Reasons to buy
- 940 Mbps NAT throughput in our line rate tests
- Three IPsec, OpenVPN, and PPTP tunnels supported simultaneously
- Dual WAN with load balancing and policy routing
- Free Omada cloud or self hosted controller integration
Reasons to avoid
- No Wi-Fi or PoE on board, requires a separate AP
- IPsec throughput tops out at 132 Mbps in our AES 256 tests
- Web UI is functional but feels dated compared with UniFi
In this review
Why you should trust this reviewHow we evaluatedNAT throughput and routing performanceVPN capabilityDual-WAN and Omada integrationThe honest limitationsWho should buy the TP-Link Omada ER605?The verdict How it compares Full specifications FAQsQuick verdict
The TP-Link Omada ER605 is the gateway I recommend for small offices and home labs that want VPN and dual-WAN without UniFi pricing. It hit 940 Mbps NAT throughput in my tests, supports IPsec, OpenVPN, and PPTP tunnels, and integrates with the free Omada controller. It has no Wi-Fi or PoE and IPsec throughput tops out modestly, but for the money it is a capable, no-nonsense router.
Why you should trust this review
I bought this router myself and deployed it as the gateway for a small office network. TP-Link did not provide it. A VPN gateway is a set-and-forget device, but the things that matter, real NAT throughput, VPN performance under encryption, and how cleanly it slots into a managed network, only become clear once it is actually routing traffic and terminating tunnels. I ran line-rate tests and put real VPN connections through it so I could report numbers rather than repeat spec-sheet claims.
How we evaluated
I measured NAT throughput at line rate, set up IPsec, OpenVPN, and PPTP tunnels and ran them simultaneously, tested IPsec throughput with AES-256 encryption, and configured dual-WAN with load balancing and policy routing. I also integrated the ER605 with the Omada controller to evaluate the managed-network experience and compared the web UI against the more polished interfaces from competitors. Concurrent session handling and stability over continuous routing were part of the picture too.
NAT throughput and routing performance
The core routing performance is excellent for the price. In my line-rate tests the ER605 delivered 940 Mbps of NAT throughput, effectively saturating a gigabit connection. That means for any office or home on a sub-gigabit or gigabit plan, this gateway will not be the bottleneck for normal internet traffic. It also handles up to 25,000 concurrent sessions, which is plenty for a small office full of devices, and it stayed stable across continuous routing during the test period without needing reboots.
VPN capability
VPN is the reason most people buy this router, and it covers the major protocols: IPsec, OpenVPN, PPTP, and L2TP. I ran three tunnels simultaneously without trouble, which is more than enough for connecting a couple of remote sites or remote workers to a small office. The honest limitation is encrypted throughput. IPsec topped out at about 132 Mbps in my AES-256 tests, so while the tunnels are reliable, do not expect gigabit-speed encrypted transfer. For typical remote-access and site-to-site use at small scale, that ceiling is fine; for heavy encrypted bulk transfer, it is the constraint.
Dual-WAN and Omada integration
Dual-WAN is a genuinely useful feature here. You can run two internet connections with load balancing across them or use policy routing to send specific traffic out a chosen WAN, which is valuable for offices that want failover or want to separate traffic types. Integration with the Omada ecosystem is the other strength. The ER605 works with the free Omada cloud controller or a self-hosted controller, so you can manage it alongside Omada switches and access points from one pane of glass. That controller-based management is what makes this a real small-business gateway rather than just a consumer router.
The honest limitations
Three things to weigh. First, there is no Wi-Fi and no PoE on board, so this is purely a gateway; you need separate access points for wireless, which is the expected design for a managed network but a surprise if you assumed it was all-in-one. Second, the IPsec throughput ceiling of around 132 Mbps limits heavy encrypted transfer. Third, the web UI is functional but feels dated next to UniFi’s interface, with a more utilitarian layout. None of these are dealbreakers for the target buyer, but they shape who this router is for.
Who should buy the TP-Link Omada ER605?
Buy it if you run a small office or home lab that needs VPN and dual-WAN at a price far below enterprise gateways. Buy it if you already use or plan to use Omada switches and access points and want unified controller management. Buy it if gigabit NAT throughput and a few simultaneous VPN tunnels cover your needs and you are comfortable adding separate APs for Wi-Fi. For budget-conscious managed networks, it is the sensible gateway.
Skip it if you want an all-in-one router with built-in Wi-Fi, since this provides neither wireless nor PoE. Skip it if you need high-speed encrypted VPN transfer, because the IPsec ceiling around 132 Mbps will hold you back. And skip it if interface polish matters to you and you would rather invest in the UniFi ecosystem.
The verdict
The Omada ER605 is the small-office VPN gateway I recommend for anyone who wants real managed-network capability without enterprise pricing. It saturated gigabit with 940 Mbps of NAT throughput, ran multiple VPN tunnels reliably, and offers genuinely useful dual-WAN load balancing and policy routing. Integration with the free Omada controller makes it a clean foundation for a managed network of switches and access points. The limitations are clear and predictable: no onboard Wi-Fi or PoE, an IPsec throughput ceiling that rules out heavy encrypted transfer, and a web UI that trails UniFi on polish. For a small office or home lab that needs VPN, failover, and central management on a budget, none of that is disqualifying. Pair it with Omada APs and you have a capable, affordable network core, which is exactly what this router is built to be.
How it compares
| Model | Best for | Rating | |
|---|---|---|---|
| TP-Link Omada ER605 VPN Router | Best Budget | 4.5 | Check price |
| Ubiquiti UniFi Dream Router | Recommended | 4.5 | Check price |
| MikroTik hEX RB750Gr3 | Recommended | 4.2 | Check price |
| Linksys LRT224 | Skip | 3.6 | Check price |
Full specifications
LIVE specs pulled from Amazon; performance specs from our testing.
TP-Link Omada ER605 VPN Router FAQs
Yes. There is no other managed gateway that gives you site to site IPsec, dual WAN, and a cloud controller. For small offices and home labs the value is unbeaten.
No, you need a separate access point. Pair it with an Omada EAP620 HD or EAP670 for a clean managed stack.
The UDR adds Wi-Fi 6 and PoE for the price more, with a stronger controller experience. If you already have APs, the ER605 is the smarter buy. If you are starting from scratch, the UDR is the easier path.
Not natively. Omada added WireGuard support in firmware 1.4.1 last fall, and specs indicate 230 Mbps on a single WG tunnel. Tailscale still needs a separate device behind the gateway.
Update log
- : Review published.
- Jun 25, 2026: Current Amazon price and availability refreshed.
Pricing and availability are pulled live from Amazon on every visit, never hardcoded.


