Release Date:
May 1, 2026
New Features and Enhancements:
Firmware version 3.0.0.105 is the first firmware release for the PR460X to integrate SASE (Secure Access Service Edge) security capabilities powered by the Exium cloud platform. Enabling SASE security on the router provisions two categories of features: capabilities that run directly on the router, and capabilities that become accessible via the Exium cloud portal.
Note: Enabling SASE security activates multiple security services on the router, including features such as Intrusion Detection (IDS), Web Filtering, and SD-WAN. As a result, increased CPU and memory utilization is expected compared to operation with SASE disabled. Network throughput might also be reduced depending on traffic volume and enabled security services. This is expected behavior when security services are active.
On-Device Security Features:
The following security modules are embedded in the firmware and run directly on the PR460X router. They are automatically activated when SASE security is enabled from the Insight portal.
·
IDS
— Intrusion Detection System:
IDS monitors network traffic
for potential threats and suspicious activity, generating alerts for further
investigation. This includes
traffic between the LAN and WAN (inbound and outbound), as well as inter-VLAN
traffic routed through the router.
Note: Traffic within the same subnet (switched locally) is not
inspected.
Detection rule sets are managed and
updated automatically by the Exium cloud:
o
Real-time
inspection of LAN-to-WAN, WAN-to-LAN, and inter-VLAN traffic routed through the
router.
o
Threat
detection rule sets are configurable from Exium
cloud.
o
IDS
Dashboard with alerts and events on Exium security
portal.
o
This
feature is enabled when SASE security is activated on the device.
·
Web
Filtering:
Domain and URL filtering is a cornerstone
of web and SaaS security. By implementing comprehensive Web filtering policies
and controls, organizations can mitigate risks, protect sensitive data, ensure
regulatory compliance, and promote a security-conscious culture. In an evolving
threat landscape, robust Web filtering is essential for safeguarding digital
assets and maintaining a resilient security posture.
DNS-based web filtering is built into firmware. When SASE security is
enabled, the web filtering engine intercepts all DNS queries from connected
clients, blocking access to domains that match configured filter lists. No
configuration is required on individual client devices.
o
DNS-level
filtering is applied to all clients connected to the router.
o
Blocks
access to malicious domains, phishing sites, and
configured content categories.
o
Filter
lists are managed and updated automatically via the Exium
portal.
o
When
a client accesses a blocked domain, an Exium-branded
(or optionally administrator defined) block page is displayed.
·
SD-WAN
— Software-Defined WAN:
SD-WAN establishes encrypted site-to-site
Secured mesh tunnels between multiple PR460X routers across different sites,
enabling policy-driven traffic steering across WAN links for improved
connectivity resilience and performance in multi-site deployments.
o
Encrypted
site-to-site SD-WAN tunnels between PR460X deployed sites.
o
Traffic
steering across multiple WAN interfaces with Dual WAN failover support.
o
Conflict
detection and validation between SD-WAN and IPSec site-to-site VPN tunnels.
Exium
Cloud Security Portal Features:
The following features are accessible via
the Exium cloud portal when SASE security is enabled
on the PR460X. These features are not embedded in the firmware but are part of
the overall SASE security solution delivered with this release.
·
ZTNA
— Zero Trust Network Access:
Zero Trust Network Access provides
identity-based, per-device access control for users connecting to network
resources. Users install the Exium agent on their
device to authenticate — protected resources access is controlled based on
device identity and verification using the Exium
agent.
o
Supported
on Windows, macOS, Android, and iOS client devices.
o
Access
policies are configured and enforced via the Exium
cloud portal.
·
Admin
console
o
View
Web and SaaS Dashboards, blocked threats, and status of devices.
o
Onboard
users and devices.
o
Configure
Zero Trust policies.
o
View
connectivity status for users, gateways, and devices.
Insight Cloud
Management Integration:
SASE security can be enabled and monitored
via the NETGEAR Insight cloud portal. Administrators can manage SASE directly
from Insight
·
Enable
or disable SASE security for the device from the Insight web portal.
·
Onboard
the PR460X to Insight and activate SASE security in a single flow.
·
The
current SASE security status (On/Off) is displayed on the
router local GUI Dashboard as a read-only indicator. SASE security can
only be enabled or disabled via the Insight portal.
To configure
SASE on a PR460X Pro Router using Insight:
Security
Fixes:
This firmware
addresses security vulnerabilities. For more information about security
vulnerabilities, visit https://www.netgear.com/about/security.
Bug Fixes:
This firmware
addresses the following customer-reported issues:
Known
Issues:
This firmware contains the following known
issues:
·
Clients
may lose internet connectivity after a router reboot with SASE security
enabled. When this occurs, the router internet LED shows amber and DNS
resolution fails for all connected clients, while direct IP address
connectivity remains functional. This issue has been observed in rare cases.
