Skip to content
LizoraINFOTECH
Routing2 September 20264 min read

Lysora cloud routers: sizing a gateway that does not become the bottleneck

2.5G to every AP — the radio is never the bottleneck. A Gigabit access port caps a tri-band Wi-Fi 7 AP well below what it is rated for.

A gateway is the one device every packet crosses, which makes undersizing it uniquely annoying: everything gets slower at once and nothing points at the cause. The Lysora range has three, and picking between them is mostly a matter of understanding two numbers that datasheets print side by side as if they were the same thing.

Throughput and sessions are different problems

Throughput is how much data per second. Concurrent sessions is how many simultaneous conversations the device can track. A single large file transfer is high throughput and one session. Two hundred people with browsers, chat apps, email clients and background sync is modest throughput and tens of thousands of sessions.

Offices, hotels and retail sites usually run out of sessions before they run out of throughput. If a gateway feels slow while the internet link is barely loaded, this is almost always why.

The three Lysora cloud routers
ModelThroughputSessionsUsersPortsPoE out
LR100G600 Mbps (1 Gbps turbo)12,0001005× GbENone
LR300G-P1.5 Gbps100,000300–35010× GbE8 ports, 110 W
LR1500XS4 Gbps300,0001,5004× 2.5G + 4× 1G + 2× 10GE SFP+None
Branch box, PoE gateway and rack unit. The middle one is what most sites end up with.

Dual WAN is the feature you buy it for

Every model here terminates more than one internet circuit with SD-WAN policy and automatic failover. For a retail site this is not a nice-to-have: cloud point of sale, card authorisation and stock lookup all stop when the link does, and the shop cannot fall back to paper the way it once could.

Failover only helps if the important traffic is prioritised on the surviving link. Application control and traffic audit on the LR300G-P and LR1500XS let you put point of sale or voice ahead of guest browsing, so a slower backup circuit degrades the right things.

VPN, and when you need routing rather than NAT

All three carry a full VPN suite — IPsec, WireGuard, OpenVPN, L2TP and PPTP — which covers branch-to-head-office tunnels and remote access without a separate concentrator.

Dynamic routing is where they separate. The LR300G-P adds BGP and OSPF; the LR1500XS adds RIP as well. If your network has to peer properly — a campus core, an ISP edge, a multi-building estate with its own address space — that matters. If every site is a branch that NATs to the internet, it does not, and the LR100G is enough.

Which one, in practice

LR100G — small branch, kiosk, small store

Five Gigabit ports, up to two WAN, 100 users, 5 W and fanless. Genuinely silent, which matters when it lives under a counter rather than in a rack. No PoE, so the access points and cameras need their own switch.

LR300G-P — the one most sites end up with

Ten Gigabit ports with eight of them delivering PoE/PoE+ within a 110 W budget, so a small site needs no separate switch at all. 1.5 Gbps, 100,000 sessions, 64 VLANs, BGP and OSPF, application control. This is the default for a retail branch, a small hotel or a single-floor office.

LR1500XS — campus and large property

Four 2.5G and four Gigabit RJ45 ports plus two 10GE SFP+, 4 Gbps, 300,000 sessions, 1,500 recommended clients. Also 4 GB of RAM, 8 GB eMMC and a SATA bay, which means on-box logging rather than shipping everything off-site.

2.5G TO EVERY AP — THE RADIO IS NEVER THE BOTTLENECKFLOOR 3L7 · Wi-Fi 7LS2P-8MG2XS-P8× 2.5G · 2× 10G SFP+FLOOR 2L7 · Wi-Fi 7LS2P-8MG2XS-P8× 2.5G · 2× 10G SFP+FLOOR 1L7 · Wi-Fi 7LS2P-8MG2XS-P8× 2.5G · 2× 10G SFP+10G fibre riserLS3-24SFP/8GT4XSLayer 3 core · OSPFLR1500XSSD-WAN · 4 GbpsWAN 1WAN 2A Gigabit access port caps a tri-band Wi-Fi 7 AP well below what it is rated for
The LR1500XS terminating two circuits behind a Layer 3 core, in a three-floor office.
The three modelsLR100GLR300G-PLR1500XS

How many users can the LR300G-P really handle?

The manufacturer states 300 in its feature copy and 350 in its spec table — we show both rather than picking one. In practice the 100,000 concurrent sessions is the more useful limit: a site of 300 ordinary office users sits comfortably inside it, a site of 300 people each running a dozen background-syncing apps sits closer to the edge.

Do I need a separate switch with the LR300G-P?

Not for a small site. Eight of its ten ports deliver PoE/PoE+ within 110 W, which covers a couple of access points and a few cameras. Beyond that, or if you need more than 64 VLANs, add a switch and let the gateway route.

Does failover drop active connections?

Sessions established on the failed link are lost — that is true of any failover that is not session-mirrored. What continues is everything started afterwards, within seconds and without anyone touching the equipment. For point of sale, the practical effect is one retried transaction rather than a closed till.

Can these replace a firewall?

They do NAT, VLAN isolation, VPN termination and application control, which covers a lot of small-site requirements. They are not a next-generation firewall — no IPS, no deep inspection licensing. Where a tender or a compliance regime asks for one, we supply Fortinet alongside.

Sizing something specific right now?

Send the floor plan, the camera count or an existing BOQ. You get a coverage heatmap and a line-item quote back, free.