Vigor 2860 ADSL/VDSL Router Firewall Overview The Vigor 2860 is Draytek’s new router/firewall which can support either ADSL or VDSL (BT Infinity/FTTC), making the Vigor 2860 ideal for users with ADSL now who may wish to upgrade to VDSL later. Alternative WAN ports can instead provide connectivity to Ethernet feeds, secondary x DSL modems or a 3G cellular service using a USB (Universal Serial Bus) adaptor. This latest router series
Includes:: support for professional features such as VLAN tagging & Gigabit Ethernet. The Vigor 2860 is packed with professional-level features, offering truly comprehensive DSL connectivity & security. The V2860 is compatible with all UK variants of ADSL (including ADSL2+ & Annex M), VDSL & VDSL2, the Vigor 2860 can also be used for cable-modem, leased line & EFM applications using its Gigabit Ethernet WAN port. On VDSL, the Vigor 2860 supports the very latest services for speeds up to 80 Mb/s (depending on line quality & length). A 6-port Gigabit Ethernet switch on the LAN side provides high speed connectivity for your server, other local PCs or for uplink to a larger Ethernet switch. The V2860 comes with A superbly comprehensive set of security features including web application controls, content filtering & an object based firewall management system. Runs on either ADSL or VDSL The Vigor 2860's built in DSL interface will connect to either an ADSL or VDSL line. If you have a second line (of either type) you can add an additional modem (or your existing modem from your other line) to the Vigor 2860's Ethernet WAN ports. You can set the two lines up in load balancing mode, where traffic is split across both of them, or into failover mode, where the other DSL line only kicks-in if your primary DSL line fails (or vice versa). ADSL makes a particularly good method of failover for VDSL because they are delivered differently. VDSL service is provided & powered by a cabinet in your street
- that's where the line terminates. ADSL service, on the other h&, comes all the way from your local exchange, which coul be miles away & is powered from there. That means that if your street's VDSL cabinet is damaged, its DSLAM fails or you lose power to your street, you lose VDSL, but your ADSL line comes via a different method & route, so it's unlikely that both would be affected. These failover methods can also be used instead for the other WAN ports on the router (Ethernet or 3G). Robust & Comprehensive Firewall Security is always a serious consideration with Dray Tek routers. The firewall protects against attacks including Do S (Denial of Service) attacks, IP-based attacks & access by unauthorised remote systems. Wireless, Ethernet & VPN are also protected by various protection systems. The latest ' Version 3' Dray Tek object-based firewall allows even more setup flexibility than ever, enabling you to create combinations of users, rules & restrictions to suit multi-departmental organisations. The Vigor 2860 now also allows selective direction firewall rules of LAN to WAN, WAN to LAN or LAN to VPN. In addition, Qo S (Quality of Service Assurance) can now be selectively applied to specific users. IPv 6
- Next Generation Internet Routing The Vigor 2860 supports IPv 6
- the successor to the current IPv 4 addressing system that has been used since the Internet was first created. IPv 4 address space is full up & IPv 6 allows for much more efficient routing & a larger address space. IPv 6 is supported both from your own ISP, but if your ISP does not (yet) support IPv 6, the Vigor 2860 also supports IPv 6 broker/tunnel services to provide IPv 6 access using either TSPC or AICCU via 3rd party IPv 6 providers. Web Content Filtering The content control features of the Vigor 2860 means that you can set restrictions on web site access, blocking download of certain file or data types, blocking specific web sites with whitelists or blacklists, blocking IM/P2P applications or other potentially harmful or wasteful content. Restrictions can be per user, per PC or univeral. Using Dray Tek's Global View service, you can block whole categories of web sites (e.g. gambling, adult sites etc.), subject to an annual subscription to the Globalview service, which is continuously updated with new or changed site categorisations or sites which have become compromised (such as infected with Malware). A free 30-day trial is included with your new router. WAN Load Balancing & Backup The Vigor 2860 features three methods of WAN connectivity
- ADSL/VDSL, Ethernet (Gigabit, switchable with LAN6) & a USB (Universal Serial Bus) port for connection of a 3G modem. The Ethernet port can connect to a second ADSL modem (e.g. Vigor 120), a cable modem or any other Ethernet-based Internet feed. The multiple WAN interfaces can be used either for WAN-Backup or load balancing. Load-balancing or failover supports IPv 4 only currently. WAN-Backup provides contingency (redundancy) in case of your primary ADSL line or ISP suffering temporary outage). Internet Traffic will be temporarily routed via the secondary Internet access. When normal services are restored to your primary ADSL line, all traffic is switched back to that. If you don't have VDSL or ADSL, the Ethernet WAN port can instead be used as your primary/only Internet connection (using NAT) so the same router can be used regardless of whether you have x DSL or Ethernet Internet connections currently. The USB (Universal Serial Bus) port provides Internet connectivity (main, backup or load balanced) by connecting to a compatible USB (Universal Serial Bus) modem (or cellphone) for access to the high speed 3G cellular networks from UK providers such as Vodafone, O2, 3 & EE. If you don't have ADSL at all, the USB/3G access method can be used as your primary/only Internet connection, ideal for temporary locations, mobile applications or where broadband access is not available. In addition you can instead connect a compatible analogue modem to use analogue dial-up connections for failover in the event of your broadband failing. VPN
