Vigor 2860n VDSL2/ADSL2+ Wireless-N Router Firewall Overview The Vigor 2860n is Draytek’s new wireless-N router/firewall which can support either ADSL or VDSL (BT Infinity/FTTC), making the Vigor 2860n ideal for users with ADSL now who may wish to upgrade to VDSL later. Alternative WAN ports can instead provide connectivity to Ethernet feeds, secondary x DSL modems or a 3G cellular service using a USB (Universal Serial Bus) adaptor. This latest router series Includes:: support for professional features such as VLAN tagging & Gigabit Ethernet. The Vigor 2860n is packed with professional-level features, offering truly comprehensive DSL connectivity & security. The V2860n is compatible with all UK variants of ADSL (including ADSL2+ & Annex M), VDSL & VDSL2, the Vigor 2860n can also be used for cable-modem, leased line & EFM applications using its Gigabit Ethernet WAN port. On VDSL, the Vigor 2860n supports the very latest services for speeds up to 80 Mb/s (depending on line quality & length). A 6-port Gigabit Ethernet switch on the LAN side provides high speed connectivity for your server, other local PCs or for uplink to a larger Ethernet switch. The V2860n comes with A superbly comprehensive set of security features including web application controls, content filtering & an object based firewall management system. Runs on either ADSL or VDSL The Vigor 2860n's built in DSL interface will connect to either an ADSL or VDSL line. If you have a second line (of either type) you can add an additional modem (or your existing modem from your other line) to the Vigor 2860n's Ethernet WAN ports. You can set the two lines up in load balancing mode, where traffic is split across both of them, or into failover mode, where the other DSL line only kicks-in if your primary DSL line fails (or vice versa). ADSL makes a particularly good method of failover for VDSL because they are delivered differently. VDSL service is provided & powered by a cabinet in your street - that's where the line terminates. ADSL service, on the other h&, comes all the way from your local exchange, which coul be miles away & is powered from there. That means that if your street's VDSL cabinet is damaged, its DSLAM fails or you lose power to your street, you lose VDSL, but your ADSL line comes via a different method & route, so it's unlikely that both would be affected. These failover methods can also be used instead for the other WAN ports on the router (Ethernet or 3G). Robust & Comprehensive Firewall Security is always a serious consideration with Dray Tek routers. The firewall protects against attacks including Do S (Denial of Service) attacks, IP-based attacks & access by unauthorised remote systems. Wireless, Ethernet & VPN are also protected by various protection systems. The latest ' Version 3' Dray Tek object-based firewall allows even more setup flexibility than ever, enabling you to create combinations of users, rules & restrictions to suit multi-departmental organisations. The Vigor 2860n now also allows selective direction firewall rules of LAN to WAN, WAN to LAN or LAN to VPN. In addition, Qo S (Quality of Service Assurance) can now be selectively applied to specific users. IPv 6 - Next Generation Internet Routing The Vigor 2860n supports IPv 6 - the successor to the current IPv 4 addressing system that has been used since the Internet was first created. IPv 4 address space is full up & IPv 6 allows for much more efficient routing & a larger address space. IPv 6 is supported both from your own ISP, but if your ISP does not (yet) support IPv 6, the Vigor 2860n also supports IPv 6 broker/tunnel services to provide IPv 6 access using either TSPC or AICCU via 3rd party IPv 6 providers. Web Content Filtering The content control features of the Vigor 2860n means that you can set restrictions on web site access, blocking download of certain file or data types, blocking specific web sites with whitelists or blacklists, blocking IM/P2P applications or other potentially harmful or wasteful content. Restrictions can be per user, per PC or univeral. Using Dray Tek's Global View service, you can block whole categories of web sites (e.g. gambling, adult sites etc.), subject to an annual subscription to the Globalview service, which is continuously updated with new or changed site categorisations or sites which have become compromised (such as infected with Malware). A free 30-day trial is included with your