12Gb Enterprise Level High-Performance VPN Concentrator with Powerful Quad-Core Processor
The Vigor 3912 is a Multi-WAN VPN Router designed for high performance and capable of handling the requirements of large and complex networks, with applications including Remote Access, Firewalling, Load-Balancing and Failover.
Featuring 12 LAN and WAN interfaces in total, 4 dedicated LAN ports and 8 switchable ports that can operate as LAN or WAN ports to fit your network requirements.
With up to 12Gb/s of NAT & Firewall throughput, the Vigor 3912 is suitable for the most demanding and bandwidth intensive SME applications. Each of the WAN ports on the Vigor 3912 can be grouped together to provide Load Balancing or operate as Failover or Backup WAN connections.
Based on the familiar DrayOS platform, the Vigor 3912 combines high performance and capacity with DrayTek's traditional ease of use and comprehensive feature set.
For multi-tenant or departmental flexibility, the Vigor 3912 will support multiple LAN IP subnets, together with VLAN capabilities and user management, providing access to WAN resources only to the appropriate users or departments, as well as maintaining infrastructure efficiency.
Powerful 12Gb Capable Internet Gateway
The Vigor 3912 is specially designed to cope with the throughput demands of large networks and as a VPN concentrator, has suitable processing power to meet the demands of hundreds of active VPN tunnels.
Firewall and NAT throughput of the router can reach over 12 Gigabits per second when connected via multiple interfaces including the 10 Gigabit SFP+ ports which help to spread over multiple Internet connections with Load Balancing.
The Vigor 3912 accelerates LAN-to-LAN IPsec VPN throughput up to 5 Gigabits per second, with up to 500 active VPN tunnels it can provide enough throughput to each tunnel, without becoming a bottleneck to the user experience.
The SSL VPN capabilities of the Vigor 3912 are also increased, with over 3 Gigabit per second of total SSL VPN throughput, suitable to cater to the bandwidth requirements of up to 200 active SSL VPN users.
High-Performance VPN Concentrator
A feature central to DrayTek routers is its VPN (Virtual Private Networking) capabilities. A VPN enables you to link remote offices and branch offices back to HQ, or home-based/mobile teleworkers back to your office.
Once connected, they have access to your office/remote resources through a secure encrypted tunnel allowing remote desktop, file sharing and seamless access to other resources and devices.
The Vigor 3912 allows you to have up to 500 simultaneous VPN tunnels to remote offices or teleworkers, with up to 5Gbps of VPN throughput.
It supports all common industry standard protocols, encryption types and authentication methods (see specification tab for full support list). Teleworkers can authenticate directly with your LDAP server if preferred.
The Vigor 3912 supports VPN trunking; this allows you to create tunnels down multiple WAN connections to a remote site in order to increase bandwidth. VPN trunking also provides failover (backup) of your VPN route down a secondary WAN connection.
You can learn more about DrayTek VPN here. Teleworkers can also use 2FA (Two factor authentication) such as Mobile One-Time Passwords (MOTP) or Time-based One-time Password (TOTP).
Load Balancing - Ultimate Resiliency & Reliability
The Vigor 3912 features Multi-WAN connectivity with up to 8 WAN interfaces:
- 4 RJ-45 1GbE ports
- 2 RJ-45 2.5GBase-T (backwards compatible with 1GbE) ports
- 2 SFP+ module slots
The Ethernet and 2.5GBase-T ports can be connected to:
- Leased Lines
- DSL modems (e.g. Vigor 166) for ADSL 2+, VDSL and G.Fast connectivity
- 4G and LTE through the Vigor 2620Ln in LTE bridge mode
- Cable modems
- Any other Ethernet-based Internet feed
The SFP+ ports, when fitted with an optional SFP+ or SFP module, can be linked to 1GbE or 10GbE uplinks, through Fibre or any other link type with a suitable transceiver.
Fibre is of particular use for longer distance deliveries, beyond the range of standard Ethernet, or where copper connections cannot be used.
These multiple WAN interfaces can be used either for WAN-Backup or Load Balancing with Policy-based Routing giving you full control of where and how traffic is routed. Load-balancing or failover supports IPv4 only currently (not IPv6).
