1U Edge Router -- the only device in the roster that can hold the ISP uplink. Everything the rack does that touches the outside world routes through whichever router owns that connection.
One 10G WAN port, two LAN ports, real DHCP server support, 10Gbps max throughput. Enable its DHCP server and wire client devices to its LAN side (directly or through a switch) to actually hand out working IP addresses.
No IP = no service, full stop -- a device with no address from a real DHCP server can't run a hosted game, mine crypto usefully, rent AI compute, or do anything else that depends on being reachable.
Also carries real defensive stats (128 firewall rules) even without a dedicated Firewall device sitting in front of it, though a real Firewall device's deep packet inspection goes further for Heat purposes.
Tip: the ISP connection itself is an "invisible uplink" the same way the Residential Grid is for power -- the router needs its WAN port explicitly wired to it before anything downstream is actually online, not just powered.
VPN tunnels start at 0 (edit the stat in this router's own Inspector panel to provision some) -- once this router has at least 1 configured and is powered on, every terminal in this rack can run racks / rackscan <id> / ping against your OTHER owned racks too, no cable required. See the Rack-to-Rack Terminal Access section for the full flow.