- Linking remote offices, HQ, tele-workers & mobile staff A feature central to Dray Tek routers is the VPN (Virtual Private Networking) features. A VPN enables you to link two remote offices, branch offices back to HQ or home-based/mobile tele-workers back to your office. Once connected, they have access to your office/remote resources through a secure encrypted tunnel allowing remote desktop, file sharing & seamless access to other resources & devices. The Vigor 2860 means that you can set up up to 32 simultaneous VPN tunnels to remote offices or tele-workers. The Vigor 2860 supports all industry standard protocols, including encryption & authentication methods. Tele-workers can authenticate directly with your LDAP server if preferred. The Vigor 2860 supports VPN trunking; this means that you can create tunnels down multiple WAN connections to a remote site in order to increase bandwidth. VPN trunking also provides failover (backup) of your VPN route down a secondary WAN connection. The Vigor 2860 also supports SSL VPN. These are encrypted tunnels linking your tele-worker back to your main office but they are 'clientless’ in that your O/S does not need to generate the tunnel & you do not need to install any VPN software manually. You instigate an SSL tunnel from your regular web browser, so it could be in a web cafe or guest network, & the tunnel is creating using SSL technology
- the same encryption that you use for secure web sites such as your bank. The Vigor 2860 can operate SSL VPNs in either Proxy or full tunnel mode & allows up to 10 simultaneous incoming users. 802.1q Tagged, Wireless & Port Based VLAN The Vigor 2860 features a hugely flexible VLAN system. Each of the six Gigabit LAN ports can be isolated from each other, for example to feed different companies or departments but keeping their local traffic completely separated. For more sophisticated scenarios, the Vigor 2860
Includes:: tagged VLANs (802.1q) whereby data is marked with a VLAN identifier. This identifier can be read by an onward Ethernet switch & directed to specific ports or just passed to the LAN for specific VLAN clients to pick up; priorities can also be applied for LAN-side Qo S. The VLANs can be tied to any other individual 6 RJ45 ports on the front of the Vigor 2860, or, as seen below, by the use of VLAN tagging, you can uplink to a larger switch & retain the separation for larger groups. The VLANs can each be tied into each of the different IP subnets that the router may also be operating, to provide even more isolation. On the Wireless-equipped models (Vigor 2860n / 2860 Vn) each of the wireless SSIDs can also be grouped within one of the VLANs. Each individual private subnet can be independent (isolated) or common (able to communicate with each other). This is ideal for departmental or multi-occupancy applications. User Management/ Authentication The Vigor 2860 has built-in user management which means that you can provide internet access to users based on their own unique login. Accounts can be restricted by schedules or maximum usage times but also any other aspect of the firewall or content filtering can be applied on a user-by-user basis. For example, a sales department might not be allowed access to social networking sites except at lunch time, or in a school, teachers & staff have more access permitted than pupils. This works with Wireless (Wi Fi – ‘n’ & ‘ Vn’ models only) clients too so is ideal for guest or temporary access as users can be isolated from the rest of the company LAN. 3G/4G Cellular Data Features The Vigor 2860 Series' USB (Universal Serial Bus) port can host a compatible 3G modem for access to the cellular network for full Internet Access. All UK networks provide high speed HSDPA data connections & some are starting to roll out 4G. The 3G/4G connection can be used as your primary/only Internet access, or as backup to your main ADSL line connection. This facility is ideal for homes or offices which don't want to pay fixed line + broadband rental & also for temporary locations, or those to where fixed lines aren't available but for businesses, having 3G as a failover to your main connectivity means that your business stays online when your broadband doesn't! Please check with us for the latest USB (Universal Serial Bus) modem compatibility; the phone companies (Vodafone, EE, O2, 3 etc.) continuously introduce new models, so additional Modem Support is added continuously. If you have a new modem, not yet supported, it is possible to obtain logs for our engineers to assess. The Vigor 2860 & 3G/4G cellular modem setup is ideal for: Backup to your primary Internet feed (ADSL, cable etc.) Providing lower cost broadband than a fixed line solution Areas without fixed line broadband access Compatible with a wide range of 3G modems/phones Temporary Locations Mobile Homes Locations on the move
- coaches, trains Fairgrounds & temporary exhibitions Outdoor locations (the router & modem itself must be indoors!) Disaster Planning & High Availability Network Attached Storage (NAS) The Vigor 2860's USB2.0 port can also be used to add storage memory to the unit in the form of a USB (Universal Serial Bus) memory key (as shown right) or for higher capacity a USB (Universal Serial Bus) hard drive (normally requires its own power). The Vigor 2860 then provides FTP access file uploading/downloading which can be from the local LAN or from anywhere on the Internet
- ideal for a simple to deploy file depository. Access can be 'public' or using usernames & passwords, each of which can have their own directories and/or file access rights. As well as FTP, file sharing is available as a Windows 'network drive'. You can also use Windows Explorer to view & access the contents of the USB (Universal Serial Bus) drive. If you do have a USB (Universal Serial Bus) memory key connected, you can also have the router save it's system logs (syslog) to that memory instead of to a connecting computer; useful for technical personnel (Sys Admins). The NAS facility uses any FAT32 formatted device (
Includes: USB (Universal Serial Bus) memory sticks, USB (Universal Serial Bus) hard drives etc.) & supports a transfer rate of 12 Mb/s so ideal for occasional or remote storage.