SDR Board Reference
Hardware Profile

XCZU5EV / AD9361
2×2 MIMO SDR Carrier Board

A Zynq UltraScale+ MPSoC carrier board built around the Analog Devices AD9361 RF transceiver — a switched six-band RF front end, onboard Wi-Fi/BT and GNSS, DDR4 and dual-port USB debug, all on a single compact PCB.

Zynq UltraScale+ MPSoC AD9361 2×2 MIMO 1 GB DDR4 Gigabit Ethernet Wi-Fi / BT (ESP32) u-blox GNSS
XCZU5EV AD9361 2x2 MIMO SDR board, top view
Fig. 1 — Board top side, as populated
00 · At a Glance

Board specifications

Processor
Xilinx / AMD Zynq UltraScale+ MPSoC
BGA784 package, quad Cortex-A53 + dual Cortex-R5 + Artix/Kintex-class PL fabric
RF Transceiver
Analog Devices AD9361
2×2 MIMO, integrated 12-bit ADC/DAC, tunable synthesizers
System Memory
2 × MT40A256M16 DDR4
~1 GB total, PS-attached DDR4 interface
Boot Storage
256 Mbit QSPI NOR + microSD
MT25QU256 flash plus TF-SD card slot
Ethernet
RTL8211E Gigabit PHY
RJ45 jack with integrated magnetics (HR911130C)
Wireless
ESP32 Wi-Fi/BT + u-blox GNSS
Onboard co-processor radio and GPS/GLONASS/Galileo/BeiDou receiver
RF Front End
6-band switched filter bank
400 MHz – 5.85 GHz coverage across RX1 / RX2
Power Input
12 V DC barrel jack
On-board regulation to 15+ rails via buck converters and LDOs
Debug
USB-C dual-UART + JTAG
CH334P hub feeds two CH340E bridges; 6-pin JTAG header
Files

Downloads

Full schematics, block diagram, and bill of materials for this board.

01 · Physical I/O

Front and bottom edge connectors

Reading directly off the board's silkscreen — what's actually populated on this unit.

Top edge — RF & antenna

WFWi-Fi / BT antenna. Feeds the onboard ESP32 wireless co-processor through a diplexer.
GPSGNSS antenna. Active-antenna feed into the u-blox MAX-M8 receiver.
RX1Receive channel 1. AD9361 RX1 path through the switched 6-band filter bank.
RX2Receive channel 2. Second AD9361 RX path — enables 2×2 MIMO reception or diversity.
TX2Transmit output. AD9361 TX path through a fixed wideband low-pass filter (not band-switched).

Bottom edge — power, data & debug

UARTHeader, 5-pin. Direct serial console access alongside the USB-C debug bridges.
12V VINDC barrel jack. Main board power input, fused, feeding the on-board regulator tree.
USB-CUSB 2.0 receptacle. Carries two virtual COM ports (ESP32 + PS debug UART) through an onboard USB hub.
JTAG6-pin header. VREF, GND, TCK, TDO, TDI, TMS — direct Xilinx JTAG programming/debug.
BOOT4-position DIP switch. Sets PS_MODE[3:0] to choose the MPSoC boot source.
02 · System Architecture

Simplified block diagram

How the major subsystems connect around the MPSoC.

WF
Wi-Fi/BT ant.
GPS
GNSS ant.
ESP32-C5
Wi-Fi / BT MCU
u-blox MAX-M8
GPS/GLONASS/Galileo/BeiDou
RX1 / RX2
SMA, filtered
6-Band Filter Bank
Mini-Circuits LC + RF switch
AD9361
2×2 MIMO RF transceiver
LPF
Wideband TX filter
TX2
SMA
Clock Subsystem
40 MHz VCTCXO + DAC trim + buffer
Zynq UltraScale+ MPSoC
ARM PS + programmable logic (LVDS TX/RX to AD9361)
DDR4
2× MT40A256M16, ~1 GB
QSPI Flash
256 Mbit boot
microSD
TF card slot
RTL8211E + RJ45
Gigabit Ethernet
USB-C Hub
Dual UART debug
GPIO / JTAG
Expansion headers
Reading the diagram: the AD9361 handles all RF up/down-conversion and hands digital I/Q samples to the MPSoC's programmable logic over an LVDS link; the ARM cores in the PS then run Linux, routing, and control software while the PL fabric handles time-critical baseband work.
03 · Core Components

