Skip to main content

Manage Peplink WAN performance

BoatKit can connect to a Peplink router on the vessel LAN, reserve an address for the BoatKit host, and run bounded download tests through each WAN connection. You can collect per-WAN history without changing priorities, then optionally allow BoatKit to move connections between shared Peplink priority tiers.

This integration uses private APIs from Peplink's local web administration portal. Peplink's published Device API does not provide all the LAN and outbound-policy operations BoatKit needs. This is therefore not an officially supported Peplink public API integration, and you should confirm its behavior after changing Peplink firmware.

Compatibility and prerequisites​

Current field experience is limited to BR-series local-portal behavior. A broader list of validated models and firmware versions is not yet documented.

Before starting, you need:

  • A dedicated BoatKit host on the same reachable LAN as the Peplink router
  • Vessel administrator access in BoatKit
  • A dedicated local Peplink administrator account with permission to view WANs and manage DHCP reservations, outbound policies, and WAN priorities
  • At least one visible, enabled Peplink WAN connection
  • Internet access through every WAN you intend to test

BoatKit runs iperf3 on the vessel host. Each performance test is an actual download from a public test server.

You can first run Auto-discover integrations. On hosts that expose their IPv4 gateways, BoatKit checks the unauthenticated local web-admin entry point for Peplink or Pepwave branding. A recognized gateway adds Peplink disabled with the portal address filled in. Discovery does not enter credentials, change router settings, or run performance tests. Existing integrations and retained custom router settings are preserved. If the router uses a custom portal port or is not the LAN gateway, add it manually.

  1. Open Settings, then Integrations.
  2. Select Add Integration.
  3. Open Network Management, find Peplink, and select Add.
  4. Open the added integration and enable Peplink integration.
  5. Enter the router's local hostname or IP address under Peplink address. Include https:// when the local portal uses HTTPS.
  6. Enter the username for the dedicated local administrator account.
  7. If the HTTPS certificate requires a private certificate authority, configure trust as described in Use a private certificate authority before entering the password.
  8. Enter the password. BoatKit logs in and reads the WAN inventory before it saves the password.
  9. Confirm that the integration reports Connected and lists the router's WAN connections.

The password is a write-only device secret. Viewer clients cannot retrieve it, and portable BoatKit backups do not include it. Changing Peplink address or Username clears the saved password so BoatKit cannot send an old credential to a different router or account.

After a successful connection, BoatKit reconnects at startup and periodically refreshes the WAN inventory. If the router is starting or temporarily unreachable, BoatKit retries with increasing delays. Select Validate and refresh when you want an immediate retry.

Use a private certificate authority​

A Linux-hosted BoatKit vessel can trust a private certificate authority for an https:// Peplink address:

  1. Open Peplink HTTPS Trust.
  2. Select Upload CA bundle.
  3. Choose a PEM-encoded CA certificate or bundle no larger than 256 KiB.
  4. After the upload succeeds, select Validate and refresh in Peplink Credentials.

BoatKit verifies that every certificate in the bundle is a certificate authority. It adds the uploaded authorities to the Linux system roots used by the isolated Peplink client; it does not change certificate trust for other BoatKit integrations or the host system generally.

Custom CA upload is available only on Linux-hosted vessels. Non-Linux app-hosted runtimes, including iOS and Android vessels, do not expose this capability.

The CA bundle is nonsecret trust configuration. It remains aboard and usable without BoatKit Cloud, and portable configuration backups include it. The Peplink password remains excluded from those backups.

Reserve BoatKit's LAN address​

The BoatKit Static IP section shows the IP address and hardware address of the network interface the operating system currently uses to reach Peplink.

This reservation is optional and is not required for WAN performance testing. BoatKit's managed test rules identify the host by its interface hardware address, so a changing DHCP lease does not break test routing.

  1. Enter the private IPv4 address Peplink should reserve under Reserved BoatKit IP. BoatKit initially offers the current address.
  2. Select Ensure reservation.
  3. Review and confirm the router change.
  4. Confirm that BoatKit reports that the reservation is present or was created.