Workaround: Restart the router to restore
internet connectivity.
·
After
downgrading from firmware version 3.0.0.x to a previous firmware version
(2.7.x) and then upgrading back to 3.0.0.105, SASE security may show as Enabled
in the Insight portal but the Exium
Cyber Gateway (CGW) remains Disconnected. In this state, SASE security features
are not active despite the UI indicating otherwise.
Workaround: Toggle security for the router to sync the
security status. In Insight, navigate to the router, disable security under
router settings, wait a few moments, and then re-enable it. If the issue
persists, contact NETGEAR support.
·
After
moving a device between different organizations, a temporary mismatch may occur
where the Insight portal shows security as enabled, while the Exium Cloud portal displays the device as disconnected.
Workaround: Before moving a device between
organizations, disable security for the router and delete the device from the
current organization. Then proceed with adding it to the new organization. If
the issue persists, contact NETGEAR support.
·
In a
Dual WAN configuration, after the primary WAN interface goes down, the SD-WAN
tunnel may show as established but no traffic passes through. This may occur
when failing over to a DHCP-based WAN interface, where the tunnel handshake
does not fully complete.
·
SNMP
traps are not received when SASE security is enabled. SNMP polling operations
(GET, GET subtree, WALK) continue to work correctly.
Workaround: Configure your network monitoring system
to use SNMP polling (GET/WALK) instead of traps to monitor the router while
SASE is enabled. SNMP polling functions correctly when SASE is active.
·
Web
filtering is not functioning when a client browser has Secure DNS
(DNS-over-HTTPS / DoH) enabled. Clients using
browser-level DoH can bypass the router's web
filtering policies.
Workaround: Disable Secure DNS / DNS-over-HTTPS in the
client browser settings to ensure web filtering operates correctly. When a
browser uses its own encrypted DNS, DNS queries bypass the router's filtering
engine.
·
The
Intrusion Detection System (IDS) does not generate alerts when the LAN is
configured using public IP address space. This behavior indicates a limitation
in how traffic is classified and processed under this configuration, which can
affect alert generation. WAN-to-LAN IDS inspection may not work properly if the
WAN-side client uses a private IP subnet.
Workaround: Configure the LAN side to use private IP
address ranges to ensure traffic is properly inspected by the IDS and alerts
are generated as expected. If the issue persists, contact NETGEAR support.
·
IPSec
Tunnel Not Created in Insight When Subnet Overlaps with SD-WAN: When
configuring an IPSec Site-to-Site tunnel from the NETGEAR Insight portal, if
the specified IPSec subnet overlaps with any VLAN subnet used by routers in the
same SD-WAN location, the configuration is rejected by the router firmware.
However, the Insight portal does not display an error
or warning. The configuration appears to be accepted
successfully, but the IPSec tunnel is not created. When configuring the same
tunnel via the router’s local GUI, the subnet conflict is correctly detected and an error message is displayed.
Workaround: Before creating an IPSec Site-to-Site
tunnel in Insight, ensure that the IPSec subnet does not overlap with any VLAN
subnets across all routers in the same SD-WAN location.
The following issues were present in the
previous firmware release and remain unresolved in this release:
·
The
Insight portal does not support configuring Dual WAN Load Balancing. This
feature is not available in the Insight device configuration for Dual WAN mode.
Workaround: Configure Dual WAN Load Balancing directly
in the router local GUI.
·
A WireGuard VPN client configured in full tunnel mode cannot
access its local network because all traffic is directed through the VPN
tunnel.
Workaround: Uncheck the 'Block untunneled
traffic' option in the WireGuard client software, or temporarily disable the WireGuard
VPN tunnel to access the local network.
·
In a
Dual WAN configuration, an IPSec site-to-site tunnel may show the status as
'UP' on the secondary WAN interface while the primary WAN interface is active.
Workaround: The IPSec tunnel operates correctly on the
active WAN interface. The tunnel on the secondary interface acts as a standby
backup and activates automatically on WAN failover.
·
The
router allows configuring the OpenVPN IP address range for VPN clients in the
same subnet as the LAN or WAN interfaces. This causes routing conflicts and
loss of connectivity.
Workaround: Configure the OpenVPN IP address range for
VPN clients in a subnet that does not overlap with any configured LAN or WAN
subnets.
·
VPN
clients connected over Client-to-Site VPN cannot access the internet if the
site-to-site remote IP address range overlaps with the IP address range
configured for VPN clients.
Workaround: Ensure the site-to-site remote IP address
range does not conflict with the IP address range configured for Client-to-Site
VPN clients.