Processing subsystem

RefPartFunction
U5Zynq UltraScale+ MPSoC (XCZU5EV, BGA784)Main SoC — quad-core ARM Cortex-A53 application processor, dual-core Cortex-R5 real-time processor, and FPGA programmable logic fabric. LVDS TX/RX lanes connect directly to the AD9361 for baseband I/Q streaming.
U50TCM811TERCTRVoltage supervisor generating the PS power-on-reset signal.
SW1Tactile switchManual system reset.
SW24-position DIP switchSets PS_MODE[3:0] boot-source pins (QSPI / SD / JTAG boot select).
J66-pin 2.54 mm headerJTAG: VREF, GND, TCK, TDO, TDI, TMS.
The board is documented across two related MPSoC variants — XCZU3EG and XCZU5EV — which are pin-compatible, letting the same PCB scale from a smaller to a larger amount of programmable-logic resource depending on the application.
04 · RF Signal Chain

RF front end

The AD9361 shares two receive chains and one transmit chain with the outside world through a switched filter bank and a set of RF transformers.

Core RF silicon
RefPartFunction
U2AD9361BBCZRF Agile Transceiver — 2×2 MIMO, integrated fractional-N synthesizers, 12-bit ADCs/DACs, tunable analog and digital filters.
T1, T2, T3TCM1-63AX+RF transformers (baluns) converting the AD9361's differential RX2/RX1/TX ports to single-ended signals for the filter and switch network.
U16, U19SKY13418-485LFRF switches selecting the active band's filter path for each receive chain.
Switched RX filter bank — 6 bands, RX1 & RX2
400–600 MHz
Sub-GHz ISM (e.g. 433 / 470 MHz)
LFCN-630+
800–900 MHz
Cellular / 868–915 MHz ISM
HFCN-740+ · LFCN-1000+
2400–2460 MHz
2.4 GHz ISM / Wi-Fi
HFCN-2100D+ · LFCN-2500+
2450–2510 MHz
2.4 GHz ISM, alternate slot
HFCN-2275+ · LFCN-2600+
5150–5250 MHz
5 GHz U-NII-1 Wi-Fi
HFCN-4400+ · LFCN-5500+
5650–5850 MHz
5.8 GHz ISM
HFCN-5050+ · LFCN-5850+

Each band is realized as a pair of Mini-Circuits LC filters (a high-pass plus a low-pass section forming a band-pass), switched in and out per receive chain by the SKY13418 RF switches. The TX2 output bypasses the switched bank entirely, using a single fixed low-pass filter (LFCN-1400+) for simple wideband transmit.

Regulatory note: which of these bands you may legally transmit or receive on depends on your region, license class, and antenna. This is a description of the hardware's capability, not a statement of where it's authorized to operate.
05 · Core Components

Memory & storage

RefPartFunction
U3, U4MT40A256M16 DDR4Two DDR4 SDRAM chips forming the PS-attached system memory — roughly 1 GB total.
U34MT25QU256ABA1EW7256 Mbit QSPI NOR flash — primary boot device for the MPSoC.
J1microSD slot (TF-SD)Removable-card boot / storage option.
U39TXS02612RTWRVoltage-level translator between the SD card's 3.3/1.8 V I/O and the MPSoC's SD controller.
U30TPS51200DDR4 VTT/VREF termination regulator.
06 · Core Components

Wireless, networking & GNSS

RefPartFunction
U29ESP32-D0WDQ6-V3Wi-Fi / Bluetooth co-processor — an independent MCU + radio, bridged to the MPSoC over UART for network connectivity or out-of-band control.
U27DPX165950DT-8060A12.4 GHz / 5 GHz diplexer feeding the ESP32's dual-band antenna port from the WF SMA connector.
U25MAX-M8C-0 (u-blox)Concurrent GNSS receiver — GPS, GLONASS, Galileo and BeiDou — providing position and a PPS timing reference.
U6RTL8211E-VBGigabit Ethernet PHY transceiver.
U7HR911130CRJ45 jack with integrated magnetics and status LEDs.
U42CH334PUSB hub controller — splits the single USB-C port into multiple internal USB endpoints.
U41, U43CH340E ×2USB-to-UART bridges, exposing the ESP32 console and the MPSoC PS debug UART as two separate virtual COM ports.
07 · Core Components

Clocking

A clean, adjustable reference clock matters more for an SDR than almost any other subsystem — frequency and phase noise on this line set a hard ceiling on RF performance.