Immediately before making the change, BoatKit reads the complete untagged LAN profile and preserves fields it does not manage. It changes only the DHCP reservation matching the BoatKit interface's hardware address and refuses to use an address already reserved for another device.

Peplink uses a shared staged-configuration transaction for this change. BoatKit refuses to modify the reservation while the router has unrelated unapplied changes. Apply or discard those changes in the Peplink local administration portal before trying again.

If you reserve an address different from the host's current lease, BoatKit may continue using the old address until the lease renews or the host network is restarted. Plan the transition so it does not interrupt active work aboard.

Configure WAN performance tests​

Set the shared testing policy under WAN Performance Management:

  • iperf3 test host selects a curated worldwide Leaseweb target. BoatKit probes target reachability and latency without running a bandwidth test, sorts reachable targets by latency, and marks the nearest result as recommended. Every curated target supports BoatKit's managed per-WAN test routing.
  • Minimum acceptable download is the global threshold for every WAN. A test stops early when a complete interval reaches this rate.
  • Maximum test duration is the per-WAN cap, including a one-second warm-up. The default is five seconds, and the allowed range is 2 through 60 seconds.
  • Normal priority is the global Peplink tier to use after an acceptable result.
  • Low-bandwidth priority is the equal or less-preferred global tier to use after a low result or failed test.

BoatKit automatically allocates the internal routing needed for each visible WAN that is enabled and not disconnected. It creates narrow outbound-policy rules that match the BoatKit interface's hardware address and the test's TCP ports, repairs conflicting BoatKit-managed assignments, and does not create assignments for hidden, disabled, or disconnected WANs. Disconnected WANs also receive no speed tests and appear with disabled connections in the WAN board.

Observation mode still manages test routing

Leaving priority enforcement off prevents BoatKit from moving WAN priority tiers. BoatKit must still create and maintain Peplink outbound-policy rules so each test uses the intended WAN.

As with the DHCP reservation, BoatKit refuses to change managed test routing while unrelated Peplink changes are pending. Apply or discard the pending configuration in the local Peplink portal first.

Tests consume metered data

Each test is a real download. BoatKit tests WANs sequentially in reverse mode so the tests do not compete with one another. A test stops at the first complete interval that meets the acceptable threshold or at the configured duration cap. Use conservative settings for cellular and satellite plans.

Select Run tests now to perform an initial cycle. The results appear in the WAN board, which:

  • Follows the WAN inventory displayed by Peplink
  • Omits internal cellular child or module slots that Peplink hides
  • Groups enabled connections by their current priority tier
  • Lists disabled connections separately
  • Shows Peplink's current connection status for each WAN
  • Charts 30 days of download results for each WAN

Start with observation-only history​

Scheduled testing and automatic priority enforcement are separate opt-ins. Begin with enforcement disabled so you can decide whether the chosen server and threshold produce reliable results for your vessel.

  1. Set Maximum time between tests. The default is six hours.
  2. Set Movement test trigger. The default is ten statute miles.
  3. Enable Scheduled performance testing and confirm the metered-data warning.
  4. Leave Automatic priority enforcement off while you gather history.

BoatKit starts a cycle when either the configured time has elapsed or the vessel has moved the configured distance, whichever happens first. After an attempt finishes, the time and movement baselines are both reset. This includes an attempt stopped by a router or test error, which prevents a persistent failure from immediately consuming more data.

Movement scheduling requires a trusted vessel position. Simulated or quarantined positions do not trigger it, but time-based scheduling continues when a trusted position is unavailable.

Observation mode records the same measurements and 30-day charts without changing WAN priorities. Results also enter BoatKit's time-series history.

Optionally enforce priority tiers​

After repeated tests show that the selected target and minimum rate distinguish usable and degraded connections reliably, enable Automatic priority enforcement.

For each tested WAN, BoatKit then:

  • Moves the connection to Normal priority after an acceptable result
  • Moves it to Low-bandwidth priority after a low result or failed test

Both settings apply globally to all managed WANs and use Peplink tiers 1 through 4, where tier 1 is the most preferred. The low-bandwidth tier cannot be more preferred than the normal tier.

