Release Date:
May 1, 2026
New Features and Enhancements:
Firmware version 3.0.0.105 is the first firmware release for the PR60X to integrate SASE (Secure Access Service Edge) security capabilities powered by the Exium cloud platform. Enabling SASE security on the router provisions two categories of features: capabilities that run directly on the router, and capabilities that become accessible via the Exium cloud portal.
Note: Enabling SASE security activates multiple security services on the router, including features such as Intrusion Detection (IDS), Web Filtering, and SD-WAN. As a result, increased CPU and memory utilization is expected compared to operation with SASE disabled. Network throughput might also be reduced depending on traffic volume and enabled security services. This is expected behavior when security services are active.
On-Device Security Features:
The following security modules are embedded in the firmware and run directly on the PR60X router. They are automatically activated when SASE security is enabled from the Insight portal.
·
IDS
— Intrusion Detection System:
IDS monitors network
traffic for potential threats and suspicious activity, generating alerts for
further investigation.
This includes traffic between the LAN and WAN (inbound and outbound), as well
as inter-VLAN traffic routed through the router.
Note: Traffic within the same subnet (switched locally) is not inspected.
Detection rule sets are managed and
updated automatically by the Exium cloud:
o
Real-time
inspection of LAN-to-WAN, WAN-to-LAN, and inter-VLAN traffic routed through the
router.
o
Threat
detection rule sets are configurable from Exium
cloud.
o
IDS
Dashboard with alerts and events on Exium security
portal.
o
This
feature is enabled when SASE security is activated on the device.
·
Web
Filtering:
Domain and URL filtering is a
cornerstone of web and SaaS security. By implementing comprehensive Web
filtering policies and controls, organizations can mitigate risks, protect
sensitive data, ensure regulatory compliance, and promote a security-conscious
culture. In an evolving threat landscape, robust Web filtering is essential for
safeguarding digital assets and maintaining a resilient security posture.
DNS-based web filtering is built into firmware. When SASE
security is enabled, the web filtering engine intercepts all DNS queries from
connected clients, blocking access to domains that match configured filter
lists. No configuration is required on individual client devices.
o
DNS-level
filtering is applied to all clients connected to the router.
o
Blocks
access to malicious domains, phishing sites, and
configured content categories.
o
Filter
lists are managed and updated automatically via the Exium
portal.
o
When
a client accesses a blocked domain, an Exium-branded
(or optionally administrator defined) block page is displayed.
·
SD-WAN
— Software-Defined WAN:
SD-WAN establishes encrypted
site-to-site Secured mesh tunnels between multiple PR60X routers across
different sites, enabling policy-driven traffic steering across WAN links for
improved connectivity resilience and performance in multi-site deployments.
o
Encrypted
site-to-site SD-WAN tunnels between PR60x deployed sites.
o
Traffic
steering across multiple WAN interfaces with Dual WAN failover support.
o
Conflict
detection and validation between SD-WAN and IPSec site-to-site VPN tunnels.
Exium Cloud Security Portal Features:
The following features are accessible
via the Exium cloud portal when SASE security is
enabled on the PR60X. These features are not embedded in the firmware but are
part of the overall SASE security solution delivered with this release.
·
ZTNA
— Zero Trust Network Access:
Zero Trust Network Access provides
identity-based, per-device access control for users connecting to network
resources. Users install the Exium agent on their
device to authenticate — protected resources access is controlled based on
device identity and verification using the Exium
agent.
o
Supported
on Windows, macOS, Android, and iOS client devices.
o
Access
policies are configured and enforced via the Exium
cloud portal.
·
Admin
console
o
View
Web and SaaS Dashboards, blocked threats, and status of devices.
o
Onboard
users and devices.
o
Configure
Zero Trust policies.
o
View
connectivity status for users, gateways, and devices.
Insight
Cloud Management Integration:
SASE security can be enabled and
monitored via the NETGEAR Insight cloud portal. Administrators can manage SASE
directly from Insight
·
Enable
or disable SASE security for the device from the Insight web portal.
·
Onboard
the PR60X to Insight and activate SASE security in a single flow.
·
The
current SASE security status (On/Off) is displayed on the
router local GUI Dashboard as a read-only indicator. SASE security can
only be enabled or disabled via the Insight portal.
To configure
SASE on a PR60X Pro Router using Insight:
Security
Fixes:
This
firmware addresses security vulnerabilities. For more information about
security vulnerabilities, visit https://www.netgear.com/about/security.
Bug
Fixes:
This
firmware addresses the following customer-reported issues:
Known Issues:
This firmware contains the following
known issues:
·
Clients
may lose internet connectivity after a router reboot with SASE security
enabled. When this occurs, the router internet LED shows amber and DNS
resolution fails for all connected clients, while direct IP address
connectivity remains functional. This issue has been observed in rare cases.