WAN-Backup provides contingency (redundancy) in case of your primary Internet connection or ISP suffering temporary outage. Internet Traffic will be temporarily routed via the secondary Internet access. When normal services are restored to your primary Internet line, all traffic is switched back to that.
Flexible WAN & LAN Ports
The Vigor 3912 features 12 physical ports in total, with 8 ports that can be switched between LAN and WAN usage to fit your network requirements, with many combinations being possible, including:
- 8 WAN interfaces with 4 LAN ports
- 1 WAN interface with 11 LAN ports
These configurable LAN or WAN interfaces consist of:
High Availability
For even greater resilience, the Vigor 3912 provides High Availability (HA), with both a primary and secondary router able to provide connectivity to your network and subnets.
In the event of the primary unit failing, the secondary unit will take its place on the network, automatically switching over to resume Internet, routing and VPN connectivity with no intervention required. This can remove the possibility of a single point of failure within your routers.
With Config Sync, the two routers are managed as a single unit, so that any changes made to the primary router will automatically propagate to the secondary router, ensuring it’s ready to take over at any time.
Read more about DrayTek High Available here.
Manage Multiple Networks
The Vigor 3912 features a hugely flexible local network interface, with the router managing up to 100 separate Local Networks (or Subnets) through the use of 802.1Q VLAN Tags. Each network can be used in NAT or Routing modes, containing anywhere from 253 to 4093 devices each, with larger subnet support.
Each of the 100 VLAN subnets can be isolated from each other, for example to feed different companies or departments but keeping their local traffic completely separated. With Inter-LAN routing, specified networks can be allowed to communicate with each other or share resources, with the router’s Firewall controlling access.
To take full advantage of VLAN tagging, the Vigor 3912 can be connected to any one of the switches from the DrayTek VigorSwitch range such as the VigorSwitch PQ2200xb.
For more detailed explanation about VLANs click here.
Robust & Comprehensive IPv4 / IPv6 Firewall
Security is always taken seriously with DrayTek routers. The firewall protects against attacks including DoS (Denial of Service) attacks, IP-based attacks and access by unauthorised remote systems.
The DrayTek object-based firewall allows even more setup flexibility than ever, enabling you to create combinations of Firewall rules and Content Filtering to suit a large office environment, applying Content Filtering to the whole network, only specified devices or just the network that guests can connect to.
The Vigor 3912 supports IPv6 - the successor to the current IPv4 addressing system that has been used since the Internet was first created. IPv6 can be provided directly by your ISP, but if your WAN interfaces do not (yet) support IPv6, the Vigor 3912 also supports IPv6 broker/tunnel services to provide IPv6 access using either TSPC or AICCU via 3rd party IPv6 providers over each of its interfaces. To learn more about IPv6, you read our detailed IPv6 guide here.
The advanced networking features of the Vigor 3912, such as the object-based Firewall, Quality of Service, Content Filtering and VLANs support both IPv4 and IPv6 networks.
10GbE SFP+ and 2.5GbE Ports
The Vigor 3912 goes beyond 1 Gigabit throughput per port, with both 2.5GbE RJ-45 (copper) ports and 10GbE SFP+ ports.
The faster 10 Gigabit uplink capability allows you to make high bandwidth links to both WAN connections and LAN devices.
10GbE capable switches such as the VigorSwitch PQ2200xb allow you to expand the router’s ports without the risk of creating a bottleneck. Connect other 10GbE capable devices such as Network Attached Storage and Servers to provide more throughput to your network.
The SFP+ ports provide compatibility with your choice of SFP / SFP+ modules (not included) and therefore the most appropriate medium for your application.
Connect a passive Direct Attach SFP+ cable such as the DrayTek DAC-CX10-01M to the SFP+ module port of 1Gbps/10Gbps capable Switches, Network Attached Storage and Servers, for a cost effective, up to 10Gbps network link.
The 2.5GbE ports can be connected to other devices that support the 2.5GbE standard over standard Cat5e copper cabling, or as they are backwards-compatible with 1GbE, they can be used simply to expand the number of available RJ-45 ports on the router.