RefPartFunction
X540 MHz VCTCXOVoltage-controlled temperature-compensated crystal oscillator — the master RF reference clock for the AD9361.
U45LTC2630ACSC6-HZ1212-bit DAC that trims the VCTCXO's control voltage for fine frequency calibration.
U46CDC3RL02YFPRLow-jitter clock buffer, fanning the reference clock out to the MPSoC and other clock consumers.
X233.33 MHz active oscillatorMPSoC PS reference clock.
X1, X3, X625 / 48 / 12 MHz crystalsLocal reference clocks for the ESP32, USB hub, and USB-UART bridges respectively.
08 · Core Components

Power architecture

A single 12 V input is stepped down and regulated into more than a dozen individual rails feeding the MPSoC core, RF analog circuitry, DDR4, and I/O domains separately.

12 V input
Main DC barrel jack, fused, feeding every downstream regulator on the board.
J2
Multi-rail buck controller
Generates the PL core (0.9 V), DDR (1.2 V), auxiliary PS, and 3.3 V rails from the 12 V input.
U1 · EA3059QDR
MPSoC core buck converters
Additional synchronous buck stages supplying VCCINT and the PS internal core rails.
U8, U9 · JW5068A
VCCAUX buck stage
Auxiliary MPSoC supply rail.
U31 · SCT2230CTVBR
Integrated PoL module
Compact point-of-load power module for an additional low-voltage rail.
U44 · TPS82130SILR
RF analog LDOs
Low-noise linear regulators cleaning up MGTAVCC / MGTAVTT and other sensitive analog supplies feeding the AD9361 and MPSoC transceivers.
U37, U38 · ADP1755
General-purpose LDOs
3.3 V / 1.8 V / adjustable output regulators distributed across the Ethernet PHY, GNSS, Wi-Fi, and USB subsystems.
SPX3819 ×5, ME6217, TPS74801 ×4
Power-on reset supervisor
Holds the MPSoC in reset until supply rails are stable.
U50 · TCM811TERCTR
09 · Bring-up

Bring-up & debug interfaces

JTAG programming
6-pin 2.54 mm header (J6) for direct Xilinx JTAG programming and debug, independent of the USB-C link.
VREFGNDTCKTDOTDITMS
Boot mode select
4-position DIP switch (SW2) sets the PS_MODE[3:0] pins that tell the MPSoC where to boot from — QSPI flash, SD card, or JTAG.
MODE0MODE1MODE2MODE3
USB-C dual console
A single USB-C cable exposes two independent virtual COM ports through an onboard hub — one for the ESP32 co-processor, one for the MPSoC PS debug UART.
Status indicators
An FPGA_DONE LED confirms the programmable logic bitstream has loaded; a PS status LED and the RJ45's integrated link/activity LEDs cover the rest.
10 · Software

BATMAN-adv & OpenWiFi bring-up

Two separate layers get confused a lot, so it's worth being precise about which is which before flashing anything.

BATMAN-adv is a Layer-2 mesh routing protocol — a standard Linux kernel module. It doesn't transmit RF by itself; it rides on top of whatever network interface you give it (Ethernet, or a Wi-Fi–style interface). OpenWiFi is what actually turns the AD9361 into an over-the-air 802.11 radio, exposing a normal wlan0/sdr0 interface. For a true wireless MANET over this board's RF front end, you need OpenWiFi (or an equivalent mac80211 driver) running first, with BATMAN-adv attached to the interface it creates.
STEP 1Get Linux running on this exact board

This is a custom carrier board, not one of Analog Devices' own listed reference designs — so there is no prebuilt "ADI Kuiper Linux" image for it. Kuiper only ships pre-built boot files for ADI's specific supported hardware projects (Zedboard, ZC706, ADRV9361-Z7035, ZCU102+FMCOMMS, ADALM-Pluto, etc.) — this board's own MPSoC part, DDR4 layout, and AD9361 wiring aren't among them, so a stock Kuiper .img is unlikely to boot correctly here.