Workaround: Restart
the router to restore internet connectivity.
·
After
downgrading from firmware version 3.0.0.x to a previous firmware version
(2.7.x) and then upgrading back to 3.0.0.105, SASE security may show as Enabled
in the Insight portal but the Exium
Cyber Gateway (CGW) remains Disconnected. In this state, SASE security features
are not active despite the UI indicating otherwise.
Workaround: Toggle security for the router to sync
the security status. In Insight, navigate to the router, disable security under
router settings, wait a few moments, and then re-enable it. If the issue
persists, contact NETGEAR support.
·
After
moving a device between different organizations, a temporary mismatch may occur
where the Insight portal shows security as enabled, while the Exium Cloud portal displays the device as disconnected.
Workaround: Before moving a device between
organizations, disable security for the router and delete the device from the
current organization. Then proceed with adding it to the new organization. If
the issue persists, contact NETGEAR support.
·
In
a Dual WAN configuration, after the primary WAN interface goes down, the SD-WAN
tunnel may show as established but no traffic passes through. This may occur
when failing over to a DHCP-based WAN interface, where the tunnel handshake
does not fully complete.
·
SNMP
traps are not received when SASE security is enabled. SNMP polling operations
(GET, GET subtree, WALK) continue to work correctly.
Workaround: Configure your network monitoring
system to use SNMP polling (GET/WALK) instead of traps to monitor the router
while SASE is enabled. SNMP polling functions correctly when SASE is active.
·
Web
filtering is not functioning when a client browser has Secure DNS
(DNS-over-HTTPS / DoH) enabled. Clients using
browser-level DoH can bypass the router's web
filtering policies.
Workaround: Disable Secure DNS / DNS-over-HTTPS in
the client browser settings to ensure web filtering operates correctly. When a
browser uses its own encrypted DNS, DNS queries bypass the router's filtering
engine.
·
The
Intrusion Detection System (IDS) does not generate alerts when the LAN is
configured using public IP address space. This behavior indicates a limitation
in how traffic is classified and processed under this configuration, which can
affect alert generation. WAN-to-LAN IDS inspection may not work properly if the
WAN-side client uses a private IP subnet.
Workaround: Configure the LAN side to use private
IP address ranges to ensure traffic is properly inspected by the IDS and alerts
are generated as expected. If the issue persists, contact NETGEAR support.
·
IPSec
Tunnel Not Created in Insight When Subnet Overlaps with SD-WAN: When
configuring an IPSec Site-to-Site tunnel from the NETGEAR Insight portal, if
the specified IPSec subnet overlaps with any VLAN subnet used by routers in the
same SD-WAN location, the configuration is rejected by the router firmware.
However, the Insight portal does not display an error
or warning. The configuration appears to be accepted
successfully, but the IPSec tunnel is not created. When configuring the same
tunnel via the router’s local GUI, the subnet conflict is correctly detected and an error message is displayed.
Workaround: Before creating an IPSec Site-to-Site
tunnel in Insight, ensure that the IPSec subnet does not overlap with any VLAN
subnets across all routers in the same SD-WAN location.
The following issues were present in
the previous firmware release and remain unresolved in this release:
·
The
Insight portal does not support configuring Dual WAN Load Balancing. This
feature is not available in the Insight device configuration for Dual WAN mode.
Workaround: Configure Dual WAN Load Balancing
directly in the router local GUI.
·
A
WireGuard VPN client configured in full tunnel mode
cannot access its local network because all traffic is directed through the VPN
tunnel.
Workaround: Uncheck the 'Block untunneled
traffic' option in the WireGuard client software, or temporarily disable the WireGuard
VPN tunnel to access the local network.
·
In
a Dual WAN configuration, an IPSec site-to-site tunnel may show the status as
'UP' on the secondary WAN interface while the primary WAN interface is active.
Workaround: The IPSec tunnel operates correctly on
the active WAN interface. The tunnel on the secondary interface acts as a
standby backup and activates automatically on WAN failover.
·
The
router allows configuring the OpenVPN IP address range for VPN clients in the
same subnet as the LAN or WAN interfaces. This causes routing conflicts and
loss of connectivity.
Workaround: Configure the OpenVPN IP address range
for VPN clients in a subnet that does not overlap with any configured LAN or
WAN subnets.
·
VPN
clients connected over Client-to-Site VPN cannot access the internet if the
site-to-site remote IP address range overlaps with the IP address range
configured for VPN clients.
Workaround: Ensure the site-to-site remote IP
address range does not conflict with the IP address range configured for
Client-to-Site VPN clients.
·
With
more than one VLAN configured, the IP address of a connected client is not
updated after the router LAN IP address is changed.
Workaround: Disconnect and reconnect the LAN port
network cable to obtain the updated IP address.