Web Content Filtering with DNS Filter
The content control features of Vigor routers allow you to set restrictions on web site access, blocking download of certain file or data types, blocking specific web sites with whitelists or blacklists, blocking IM/P2P applications or other potentially harmful or wasteful content. Restrictions can be per user, per PC or universal and according to time schedules.
Content filtering can also block sites using HTTPS/SSL where URLs are encrypted (and normal routers cannot block).
Using the GlobalView service, you can block whole categories of web sites (e.g. gambling, adult sites etc.), subject to an annual subscription, which is continuously updated with new or changed site categorisations or sites which have become compromised (such as infected with Malware). A free 30-day trial is included with your new router.
DrayTek SSL VPN
The Vigor 3912 supports up to 200 DrayTek SSL VPN tunnel connections, with over 3Gbps of throughput available.
These encrypted tunnels link your teleworkers or remote DrayTek Vigor routers back to your main office using SSL/TLS technology - the same encryption that you use for secure web sites such as your bank.
Site to site VPN tunnels can connect branch offices to a main office, with DrayTek SSL VPN encryption securing the connection between the two offices, a TLS encrypted HTTPS tunnel which can be more secure than PPTP, and easier to configure than an IPsec VPN tunnel.
Teleworkers can easily create a secure DrayTek SSL VPN tunnel to the DrayTek Vigor 3912 using the DrayTek Smart VPN Client app, which is free and supports Windows OS, macOS, Apple iOS (iPad, iPhone) and Android.
SSL VPN is simple to configure, providing a more secure alternative to Point to Point Tunneling Protocol (PPTP VPN); which has known weaknesses and is no longer considered to be secure. Setup is similar to a PPTP VPN tunnel in that it authenticates with an SSL VPN Username and Password.
You can learn more about DrayTek SSL VPNs here.
Central Management with VigorACS
The Vigor 3912 (along with most other DrayTek routers, Access points and switches) can be centrally managed by our VigorACS central management platform.
This scalable solution provides visibility, control and reporting of your entire DrayTek product estate, ideal for dealers/SIs managing customers' devices or any user who wants to know what's going on with their devices. VigorACS also provides features like automated/bulk firmware updates, VPN management and alarms for connectivity or other issues.
For full details of VigorACS, click here.
DrayDDNS – Dynamic DNS with LetsEncrypt support
DrayTek provides a free Dynamic DNS address to each Vigor 3912 router, allowing you to link the router's current IP address to a memorable "drayddns.com" hostname, such as "vigor3912.drayddns.com".
This address automatically updates whenever the Internet connection's IP changes, so if one WAN’s IP address allocation is dynamic, or the IP changes when switching from the primary WAN connection to a backup, you can easily locate and access your Vigor 3912 router. Just use the hostname to access the router's VPN services, management and any other services you have made accessible through the router.
The Vigor 3912 can also authenticate your DrayDDNS hostname with free SSL/TLS certificates provided by LetsEncrypt, the router manages the certificate process and keeps the certificate up to date and ready for use with SSL VPN and other services.
Quality of Service & Bandwidth Control
Prioritise latency-sensitive applications on your network with Quality of Service.
Use 4 separate queues to give priority to servers & PCs (IP address), services such as VoIP or DNS, or packet tagging used by IP phones with 802.1p and DSCP support
Auto Voice VLAN allows the router to automatically prioritise VoIP calls as they pass through the router without additional configuration.
Control throughput with Bandwidth Limit, by setting speed limits for all clients individually, groups of IPs, or a shared bandwidth limit for a whole subnet, such as a Guest network.
Central AP & Switch Management
The Vigor 3912 can manage DrayTek VigorAP access points and VigorSwitch switches connected locally to the router. This enables you to centrally control, manage and administer multiple AP & Switch devices installed around your building/campus from just the one router.
Central AP Management
The DrayTek router operating as the wireless controller can provision up to 50 DrayTek VigorAP access points with Central AP Management profiles, with an option to Auto Provision - auto configuring newly installed VigorAP access points with the Auto Provisioning profile, upon initial connection to the DrayTek Vigor router's network.
Central Switch Management
DrayTek VigorSwitch switches can be provisioned and managed through the router with DrayTek’s Central Switch Management system, which allows you to:
- Easily provision VLAN configuration and other port settings directly from the router.
