By default SignLogger runs passively: it collects, signs and stores the logs that firewalls, switches and wireless controllers on the network send to it. Router Mode (also called SignRouter inside the product) changes that role. When the mode is enabled, the SignLogger appliance becomes the network's gateway; traffic between the internal network and the internet flows directly through the device. As a result the Law 5651 record is no longer a second-hand log reported by another device — it is generated first-hand, from the traffic the device itself sees. From the same panel you manage zone-based security policy, NAT / port forwarding, DHCP / DNS, the guest captive portal and multiple internet links (SD-WAN) — with no separate firewall appliance or licence.
This page is for informational purposes; for setup steps see the Router Mode and Firewall Management User Guide.
Why is Router Mode needed?
In a classic deployment the Law 5651 log is a record that another device carrying the traffic (a firewall or router) reports to SignLogger. That model has two dependencies: the intermediate device must generate the log completely and forward it correctly. Router Mode removes that dependency:
- First-hand records: the log of passing traffic is generated directly from SignLogger's own data plane, without trusting an intermediate device; the audit question "why is a record missing?" goes away.
- One device, one licence: small and medium businesses and branch offices need no separate firewall appliance, licence or management panel; log management and the network gateway merge into one box.
- Readable policy: rules are written between logical zones (internal, guest, internet) rather than interfaces, so the policy stays understandable as it grows.
- Guest network on the device: the captive portal is enforced in the guest zone; every session is matched to an identity and tied to a signed record.
How does Router Mode work?
Router Mode places SignLogger in the network's data path. The flow is:
- Placement: the device sits between the internal network and the internet; WAN and LAN interfaces are defined. Traffic physically passes through the device.
- Zones: interfaces are assigned to logical zones (e.g. LAN, Guest, WAN). Security rules are written as allow / deny between these zones.
- Recording: every passing connection is logged in the device's own data plane and then signed and retained through SignLogger's normal pipeline.
- Controlled activation: readiness checks run before the mode is enabled and the configuration is applied within a confirmation window; if it is not confirmed it rolls back automatically, so a wrong setting cannot lock you out of the network.
The mode has three states: Active (routing is running, configuration persistent), Awaiting confirmation (applied, within the confirmation period) and Disabled. The Firewall Management menu appears only while the mode is enabled and only to administrators of the root domain.
What comes with Router Mode?
Enabling the mode activates the Firewall Management menu and its modules:
- Zone-based security policy: allow / deny rules between zones; tidy, reusable policy built from address and service objects.
- NAT and port forwarding: the internal network exits through a single external address; required services (e.g. a server) are exposed surgically.
- DHCP and DNS: DHCP server or relay on internal interfaces, MAC → IP reservations, DNS settings.
- Captive portal: identity verification (SMS, form, sponsor approval, LDAP / database) is enforced in the guest zone; sessions are tied to records. See Hotspot & Captive Portal for details.
- SD-WAN (multiple internet links): the performance of several links is measured continuously; rules decide which traffic leaves through which link, with automatic failover when a link drops.
- Live Monitor: current connections, open sessions, top destinations and link status on one screen.
- Log Settings: the scope and retention behaviour of the first-hand Law 5651 record.
Where is it used?
- Small and medium businesses: a single SignLogger device instead of a separate firewall plus a separate log server; Law 5651 compliance and the gateway together.
- Branch offices: a small device at each branch; central policy logic, first-hand local records.
- Businesses with a guest network: hotels, cafés, restaurants, malls and clinics — captive portal and guest zone right at the gateway.
- Multiple internet links: sites with two or more links get uninterrupted access and traffic steering with SD-WAN.
If you already have an enterprise firewall, Router Mode is not mandatory: SignLogger keeps working alongside your existing devices with NAC and brand-independent log collection. Router Mode is an additional option for organisations that do not want a separate gateway or that want first-hand records.
What does SignLogger Router Mode offer?
- One panel, one licence: log management, signed archives, hotspot, NAC and the gateway in the same product (Router Mode is a licence-based feature).
- Safe rollout: readiness checks, a confirmation window and automatic rollback; a misconfiguration cannot lock the network.
- Zone-based, readable policy: orderly management with address / service objects and a rule wizard.
- First-hand, signed Law 5651 records: traffic is logged from the device's own data plane and signed and retained every day.
- On your own infrastructure: data stays inside the organisation; no cloud dependency.
For step-by-step setup, screen descriptions and troubleshooting see the Router Mode and Firewall Management User Guide.
Frequently Asked Questions
What is Router Mode and how does it differ from normal mode?
In normal (passive) mode SignLogger only collects the logs other devices send; it does not carry traffic. In Router Mode the device becomes the network gateway, traffic flows through it, and the Law 5651 record is generated first-hand from the traffic the device sees. The zone-based firewall, NAT, DHCP / DNS, captive portal and SD-WAN modules are also activated.
What happens to my existing firewall when I enable Router Mode?
Router Mode is not mandatory. If you have an enterprise firewall, SignLogger can keep running alongside it in passive mode. Router Mode can replace the firewall in organisations that do not want a separate gateway, or serve as a single-device solution at small sites such as branches.
Why can't I see the Firewall Management menu?
The menu is listed only while Router Mode is enabled and only for administrator accounts that belong to the root domain. If you cannot find it, first check the mode's state (Active / Awaiting confirmation / Disabled) on the Dashboard › Status screen.
Why is the Law 5651 record "first-hand"?
Because traffic passes through the device, the connection log is a record SignLogger sees in its own data plane rather than a notification another device forwards to it. The risk of an intermediate device generating an incomplete log or failing to forward it disappears; the record is then signed and retained.
How do the guest network and captive portal work in Router Mode?
The guest interface is assigned to a Guest zone and the captive portal is enforced in that zone. The guest authenticates via SMS, a form, sponsor approval or LDAP / database; the session is matched to the user and tied to the signed Law 5651 record. No separate hotspot appliance is needed.
Are multiple internet links (SD-WAN) supported?
Yes. Several WAN links are defined, their performance is measured continuously, and rules decide which traffic leaves through which link; when a link drops, traffic fails over to the other link automatically.
Is Router Mode licence-based?
Yes, Router Mode is a licence-based feature; it is enabled by adding it to your existing SignLogger licence. Contact our sales team for details.