·
The
timestamp of a syslog entry does not adjust according to the configured local
time zone. Syslog entries are recorded in UTC.
Workaround: Interpret syslog event timestamps
according to the system time displayed in the router
local GUI.
Download
link: https://www.downloads.netgear.com/files/GDC/PR60X/PR60X-V3.0.0.105.zip
Firmware Update Instructions
To update your product's firmware, follow the instructions
in your product's user manual. To find your user manual, visit https://www.netgear.com/support/, enter
your model number in the search box, and click the Documentation button
on the product page.
The following sections also describe how you can update the
firmware.
Manually
Update Firmware after Initial Setup
1.
Download the latest PR60X firmware version
3.0.0.105 file from the NETGEAR support site (https://www.netgear.com/support/).
2.
Launch a web browser from a computer that is
connected to a PR60X LAN port.
3.
Enter the IP address that is assigned to the Router.
If your computer
is directly connected to the LAN port, enter https://www.routerlogin.net.
Otherwise, enter https://<IP-address-of-router>.
Note: If
the IP address of the router is its 192.168.1.1 default address, enter https://192.168.1.1.
If your browser
displays a security warning, you can proceed, or add
an exception for the security warning. For more information, see https://kb.netgear.com/000062980.
4.
Enter the router username and password. The
username is admin. The password is the one that you specified when you
set up the router. The username and password are case-sensitive. If you did not
yet specify a custom password, the default password is password (also
stated on the router label).
5.
Click the LOGIN button. The Dashboard
page displays.
6.
Select Administration > Firmware
Update.
7.
In the Firmware Update section, click the Browse
button, navigate to the firmware file (the file name ends in .bin), and select
the firmware file.
8.
Click the Update button. A Firmware
update confirmation pop-up window displays.
9.
Click the Update button. The page
displays the update progress. The update takes about 90 seconds.
WARNING:
To avoid the risk of corrupting the firmware, do not interrupt the update. For
example, do not close the browser, click a link, or load a new page. Do not
turn off the router. Wait until the router finishes.
10. When
the update is finished, log back into the router. The firmware version displays
on the Dashboard page.
Let the Router Automatically Update the Firmware During
Initial Setup
1.
Launch a web browser from a computer that is
connected to a PR60X LAN port.
2.
Enter the IP address that is assigned to the
router. If the client is directly connected to the router's LAN network, enter https://www.routerlogin.net.
Otherwise, enter https://<IP-address-of-Router>.
Note: If
the IP address of the router is its 192.168.1.1 default address, enter https://192.168.1.1.
If your browser
displays a security warning, you can proceed, or add
an exception for the security warning. For more information, see https://kb.netgear.com/000062980
3.
Enter password as the router login password
(also stated on the router label) and click the LOGIN button. The
password is case-sensitive. The Welcome page displays.
4.
Click the Next button.
5.
On the Terms of Services page, click the I
Agree button.
6.
On the Internet Detected page, click the Next
button.
7.
On the Admin Account Settings page, set a new
router login password, and click the Next button.
8.
On the Time Zone page, select your time zone,
and click the Next button.
9.
If the New Firmware Detected page displays,
click the Next button. A pop-up window displays.
10. In
the pop-up window, click the Update button.
11. Wait
for the upgrade to complete.
12. In
the Firmware update complete pop-up window, click the OK button.
13. When
the update is finished, log back into the router. The firmware version displays
on the Dashboard page.
Let the
Router Automatically Update the Firmware When the Router Detects a New Version
1.
Launch a web browser from a computer that is
connected to a PR60X LAN port.
2.
Enter the IP address that is assigned to the
router. If your computer is directly connected to the LAN port, enter https://www.routerlogin.net.
Otherwise, enter https://<IP-address-of-router>.
Note: If
the IP address of the router is its 192.168.1.1 default address, enter https://192.168.1.1.
If your browser
displays a security warning, you can proceed, or add
an exception for the security warning. For more information, see https://kb.netgear.com/000062980
3.
Enter the router username and password. The
username is admin. The password is the one that you specified when you
set up the router. The username and password are case-sensitive. If you did not
yet specify a custom password, the default password is password (also
stated on the router label).
4.
Click the LOGIN button. The Dashboard
page displays.
5.
In the System Information pane, click the Update
Now button. A Firmware update confirmation pop-up window displays.
6.
Click the Update button. The router
locates and downloads the firmware and begins the update. The page displays the
update progress. The update takes about 90 seconds.
WARNING:
To avoid the risk of corrupting the firmware, do not interrupt the update. For
example, do not close the browser, click a link, or load a new page. Do not
turn off the router. Wait until the router finishes the update and subsequent
reboot process.
7. When the update is finished, log back into the router. The firmware version is displayed on the Dashboard view.