Compare Products


Clear All


Sales Enquiry

Product Overview

The RG-WS6008 high-performance wireless access controller (AC), developed by Ruijie Networks, is targeted for high-speed wireless networks. It can be deployed on a Layer 2 or Layer 3 network without any architecture or hardware device changes, delivering seamless and secure control over wireless networks.

The RG-WS6008 can manage up to 32 wireless access points (APs) by default. With licenses for capacity expansion, it can manage a maximum of 224 generic APs or 448 wall-mounted APs.

Through powerful centralized and visualized management and control over wireless networks, the RG-WS6008 can significantly simplify construction and deployment of wireless networks.

The RG-WS6008, adopting enhanced security and clustering technologies, offers identity-based networking services. Multiple ACs in a cluster can share a user database, allowing clients to seamlessly roam in different areas of a network. The cluster design guarantees the security and session integrity during roaming and smooth interaction of data and voice over Wi-Fi applications.

Product Features

Smart Wireless Experience

Intelligent Client Identification

The built-in Portal server of the RG-WS6008 can intelligently identify clients based on characteristics of the clients, and adaptively respond with a portal authentication page of the matching size and layout. Intelligent client identification eliminates the need to drag and resize a window, delivering users with a better intelligent wireless experience. This technology supports mainstream intelligent client operating systems including Apple iOS, Android, and Windows.

Fair Client Access

The RG-WS6008, together with Ruijie Networks' APs, provides the same access time for clients in compliance with IEEE 802.11g, 802.11n, 802.11ac, 802.11ax, and other standards. This resolves issues such as the long latency, slow speed, and low performance of APs caused by outdated NIC in clients or long distance between clients and APs. This also effectively improves the performance of low-speed clients, and ensures consistent and good wireless experience at the same location regardless of the client type.

Client Access Optimization

It can be used with Ruijie Cloud to monitor network-wide client behaviors and operating status, and obtain information such as the client signal strength and channel utilization through APs. With Wi-Fi client identification and access planning, it solves problems such as roaming stickiness and remote association, and achieves load balancing and improved network-wide wireless performance.

Intelligent Load Balancing

In a high-density environment, the RG-WS6008 can intelligently distribute clients connected to APs in real time based on the number of clients and traffic on each associated AP. This balances the traffic load, increases the average client bandwidth and QoS, and improves the availability of network connections. In addition to client-based and traffic-based intelligent load balancing, the RG-WS6008 also supports load balancing based on the frequency band. Most Wi-Fi devices use the 2.4 GHz band by default, but can achieve increased throughput in the 5 GHz band (IEEE 802.11a/n/ac/ax-compliant). Load balancing based on the frequency band enables dual-radio-capable clients to preferentially use the 5 GHz frequency band and guarantees a high-speed wireless experience for clients.

High Performance and Reliability

High Performance for Small- and Medium-sized Networks

The RG-WS6008 runs the RGOS system and can manage up to 7,168 clients and 448 APs simultaneously. It has a high-performance 4-core CPU. It can be used for small- and medium-sized networks, to set up a secure, efficient, and easy-to-manage wireless network.

Centralized/Distributed, Integrated, and Intelligent Forwarding

The RG-WS6008 can be deployed on a Layer 2 or Layer 3 network without changing the original network architecture. It constitutes an overall switching architecture with APs to facilitate control and processing of traffic on all APs. The intelligent local forwarding technology eliminates the traffic bottleneck of an AC.

With local forwarding technology, the RG-WS6008 can flexibly configure data forwarding modes for connected APs. That is, the RG-WS6008 can determine whether data needs to be forwarded through itself, or directly enters the wired network for local forwarding based on the network SSID and VLAN planning.

The local forwarding technology enables the RG-WS6008 to forward data that is sensitive to the delay and requires real-time high-performance transmission through a wired network. Facing high throughput of 802.11ac- and 802.11ax-compliant clients, this technology can greatly reduce the traffic forwarding pressure of the RG-WS6008 to better adapt to future wireless networks such as high definition (HD) Video on Demand (VoD) and Voice over Wireless Local Area Network (VoWLAN) transmission.

Intelligent RF Management

The RG-WS6008 enables an AP to perform on-demand RF scanning on a wireless network. The RG-WS6008 can scan wireless frequency bands and channels, identify unauthorized APs and wireless networks, and notifies network administrators of alarms, providing all-round protection in a security-sensitive environment.

