. However, the Insight portal does not display an error or warning. The configuration appears to be accepted successfully, but the IPSec tunnel is not created. When configuring the same tunnel via the router’s local GUI, the subnet conflict is correctly detected and an error message is displayed.

Workaround: Before creating an IPSec Site-to-Site tunnel in Insight, ensure that the IPSec subnet does not overlap with any VLAN subnets across all routers in the same SD-WAN location.

 

The following issues were present in the previous firmware release and remain unresolved in this release:

·         The Insight portal does not support configuring Dual WAN Load Balancing. This feature is not available in the Insight device configuration for Dual WAN mode.

Workaround: Configure Dual WAN Load Balancing directly in the router local GUI.

·         A WireGuard VPN client configured in full tunnel mode cannot access its local network because all traffic is directed through the VPN tunnel.

Workaround: Uncheck the 'Block untunneled traffic' option in the WireGuard client software, or temporarily disable the WireGuard VPN tunnel to access the local network.

·         In a Dual WAN configuration, an IPSec site-to-site tunnel may show the status as 'UP' on the secondary WAN interface while the primary WAN interface is active.

Workaround: The IPSec tunnel operates correctly on the active WAN interface. The tunnel on the secondary interface acts as a standby backup and activates automatically on WAN failover.

·         The router allows configuring the OpenVPN IP address range for VPN clients in the same subnet as the LAN or WAN interfaces. This causes routing conflicts and loss of connectivity.

Workaround: Configure the OpenVPN IP address range for VPN clients in a subnet that does not overlap with any configured LAN or WAN subnets.

·         VPN clients connected over Client-to-Site VPN cannot access the internet if the site-to-site remote IP address range overlaps with the IP address range configured for VPN clients.

Workaround: Ensure the site-to-site remote IP address range does not conflict with the IP address range configured for Client-to-Site VPN clients.

·         With more than one VLAN configured, the IP address of a connected client is not updated after the router LAN IP address is changed.

Workaround: Disconnect and reconnect the LAN port network cable to obtain the updated IP address.

·         The timestamp of a syslog entry does not adjust according to the configured local time zone. Syslog entries are recorded in UTC.

Workaround: Interpret syslog event timestamps according to the system time displayed in the router local GUI.

 

Download link: https://www.downloads.netgear.com/files/GDC/PR460X/PR460X-V3.0.0.105.zip

 

Firmware Update Instructions

To update your product's firmware, follow the instructions in your product's user manual. To find your user manual, visit https://www.netgear.com/support/, enter your model number in the search box, and click the Documentation button on the product page.

 

The following sections also describe how you can update the firmware.

 

Manually Update Firmware after Initial Setup

1.      Download the latest PR460X firmware version 3.0.0.105 file from the NETGEAR support site (https://www.netgear.com/support/).

2.      Launch a web browser from a computer that is connected to a PR460X LAN port.

3.      Enter the IP address that is assigned to the Router.

If your computer is directly connected to the LAN port, enter https://www.routerlogin.net. Otherwise, enter https://<IP-address-of-router>.

Note: If the IP address of the router is its 192.168.1.1 default address, enter https://192.168.1.1.

If your browser displays a security warning, you can proceed, or add an exception for the security warning. For more information, see https://kb.netgear.com/000062980.

4.      Enter the router username and password. The username is admin. The password is the one that you specified when you set up the router. The username and password are case-sensitive. If you did not yet specify a custom password, the default password is password (also stated on the router label).

5.      Click the LOGIN button. The Dashboard page displays.

6.      Select Administration > Firmware Update.

7.      In the Firmware Update section, click the Browse button, navigate to the firmware file (the file name ends in .bin), and select the firmware file.

8.      Click the Update button. A Firmware update confirmation pop-up window displays.

9.      Click the Update button. The page displays the update progress. The update takes about 90 seconds.

WARNING: To avoid the risk of corrupting the firmware, do not interrupt the update. For example, do not close the browser, click a link, or load a new page. Do not turn off the router. Wait until the router finishes.

10. When the update is finished, log back into the router. The firmware version displays on the Dashboard page.

 

Let the Router Automatically Update the Firmware During Initial Setup

1.      Launch a web browser from a computer that is connected to a PR460X LAN port.

2.      Enter the IP address that is assigned to the router. If the client is directly connected to the router's LAN network, enter https://www.routerlogin.net. Otherwise, enter https://<IP-address-of-Router>.

Note: If the IP address of the router is its 192.168.1.1 default address, enter https://192.168.1.1.

If your browser displays a security warning, you can proceed, or add an exception for the security warning. For more information, see https://kb.netgear.com/000062980

3.      Enter password as the router login password (also stated on the router label) and click the LOGIN button. The password is case-sensitive. The Welcome page displays.

4.      Click the Next button.

5.      On the Terms of Services page, click the I Agree button.

6.      On the Internet Detected page, click the Next button.

7.      On the Admin Account Settings page, set a new router login password, and click the Next button.

8.      On the Time Zone page, select your time zone, and click the Next button.

9.      If the New Firmware Detected page displays, click the Next button. A pop-up window displays.

10. In the pop-up window, click the Update button.

11. Wait for the upgrade to complete.

12. In the Firmware update complete pop-up window, click the OK button.

13. When the update is finished, log back into the router. The firmware version displays on the Dashboard page.

 

Let the Router Automatically Update the Firmware When the Router Detects a New Version

1.      Launch a web browser from a computer that is connected to a PR460X LAN port.

2.      Enter the IP address that is assigned to the router. If your computer is directly connected to the LAN port, enter https://www.routerlogin.net. Otherwise, enter https://<IP-address-of-router>.

Note: If the IP address of the router is its 192.168.1.1 default address, enter https://192.168.1.1.

If your browser displays a security warning, you can proceed, or add an exception for the security warning. For more information, see https://kb.netgear.com/000062980

3.      Enter the router username and password. The username is admin. The password is the one that you specified when you set up the router. The username and password are case-sensitive. If you did not yet specify a custom password, the default password is password (also stated on the router label).

4.      Click the LOGIN button. The Dashboard page displays.

5.      In the System Information pane, click the Update Now button. A Firmware update confirmation pop-up window displays.

6.      Click the Update button. The router locates and downloads the firmware and begins the update. The page displays the update progress. The update takes about 90 seconds.

WARNING: To avoid the risk of corrupting the firmware, do not interrupt the update. For example, do not close the browser, click a link, or load a new page. Do not turn off the router. Wait until the router finishes the update and subsequent reboot process.

7.      When the update is finished, log back into the router. The firmware version is displayed on the Dashboard view.