- Set bandwidth rate limits and schedules for individual ports.
- Log switch events for alert notifications if network problems occur
- At a glance see the devices connected on your network with a virtual topology.
Provision & Manage VigorAPs with a DrayTek Vigor router
For further details of the central management feature, click here.
Data Flow Monitor
Live view of Internet bandwidth usage, showing both WAN usage and which users are using bandwidth. Use the Block button to temporarily stop Internet access to disruptive clients:
CSM - Web Content Filtering, URL Filtering & App Enforcement
Control access to the Internet, either for all users or specific networks / clients only. Category based filtering greatly simplifies the task of filtering Internet access:
Border Gateway Protocol
Automate routing setup between networks with BGP:
Policy-based Routing
Configure Route Policy rules to control how outbound traffic is routed. Send traffic from specified LAN IPs, to Internet domains (i.e. www.bbc.co.uk) through a specific WAN interface, VPN or LAN Gateway:
Technical Specification (UK Hardware Spec.)
-
Key Specifications
- Multi-WAN Router with over 12Gbps NAT Throughput
- 8x WAN/LAN Switchable Ports & 4x fixed Ethernet LAN Ports
- 2x 10GbE SFP+ and 2x 2.5GbE for WAN/LAN
- Up to 5Gbps Total IPSec VPN Throughput
- Up to 3.5Gbps Total SSL VPN Throughput
- 500 LAN-to-LAN & Remote Teleworker VPN Tunnels
- 200 DrayTek SSL VPN or OpenVPN Tunnels
- Up to 100 LAN Subnets with VLANs (Port-based / 802.1q)
- SPI Firewall and Content Filtering
- Optional VigorCare Available
- Compatible with VigorACS Central Management Platform
Physical Interfaces | |
---|---|
WAN/LAN Switchable Port | 2x 10G/1G SFP+ Fiber Slot (P1-2) 2x 2.5G/1G/100M/10M Ethernet, RJ-45 (P3-4) 4x 1G/100M/10M Ethernet, RJ-45 (P5-8) |
Fixed LAN Port | 4x 1G/100M/10M Ethernet, RJ-45 (P9-12) |
USB Port | 2x USB 3.0 |
Console Port | 1x RJ-45 (RS-232) |
Button | 1x Factory Reset |
Performance | |
---|---|
NAT Throughput | 12.5Gb/s |
IPSec VPN Performance | 5000Mb/s |
SSL VPN Performance | 3500Mb/s |
WireGuard VPN Performance | 900Mb/s |
NAT Sessions | 1000K |
Max. Concurrent VPN Tunnels | 500 |
Max. Concurrent SSL VPN | 200 |
Internet Connection Features | |
---|---|
IPv4 | PPPoE, DHCP, Static IP |
IPv6 | PPP, DHCPv6, Static IPv6, 6rd, 6in4 Static Tunnel |
802.1p/q Multi-VLAN Tagging | |
Multi-VLAN/PVC | |
Load Balancing | IP-based, Session-based |
WAN Active on Demand | Link Failure, Traffic Threshold |
Connection Detection | PPP, Ping |
Dynamic DNS | |
DrayDDNS | with LetsEncrypt Certificate support |
LAN Management Features | |
---|---|
VLAN | 802.1q Tag-based, Port-based |
Max. Number of VLAN | 100 (NAT or Routing mode selectable per LAN interface) |
DHCP Server | Multiple IP Subnet, Custom DHCP Options, Bind-IP-to-MAC |
IP Pool Count | Up to 4093 per LAN Subnet |
LAN IP Alias | |
Wired 802.1x Port Authentication | |
PPPoE Server | |
Local DNS Server | |
Conditional DNS Forwarding | |
Port Mirroring / Packet Capturing | |
Hotspot Web Portal | |
Hotspot Authentication | Click-Through, Social Login, SMS PIN, RADIUS, External Portal Server |
Networking Features | |
---|---|
Routing | IPv4 Static Routing, IPv6 Static Routing, Inter-VLAN Routing, RIP v1/v2/ng, OSPFv2, BGP |