Moreover, the RG-WS6008 can control the RF scanning function of APs in real time, and measure the signal strength and interference. It can dynamically regulate the traffic load, transmit power, RF coverage area, and channel allocation using software tools to maximize the AP coverage and capacity.

Network-wide Seamless Roaming

The RG-WS6008 supports the best-in-class AC cluster technology. Multiple RG-WS6008 controllers in a cluster can synchronize online connection information and roaming records of all clients in real time. When a client roams, the client can roam freely on the entire network based on shared client information and authorization information in the cluster. Furthermore, the client can roam seamlessly and securely, and keep the IP address and authentication status unchanged, so as to achieve fast roaming and voice support.

Abundant QoS Policies

The RG-WS6008 supports abundant QoS policies such as bandwidth limiting in multiple modes and preferential bandwidth guarantee for key data applications.

The RG-WS6008 supports bandwidth limiting based on the WLAN, AP, and STA, and provides Wi-Fi Multimedia (WMM) that defines priorities for different service data. Therefore, it implements immediate and quantitative transmission of audio and video data, and guarantees smooth application of multimedia services.

The multicast-to-unicast technology supported by the RG-WS6008 solves the video freezing problem caused by packet loss or long latency in Video on Demand (VoD) and other multicast applications on a wireless network. It enhances the experience in the use of multicast video services on a wireless network.

Wireless IPv6 Access

The RG-WS6008 fully supports IPv6 features, ensuring IPv6 forwarding on wireless networks. IPv4 and IPv6 clients can automatically connect to the RG-WS6008 through tunnels to provide IPv6 services on wireless networks.

Advanced AC Virtualization

The RG-WS6008 supports the cutting-edge AC virtualization technology. The technology can virtualize up to four ACs into one logical AC, realizing high reliability and capacity expansion without additional hardware devices.

  • Simplified topology: All member ACs of the logical AC use the same IP address. Regardless of whether the logical AC connects to an AP or an authentication server, there is no need to assign an IP address to each member AC.
  • Simplified configuration: Multiple member ACs can be managed as one AC. Any configuration of the master AC can be automatically synchronized to all member ACs.
  • High reliability: N+M hot standby is supported. The breakdown of any AC will not affect the overall system.
  • Smooth capacity expansion: The AP and client capacity can be expanded by adding a physical AC.
  • Licensesharing: A license installed on any member AC of the logical AC can be shared by other member ACs.

Advanced Application Recognition and Policy Control

To simplify network management and protect wired and wireless network access, the RG-WS6008 supports advanced application identification and policy control technologies. The RG-WS6008 can be configured with different user objects, network objects, and VLANs for flexible policy control. In this case, there is no need to configure separate network policies for SSIDs, VLANs, and other objects.

Wired and wireless traffic is transmitted to the RG-WS6008 through the centralized/distributed, integrated, and intelligent forwarding technology, and then is managed by using application identification and control policies.

The RG-WS6008 supports application recognition and application-level QoS mapping technology for wireless clients. The RG-WS6008 in centralized forwarding mode applies Deep Packet Inspection (DPI) to packet characteristics to support over 2,500 applications. It can identify applications, collects statistics on applications, and employs QoS mapping, helping you understand the application usage on the network. Then QoS can be performed for application traffic.

For mainstream web BBS sites and search engines, the RG-WS6008 can audit and filter user posts and search contents, and allow or block data flows based on policies.

Flexible and Comprehensive Security Policies

Local Authentication

The RG-WS6008, with a built-in local user database and a built-in Portal server, authenticates wireless clients locally through web authentication. Local authentication eliminates the need to deploy an authentication server such as the external Portal server or RADIUS server. Moreover, this authentication mode simplifies the entire network architecture and greatly reduces the network construction cost, meeting requirements for secure access to small- and medium-sized wireless networks.

Client Data Encryption and Security

The RG-WS6008 supports a full range of data security protection mechanisms, including Wired Equivalent Privacy (WEP), Temporal Key Integrity Protocol (TKIP), and Advanced Encryption Standard (AES), to ensure data transmission security on wireless networks.