·
With
more than one VLAN configured, the IP address of a connected client is not
updated after the router LAN IP address is changed.
Workaround: Disconnect and reconnect the LAN port
network cable to obtain the updated IP address.
·
The
timestamp of a syslog entry does not adjust according to the configured local
time zone. Syslog entries are recorded in UTC.
Workaround: Interpret syslog event timestamps
according to the system time displayed in the router
local GUI.
Download link: https://www.downloads.netgear.com/files/GDC/PR460X/PR460X-V3.0.0.105.zip
Firmware Update Instructions
To update your product's firmware, follow the instructions in your product's user manual. To find your user manual, visit https://www.netgear.com/support/, enter your model number in the search box, and click the Documentation button on the product page.
The following sections also describe how you can update the firmware.
Manually
Update Firmware after Initial Setup
1. Download the latest PR460X firmware version 3.0.0.105 file from the NETGEAR support site (https://www.netgear.com/support/).
2. Launch a web browser from a computer that is connected to a PR460X LAN port.
3. Enter the IP address that is assigned to the Router.
If your computer is directly connected to the LAN port, enter https://www.routerlogin.net. Otherwise, enter https://<IP-address-of-router>.
Note: If the IP address of the router is its 192.168.1.1 default address, enter https://192.168.1.1.
If your browser displays a security warning, you can proceed, or add an exception for the security warning. For more information, see https://kb.netgear.com/000062980.
4. Enter the router username and password. The username is admin. The password is the one that you specified when you set up the router. The username and password are case-sensitive. If you did not yet specify a custom password, the default password is password (also stated on the router label).
5. Click the LOGIN button. The Dashboard page displays.
6. Select Administration > Firmware Update.
7. In the Firmware Update section, click the Browse button, navigate to the firmware file (the file name ends in .bin), and select the firmware file.
8. Click the Update button. A Firmware update confirmation pop-up window displays.
9. Click the Update button. The page displays the update progress. The update takes about 90 seconds.
WARNING: To avoid the risk of corrupting the firmware, do not interrupt the update. For example, do not close the browser, click a link, or load a new page. Do not turn off the router. Wait until the router finishes.
10. When the update is finished, log back into the router. The firmware version displays on the Dashboard page.
Let the Router Automatically Update the Firmware During
Initial Setup
1. Launch a web browser from a computer that is connected to a PR460X LAN port.
2. Enter the IP address that is assigned to the router. If the client is directly connected to the router's LAN network, enter https://www.routerlogin.net. Otherwise, enter https://<IP-address-of-Router>.
Note: If the IP address of the router is its 192.168.1.1 default address, enter https://192.168.1.1.
If your browser displays a security warning, you can proceed, or add an exception for the security warning. For more information, see https://kb.netgear.com/000062980
3. Enter password as the router login password (also stated on the router label) and click the LOGIN button. The password is case-sensitive. The Welcome page displays.
4. Click the Next button.
5. On the Terms of Services page, click the I Agree button.
6. On the Internet Detected page, click the Next button.
7. On the Admin Account Settings page, set a new router login password, and click the Next button.
8. On the Time Zone page, select your time zone, and click the Next button.
9. If the New Firmware Detected page displays, click the Next button. A pop-up window displays.
10. In the pop-up window, click the Update button.
11. Wait for the upgrade to complete.
12. In the Firmware update complete pop-up window, click the OK button.
13. When the update is finished, log back into the router. The firmware version displays on the Dashboard page.
Let the
Router Automatically Update the Firmware When the Router Detects a New Version
1. Launch a web browser from a computer that is connected to a PR460X LAN port.
2. Enter the IP address that is assigned to the router. If your computer is directly connected to the LAN port, enter https://www.routerlogin.net. Otherwise, enter https://<IP-address-of-router>.
Note: If the IP address of the router is its 192.168.1.1 default address, enter https://192.168.1.1.
If your browser displays a security warning, you can proceed, or add an exception for the security warning. For more information, see https://kb.netgear.com/000062980
3. Enter the router username and password. The username is admin. The password is the one that you specified when you set up the router. The username and password are case-sensitive. If you did not yet specify a custom password, the default password is password (also stated on the router label).
4. Click the LOGIN button. The Dashboard page displays.
5. In the System Information pane, click the Update Now button. A Firmware update confirmation pop-up window displays.
6. Click the Update button. The router locates and downloads the firmware and begins the update. The page displays the update progress. The update takes about 90 seconds.
WARNING: To avoid the risk of corrupting the firmware, do not interrupt the update. For example, do not close the browser, click a link, or load a new page. Do not turn off the router. Wait until the router finishes the update and subsequent reboot process.
7. When the update is finished, log back into the router. The firmware version is displayed on the Dashboard view.