Peplink applies these priority changes immediately. They do not use the shared staged-configuration transaction used for DHCP reservations and outbound-policy rules. Disabling Scheduled performance testing also disables automatic priority enforcement.

Confirm it is working​

Check the following after setup:

  • Peplink Credentials reports Connected.
  • The WAN board contains the same user-visible connections as Peplink's local portal and groups them by priority.
  • Ensure reservation reports that the BoatKit reservation exists at the requested address.
  • Run tests now changes to Testing WANs…, then records a latest result or a specific error for each enabled WAN.
  • Each tested WAN gains a point in its 30-day speed history chart.
  • If enforcement is enabled, an acceptable result moves the WAN to the normal tier and a low or failed result moves it to the low-bandwidth tier.

Offline behavior​

The Peplink connection, saved settings, custom CA trust, discovered local inventory, existing history, DHCP reservation management, and local priority display do not require BoatKit Cloud. They remain available while the vessel is offline as long as BoatKit can reach the router over the LAN.

A new performance test requires the selected public iperf3 target to be reachable through the WAN being tested. Target recommendations also require internet access. If enforcement is enabled, an unreachable or failed test is treated as a degraded result and can move that WAN to the low-bandwidth tier.

Backups and removal​

Performance measurements are stored in BoatKit's time-series history and follow the time-series backup policy you selected.

Portable configuration backups include nonsecret choices such as:

  • The Peplink address and username
  • The custom CA bundle
  • The desired DHCP reservation
  • The test target and managed route assignments
  • The schedule, threshold, and duration
  • The normal and low-bandwidth priority tiers

The password is omitted. Discovered WAN inventory and the scheduling and rule-reconciliation cursors remain device-local and are rebuilt from the attached router after a restore.

Removing the integration clears the saved password, custom CA, BoatKit-side settings, policy choices, and device-local Peplink state. It does not remove DHCP reservations or outbound-policy rules already applied to the router. Remove those separately in Peplink's local administration portal if they are no longer wanted.

Troubleshooting​

Credentials are rejected​

Confirm that Peplink address opens the intended local administration portal and that the account is a local administrator with the required permissions. Changing the address or username clears the saved password, so enter it again afterward.

HTTPS certificate validation fails​

If the router uses a private certificate authority, confirm that BoatKit is hosted on Linux and that the uploaded file contains only PEM-encoded CA certificates. A server or leaf certificate cannot be used as a trust anchor. After replacing the bundle, select Validate and refresh.

BoatKit refuses a reservation or test-routing change​

Open the Peplink local administration portal and apply or discard its pending configuration. BoatKit will not combine its LAN or outbound-policy changes with an unrelated staged change.

A WAN is missing​

Select Refresh WAN list, then compare the result with Peplink's own WAN Connection Status display. BoatKit intentionally omits hidden internal cellular children and unassociated module slots. Confirm that the expected WAN is enabled in Peplink.

A target is unreachable​

Confirm that the BoatKit host can reach the internet and that the selected WAN permits traffic to the public target. Refreshing the target list performs only a reachability and latency probe; it does not consume bandwidth like a full test.

A test reports that iperf3 is missing​

Use a current BoatKit vessel-runtime image. Older custom images may not contain the iperf3 executable.

Priorities do not change​

Confirm that both Scheduled performance testing and Automatic priority enforcement are enabled. A manual test can collect results while scheduled testing is disabled, but it does not apply automatic priority changes in that state.

Results vary between cycles​

Public speed-test servers are shared, and mobile and satellite links naturally vary. Treat a single result as an operational signal rather than a carrier-grade benchmark. Choose a threshold that reflects usable onboard service and review repeated results before enabling enforcement.

The integration stops working after a firmware update​

Use Validate and refresh and compare the displayed WANs with Peplink's local portal. Because this integration relies on private local-portal APIs, model or firmware changes can alter the behavior BoatKit depends on. Leave automatic enforcement disabled until testing confirms the integration still behaves as expected.


Peplink is a trademark of Peplink. Leaseweb is a third-party public test service. BoatKit is not affiliated with, certified by, or endorsed by Peplink or Leaseweb.