Standard Communication Protocols

The RG-WS6008 communicates with APs over Control and Provisioning of Wireless Access Points (CAPWAP) tunnels and employs Datagram Transport Layer Security Version 1.0 (DTLS 1.0) for encrypted communication. This achieves isolation from a wired network and ensures confidentiality of real-time communication between the RG-WS6008 and APs. Additionally, the RG-WS6008 can use CAPWAP to control third-party APs in the future, facilitating network expansion as well as protecting existing investment.

Virtual AP Technology

With the virtual AP technology, the RG-WS6008 can allocate multiple SSIDs on a network. Network administrators can separately isolate and encrypt subnets or VLANs using the same SSID, and can configure the separate authentication method and encryption mechanism for each SSID.

AP Virtualization Technology

This technology enables one physical AP to be virtualized into multiple virtual APs, which can be managed by different wireless access controllers. Paired with Ruijie Networks' APs that has multiple uplink physical ports, the RG-WS6008 can isolate wireless data of different virtual APs on the same physical AP, realizing exclusive use of the private network and ensuring high security of critical services. For a physical AP with a single uplink port, AP virtualization technology allows the WLAN to be shared by multiple ISPs in public places such as airports and shopping malls. This fully utilizes AP, significantly reduces the cabling cost, and eliminates interference caused by excessive APs.

RF Security

The RG-WS6008 can be flexibly configured with the RF probe scanning mechanism to discover unauthorized APs or other RF interference sources in real time. It pushes corresponding alarms to the network management system (NMS) in real time, so a network administrator can monitor potential network threats and usage in each wireless environment at any time.

The RG-WS6008 supports advanced spectrum analysis and Wireless Intrusion Detection System (WIDS). It can use WIDS to detect malicious user attacks and intrusions in the early time, helping network administrators to proactively identify potential risks on a network and provide proactive defense and early warning against wireless attackers in the first instance.

Virus and Attack Prevention

The RG-WS6008 has various built-in security mechanisms to effectively protect a network against virus and network traffic attacks, reject unauthorized network access, and allow access from authorized clients. The security mechanisms include binding of IP addresses, MAC addresses, WLANs, and other elements, hardware ACL, and data stream-based rate limiting, so the RG-WS6008 is suitable for campus, hospital, and enterprise networks where access control of guests is strengthened and access of unauthorized clients is restricted.

Secure Client Access

The RG-WS6008 supports web authentication. Clients can complete the authentication process by using a browser.

It supports 802.1X authentication on clients to guarantee network security. Moreover, it ensures host security because the 802.1X authentication client is embedded on a host for access control. Unlike web authentication, 802.1X authentication is applicable to security-sensitive areas. Furthermore, IP addresses, MAC addresses, WLANs, and other elements can be bound after authentication. This ensures that only authorized clients can access the network.

Multiple Easy-to-Use Authentication Modes

The RG-WS6008 supports conventional web authentication and 802.1X authentication for monitoring network access behaviors. It also provides convenient authentication modes for customers based on actual scenarios, such as MAC authentication bypass (MAB), and SMS-based and QR code-based guest authentication.

When connecting to a network through MAB authentication, a wireless client only needs to enter the username and password upon first login. The username and password are no longer required when the wireless client is restarted and connected to the network.

When a guest accesses a wireless network through SMS-based authentication, an authentication page pops up. On the authentication page, the guest can register an account using the mobile number, and accesses the Internet using the username and password in the SM received.

QR code-based authentication is another convenient way for guests to access the Internet. After connecting to a wireless network, a guest will receive a QR code prompt. The guest can access the Internet after being authorized by the visited employee. Guest behaviors are associated with the visited employee to ensure high security.

Anti-ARP Spoofing

The ARP inspection function can effectively prevent increasing ARP gateway and ARP host spoofing attacks on a network, so as to ensure normal network access. Automatic IP-MAC binding can greatly save the labor cost and simplify management in dynamic or static IP allocation mode. An attacker may maliciously use scanning tools to flood ARP packets, which occupy network bandwidth and result in network congestion. To address this issue, the RG-WS6008 uses ARP rate limiting to control the rate of sending ARP packets.

Rogue AP Containment

Rogue AP containment can effectively detect unauthorized APs on a wireless network. The RG-WS6008 can instruct an AP to send a probe packet to surrounding APs and wait for a response. It can detect the unauthorized AP that does not send a response packet, thereby ensuring network-wide security.