Two realistic paths:

  • Ask the board vendor for a PetaLinux/Yocto BSP or pre-built SD image for this specific design — if one exists, it's by far the fastest and safest route.
  • Build your own PetaLinux/Yocto image targeting this MPSoC, using Analog Devices' hdl and linux repositories as a starting point for the AD9361 driver, then adapting the device tree to this board's actual DDR4 parts, RTL8211E PHY, and pin mapping.

Either way, boot from the microSD card first (set the SW2 DIP switch to the SD boot position — see Bring-up & Debug above). SD boot never touches the onboard QSPI flash, so a bad image just means reflashing the card, not recovering bricked hardware.

STEP 2Enable BATMAN-adv (works immediately, even over Ethernet)

BATMAN-adv has shipped in the mainline Linux kernel since 2.6.38 — no ADI- or board-specific patch is required. As long as your kernel was built with CONFIG_BATMAN_ADV=m (the default in most Yocto/PetaLinux and Debian kernel configs), the module is already there.

enable-batman-adv.sh
# Install the userspace control tool
apt update && apt install -y batctl build-essential

# Load the kernel module
modprobe batman-adv

# Attach it to an existing network interface — eth0 works today,
# over the board's RTL8211E Gigabit Ethernet port, for bench testing
batctl if add eth0
ip link set up dev bat0
# Expected output when a second node is reachable:
batctl n   →   lists discovered mesh neighbors

This proves BATMAN-adv itself works, but it's routing over a wired link — it isn't yet the wireless MANET. For that, batctl if add needs to point at a wireless interface instead of eth0, which is what Step 3 provides.

STEP 3Bring up OpenWiFi for the actual RF mesh link (advanced)

OpenWiFi (open-sdr/openwifi) is an open-source IEEE 802.11a/g/n baseband — part FPGA logic, part Linux driver — that makes the AD9361 behave like a normal mac80211 Wi-Fi card. It officially supports six specific reference platforms:

  • Zedboard + FMCOMMS2/3/4
  • Xilinx ZC706 + FMCOMMS2/3/4
  • ADRV9361-Z7035 SOM + ADRV1CRR-BOB carrier
  • ADRV9361-Z7035 SOM + ADRV1CRR-FMC carrier
  • Low-cost Zynq-7020 + AD9361 board
  • ZCU102 (Zynq UltraScale+) + FMCOMMS2/3/4

This board isn't one of them — it has an onboard AD9361 wired directly to the MPSoC rather than an FMC daughtercard, so getting OpenWiFi running here means porting it: retargeting the openwifi-hw Vivado project to this MPSoC part number and this board's specific AD9361 LVDS/GPIO pin mapping, building a new bitstream, and following their published porting guide. Several hobbyist boards with an onboard (non-FMC) AD9361 and a Zynq-7020 — ANTSDR, the HamGeek P210, LibreSDR — have done exactly this kind of port successfully, so it's a realistic project, just not a "flash an image and go" one on unlisted hardware.

openwifi-porting-overview.sh
# 1. Get the FPGA and driver source
git clone https://github.com/open-sdr/openwifi-hw
git clone https://github.com/open-sdr/openwifi

# 2. Follow the README's porting guide to add a new board target
#    under openwifi-hw/boards/ — matching this MPSoC part number
#    and the AD9361 LVDS/control pin mapping from the schematic

# 3. Build the bitstream in Vivado, export hardware + device tree,
#    then build the openwifi Linux image from scratch per their guide

# 4. Once booted, OpenWiFi brings up a standard wireless interface:
sdr0   →   appears exactly like any other mac80211 Wi-Fi card
STEP 4Putting it together — mesh over the air

Once OpenWiFi is running and sdr0 exists, point BATMAN-adv at it instead of Ethernet, and optionally bridge both together so wired and wireless clients share the same mesh:

bring-up-manet.sh
# Attach BATMAN-adv to the OpenWiFi radio interface instead of eth0
modprobe batman-adv
batctl if add sdr0
ip link set dev sdr0 up
ip link set dev bat0 up

# Optional: bridge the mesh with the wired Ethernet port too
ip link add name br0 type bridge
ip link set dev eth0 master br0
ip link set dev bat0 master br0
ip link set dev br0 up
Regulatory note: transmitting an 802.11 baseband over open-air RF through OpenWiFi is subject to your region's spectrum regulations and any licensing requirements for the band you unlock and use. This page describes the hardware's technical capability, not where or how it's authorized to operate.