Policy-based Routing | Match via: Protocol, IP Address, Port, Domain Name, Country Direct Traffic via: WAN Interface, LAN Interface, NAT/Routing, LAN Gateway, VPN Tunnel Failover with optional Failback to: WAN/LAN, VPN, Route Policy, LAN Gateway |
High Availability | Active-Standby, Hot-Standby |
DNS Security (DNSSEC) | |
Multicast | IGMP Proxy, Bonjour |
Local RADIUS server | |
SMB File Sharing | (Requires external storage) |
VPN Features | |
---|---|
LAN-to-LAN | |
Teleworker-to-LAN | |
Protocols | PPTP, L2TP, L2TP over IPsec, IPsec IKEv1, IKEv2, IPsec-XAuth, IKEv2 EAP, GRE, DrayTek SSL, OpenVPN, WireGuard |
User Authentication | Local, RADIUS, LDAP, TACACS+, mOTP, TOTP |
IKE Authentication | Pre-Shared Key, X.509, XAuth, EAP |
IPsec Authentication | SHA-512, SHA-256, SHA-SHA-1, SHA-256, MD5 |
Encryption | MPPE, DES, 3DES, AES |
VPN Trunk (Redundancy) | Load Balancing, Failover |
Single-Armed VPN | |
NAT-Traversal (NAT-T) |
Firewall & Content Filtering Features | |
---|---|
NAT | Port Redirection (520 rules) Open Ports (260 rules, 10 port ranges per rule) Port Triggering, DMZ Host, UPnP Server Load Balance, Fast NAT, Port Knocking - NEW! |
ALG (Application Layer Gateway) | SIP, RTSP, FTP, H.323 |
VPN Pass-Through | PPTP, L2TP, IPsec |
IP-based Firewall Policy | |
User-based Firewall Policy | with Data and Time Quota Management |
Content Filtering | App Enforcement - application based URL Content Filtering DNS Keyword - URL or Category Web Category Filtering - Includes free 30-day trial (subscription required: Group S, URLR-S, 4.3.2.5 or later firmware) |
DoS Attack Defense | |
Spoofing Defense |
Bandwidth Management Features | |
---|---|
IP-based Bandwidth Limit | |
IP-based Session Limit | |
QoS (Quality of Service) | TOS, DSCP, 802.1p, IP Address, Service Type, App QoS |
VoIP Prioritization |
Router Management Features | |
---|---|
Local Service | HTTP, HTTPS, Telnet, SSH, FTP, TR-069 |
Config File Export & Import | |
VigorACS Central Management | |
Access Point Management | up to 50 DrayTek VigorAPs |
Switch Management | up to 30 DrayTek VigorSwitches |
Firmware Upgrade | TFTP, HTTP, TR-069 |
2-Level Administration Privilege | |
Access Control | Access List, Brute Force Protection |
Syslog | |
Notification Alert | SMS, E-mail |
SNMP | v1, v2c, v3 |
Operating Requirements | |
---|---|
Power | AC 100~240V, 50/60Hz directly to unit |
Max.Power Consumption | 35 watts |
Operating Temperature | 0 to 45 °C |
Storage Temperature | -10 to 55 °C |
Operating Humidity (non-condensing) | 10 to 90% |
Physical Specifications | |
---|---|
Dimensions | Depth: 285mm Width: 443mm Height: 45mm |
Weight | 3.76 kg |
Rack Mountable | Mounting Kit Included, 1U Rack Height |
Box Contents | |
---|---|
Vigor 3912 Series Router | |
Quick Start Guide | |
Cat-5e RJ-45 Network Cable | |
Rackmount Kit | |
RJ-45 to RS-232 Adapter | |
Silver RJ-45 Serial Cable | |
IEC C13 Power Cord |
Warranty | |
---|---|
Standard Warranty | Two (2) Years, RTB |
Software security updates |
Five (5) years after the EOL notification. Please note that this only applies to products sold in the UK |
VigorCare Extended Warranty |
VigorCare D3 3 Year Subscription: VCARE-D3 VigorCare D5 5 Year Subscription: VCARE-D5 |
ROHS, UKCA & CE Compliant |
All specifications are subject to change without notice.
Copyright © 2024 DrayTek