DHCP Security

DHCP snooping enables the RG-WS6008 to allow only DHCP Reply messages from trusted interfaces, preventing a private DHCP server without the permission of an administrator. This is because the private DHCP server seriously affects IP address allocation and management, resulting in network access failures. With DHCP snooping configured, the RG-WS6008 can dynamically check source IP addresses of ARP packets to prevent ARP spoofing attacks and source IP address spoofing attacks in the environment in which the DHCP server dynamically allocates IP addresses.

Management Information Security

Through the Secure Shell (SSH) and Simple Network Management Protocol version 3 (SNMPv3), the RG-WS6008 encrypts management information in Telnet and SNMP processes, ensuring information security of management devices and preventing hackers from attacking and controlling devices. Telnet access control based on the source IP address means fine-grained device management and control. With this function, only the devices with IP addresses configured by administrators can connect to the RG-WS6008, enhancing network management security.

Rich Management Policies

Multiple Management Modes and Unified Management Platform

The RG-WS6008 supports the CLI and other management modes to implement centralized, effective, and low-cost planning, deployment, monitoring, and management of network-wide APs. The RG-Cloud, a unified management platform for wired and wireless networks developed by Ruijie Networks, manages APs uniformly. The RG-WS6008 together with Ruijie Cloud implements various wireless network management functions, including topology generation, AP working status monitoring, online client status monitoring, network-wide RF planning, client locating, security alarm, link load and device utilization monitoring, roaming record, and report output. The RG-WS6008 allows an administrator to monitor and manage the running status of the entire network in a data center.

Hierarchical AC Management

The h supports hierarchical AC management. A central AC uniformly manages hundreds of branch ACs, substantially simplifying wireless device management in the scenario with the headquarters and many branches. Hierarchical AC management has the following features:

  • Unified management: The central AC uniformly upgrades the software of branch ACs and APs, and monitors the running status of each branch AP.
  • High reliability: When a branch AC fails, branch APs can be taken over by the central AC, realizing fast failover and improving the reliability of the branch wireless network.
  • License sharing: The branch AC can share the license installed on the central AC as required. A license can be installed on the central AC, and shared by all branch ACs on a network.

Eweb Management

The RG-WS6008 provides the Eweb, on which O&M personnel can complete wireless configuration easily, and manage the wireless network uniformly. On the Eweb, O&M personnel can manage APs and connected clients, limit the client rates, and restrict network access behaviors of the connected clients. With the Eweb, O&M personnel can plan, manage, and maintain wireless networks conveniently.


Dimensions and Weight


Unit dimensions (W x D x H)

440 mm x 200 mm x 43.6 mm (17.32 in. x 7.87 in. x 1.72 in.)

Rack height

1 RU


2.9 kg (6.39 lbs)



Fixed service port

6 x 10/100/1000BASE-T ports

2 x 1GE SFP/RJ45 combo ports

Fixed management port

1 x RJ45 console port

2 x USB ports

Status LED

1 x system status LED

1 x power status LED

10 x service port LEDs


1 x Reset button

● Press the button for shorter than 3 seconds. Then the device restarts.

● Press the button for longer than 3 seconds. Then the device restores to factory settings.

1 x power switch


Power Supply and Consumption


Maximum power consumption

40 W

Input power supply

1 x 40 W built-in power module

Input voltage

100 V AC to 240 V AC, 50 Hz to 60 Hz

Input current

1.5 A (maximum RMS current)

Output voltage

12 V/3.33 A


Environment and Reliability



Operating temperature: 0°C to 45°C (32°F to 113°F)

Storage temperature: –40°C to +70°C (–40°F to +158°F)

Note: At an altitude in the range of 3,000–5,000 m (9,842.52–16,404.20 ft.), every time the altitude increases by 220 m (721.78 ft.), the maximum temperature decreases by 1°C (1.8°F).


0 m to 3000 m (0 ft. to 9,842.52 ft.)


Operating humidity: 10% RH to 90% RH (non-condensing)

Storage humidity: 5% RH to 95% RH (non-condensing)


Fan speed adjustment

Fan fault alarm

Acoustic noise

< 78 dB

Mean Time Between Failure (MTBF)

200,000 hours (22 years) at the operating temperature of 25°C (77°F)


Software Specifications



Default number of manageable APs


Note: The default number of APs that can be managed by the RG-WS6008 is subject to the AP model. See the Ordering Information for details.

Maximum number of configurable APs


Maximum number of manageable APs


Note: The maximum number of APs that can be managed by the RG-WS6008 is subject to the AP model. See the Ordering Information for details.

Maximum number of manageable STAs


Note: The maximum number of STAs that can be managed by the RG-WS6008 is subject to the network environment. Contact technical support team for details.

WLAN service

Maximum number of WLAN IDs: 2,048

Maximum number of associated STAs per WLAN: 7,168

Intra-AC roaming handoff time

< 50 ms

Maximum number of virtualized ACs


Number of concurrent CAPWAP data channels


Routing and Switching

Number of MAC address entries


Number of VLANs


Number of ARP entries


DHCP address pools

Number of IPv4 address pools: 2,000

Number of IPv4 addresses: 24,576

Number of IPv6 address pools: 256

Number of IPv6 addresses: 2,048

Number of routing entries

IPv4 routing entries: 8,192

IPv6 routing entries: 10,000

Number of multicast entries

Static routing entries: 2,048

Multicast group routing entries: 4,096

Security and Authentication

Maximum number of STAs supported by the built-in Portal server


Number of ACL entries



Applicable Software Version


Applicable software version

RGOS11.9(6)W1B1 or later




IEEE 802.11 protocols

802.11, 802.11b, 802.11a, 802.11g, 802.11d, 802.11h, 802.11w, 802.11k, 802.11v, 802.11r, 802.11i, 802.11e, 802.11n, 802.11ac, and 802.11ax


Layer 2 and Layer 3 topology between an AP and an AC

An AP can automatically discover the accessible AC.

An AP can be automatically upgraded through the AC.

An AP can automatically download the configuration file from the AC.

CAPWAP through NAT


Intra-AC Layer 2 or Layer 3 roaming

Inter-AC Layer 2 or Layer 3 roaming

Forwarding mode

Centralized forwarding

Local forwarding

Service-based flexible forwarding

Wireless QoS

AP/WLAN/STA-based rate limiting

(WLAN/STA-based rate limit range: 8-261,120 in the unit of 8 Kbps. For example, if you set the value to 8, the rate limit is 8 x 8 Kbps = 64 Kbps.)

Static and intelligent rate limiting based on STA quantity

Fair scheduling

User isolation

AC-based user isolation

AP-based user isolation

WLAN-based user isolation


AC virtualization

AC failover

Multi-AC hot standby (1+1 A/A and A/S hot standby, and N+1 hot standby)

Multi-AC cluster (N-to-N)

Remote intelligent perception technology (RIPT)

Non-stop service during upgrade

STA management

Access control based on the number of STAs associated with the AP

Access control based on the number of STAs associated with the SSID

Balanced access control based on the number of STAs associated with the AP

Balanced access control based on the AP traffic

Band steering

Configuration of the RSSI threshold in dB (Range: 0-100)

Configuration of the STA idle timeout period in seconds (range: 60-86,400)

WLAN optimization

Adjustment of the transmit power for beacon packets or probe responses

RF management

Country or region code setting

Manual setting of the transmit power

Automatic setting of the transmit power

Manual setting of the operating channel

Automatic setting of the operating channel

Automatic adjustment of the data rate

Coverage hole compensation

AP load balancing based on traffic and STA quantity

Band selection

Radio Frequency Interference (RFI) detection and mitigation




IPv4 security authentication

Web authentication

802.1X authentication

MAB authentication

SMS authentication

QR code-based authentication

IPv6 security authentication

Web authentication

IEEE 802.11 security and encryption

Multi-SSID mode

SSID hiding

IEEE 802.11i-compliant PSK authentication

WPA and WPA2

WPA3: WPA3-Personal (SAE), WPA3-Enterprise (CCMP, 128-bit), and WPA3-Enterprise (GCMP, 192-bit)




Anti-ARP spoofing







AP virtualization





IPv4 protocols

Ping and traceroute

DHCP server, DHCP client, DHCP relay, and DHCP snooping

DNS client



TFTP server and TFTP client

FTP server and FTP client

IPv6 protocols

DNSv6 client

DHCPv6 relay and DHCPv6 server

TFTPv6 client

FTPv6 server and FTPv6 client



IPv6 ping

Manual tunnels and automatic tunnels

Manually configured IP addresses and automatically created local addresses

IPv6 traceroute

IPv4 routing

Static routing, RIP, and OSPF

IPv6 routing

Static routing




Network management

SNMP v1/v2c/v3



Network management platform


Ruijie Cloud


Wi-Fi heat map

User access management

Console port login, Telnet login, SSH login, and FTP upload


Regulatory Compliance


Safety regulations

IEC 62368-1, EN 62368-1

EMC regulations

EN 55032, EN 55035, EN 61000-3-3, EN IEC 61000-3-2, and ETSI EN 300 386

*For more country-specific regulatory information and approvals, contact your local sales agency.


Show More
Resources All Resources
Learn about Products or Solutions
Software and Configuration
Informasi Pemesanan

Main Unit




The next-generation wireless controller provides 6 x GE electrical ports and 2 x SFP combo ports.

It supports 32 APs by default, and up to 224 licenses are available.

The maximum number of APs that can be managed by the AC is subject to the AP model:

● A generic AP occupies one license. The RG-WS6008 can manage up to 224 generic APs.

● A wall plate AP occupies half of the license. The RG-WS6008 can manage up to 448 wall plate APs.

● An i-Share micro AP occupies no license. The RG-WS6008 can manage up to 448 i-Share micro APs.

● The number of licenses occupied by an i-Share master AP is subject to the model. See the ordering information in the datasheet of corresponding i-Share master AP for details.






The number of capacity expansion licenses for the RG-WS series wireless controller can be expanded to 16. Each license supports one generic AP or two wall plate APs. For the number of licenses occupied by an i-Share master AP, see the ordering information.


The number of capacity expansion licenses for the RG-WS series wireless controller can be expanded to 32. Each license supports one generic AP or two wall plate APs. For the number of licenses occupied by an i-Share master AP, see the ordering information.


The number of capacity expansion licenses for the RG-WS series wireless controller can be expanded to 128. Each license supports one generic AP or two wall plate APs. For the number of licenses occupied by an i-Share master AP, see the ordering information.


The number of capacity expansion licenses for the RG-WS series wireless controller can be expanded to 512. Each license supports one generic AP or two wall plate APs. For the number of licenses occupied by an i-Share master AP, see the ordering information.


The number of capacity expansion licenses for the RG-WS series wireless controller can be expanded to 1,024. Each license supports one generic AP or two wall plate APs. For the number of licenses occupied by an i-Share master AP, see the ordering information.

Show More
How would you rate your experience on this page?
Very disatisfying
Very satisfying
If you would like to offer more comment, please type in the textbox below, that would be helpful for the improvement of this page.
Thank you for your feedback!

Ruijie Networks websites use cookies to deliver and improve the website experience.

See our cookie policy for further details on how we use cookies and how to change your cookie settings.

Cookie Manager

When you visit any website, the website will store or retrieve the information on your browser. This process is mostly in the form of cookies. Such information may involve your personal information, preferences or equipment, and is mainly used to enable the website to provide services in accordance with your expectations. Such information usually does not directly identify your personal information, but it can provide you with a more personalized network experience. We fully respect your privacy, so you can choose not to allow certain types of cookies. You only need to click on the names of different cookie categories to learn more and change the default settings. However, blocking certain types of cookies may affect your website experience and the services we can provide you.

  • Performance cookies

    Through this type of cookie, we can count website visits and traffic sources in order to evaluate and improve the performance of our website. This type of cookie can also help us understand the popularity of the page and the activity of visitors on the site. All information collected by such cookies will be aggregated to ensure the anonymity of the information. If you do not allow such cookies, we will have no way of knowing when you visited our website, and we will not be able to monitor website performance.

  • Essential cookies

    This type of cookie is necessary for the normal operation of the website and cannot be turned off in our system. Usually, they are only set for the actions you do, which are equivalent to service requests, such as setting your privacy preferences, logging in, or filling out forms. You can set your browser to block or remind you of such cookies, but certain functions of the website will not be available. Such cookies do not store any personally identifiable information.

Accept All

View Cookie Policy Details



How can we help you?


Get an Order help


Get a tech support