new router. WAN Load Balancing & Backup The Vigor 2860n features three methods of WAN connectivity - ADSL/VDSL, Ethernet (Gigabit, switchable with LAN6) & a USB (Universal Serial Bus) port for connection of a 3G modem. The Ethernet port can connect to a second ADSL modem (e.g. Vigor 120), a cable modem or any other Ethernet-based Internet feed. The multiple WAN interfaces can be used either for WAN-Backup or load balancing. Load-balancing or failover supports IPv 4 only currently. WAN-Backup provides contingency (redundancy) in case of your primary ADSL line or ISP suffering temporary outage). Internet Traffic will be temporarily routed via the secondary Internet access. When normal services are restored to your primary ADSL line, all traffic is switched back to that. If you don't have VDSL or ADSL, the Ethernet WAN port can instead be used as your primary/only Internet connection (using NAT) so the same router can be used regardless of whether you have x DSL or Ethernet Internet connections currently. The USB (Universal Serial Bus) port provides Internet connectivity (main, backup or load balanced) by connecting to a compatible USB (Universal Serial Bus) modem (or cellphone) for access to the high speed 3G cellular networks from UK providers such as Vodafone, O2, 3 & EE. If you don't have ADSL at all, the USB/3G access method can be used as your primary/only Internet connection, ideal for temporary locations, mobile applications or where broadband access is not available. In addition you can instead connect a compatible analogue modem to use analogue dial-up connections for failover in the event of your broadband failing. VPN - Linking remote offices, HQ, tele-workers & mobile staff A feature central to Dray Tek routers is the VPN (Virtual Private Networking) features. A VPN enables you to link two remote offices, branch offices back to HQ or home-based/mobile tele-workers back to your office. Once connected, they have access to your office/remote resources through a secure encrypted tunnel allowing remote desktop, file sharing & seamless access to other resources & devices. The Vigor 2860n means that you can set up up to 32 simultaneous VPN tunnels to remote offices or tele-workers. The Vigor 2860n supports all industry standard protocols, including encryption & authentication methods. Tele-workers can authenticate directly with your LDAP server if preferred. The Vigor 2860n supports VPN trunking; this means that you can create tunnels down multiple WAN connections to a remote site in order to increase bandwidth. VPN trunking also provides failover (backup) of your VPN route down a secondary WAN connection. The Vigor 2860n also supports SSL VPN. These are encrypted tunnels linking your tele-worker back to your main office but they are 'clientless’ in that your O/S does not need to generate the tunnel & you do not need to install any VPN software manually. You instigate an SSL tunnel from your regular web browser, so it could be in a web cafe or guest network, & the tunnel is creating using SSL technology - the same encryption that you use for secure web sites such as your bank. The Vigor 2860n can operate SSL VPNs in either Proxy or full tunnel mode & allows up to 10 simultaneous incoming users. 802.1q Tagged, Wireless & Port Based VLAN The Vigor 2860n features a hugely flexible VLAN system. Each of the six Gigabit LAN ports can be isolated from each other, for example to feed different companies or departments but keeping their local traffic completely separated. For more sophisticated scenarios, the Vigor 2860n Includes:: tagged VLANs (802.1q) whereby data is marked with a VLAN identifier. This identifier can be read by an onward Ethernet switch & directed to specific ports or just passed to the LAN for specific VLAN clients to pick up; priorities can also be applied for LAN-side Qo S. The VLANs can be tied to any other individual 6 RJ45 ports on the front of the Vigor 2860n, or by the use of VLAN tagging, you can uplink to a larger switch & retain the separation for larger groups. The VLANs can each be tied into each of the different IP subnets that the router may also be operating, to provide even more isolation. On the Wireless-equipped models (Vigor 2860n / 2860 Vn) each of the wireless SSIDs can also be grouped within one of the VLANs. Each individual private subnet can be independent (isolated) or common (able to communicate with each other). This is ideal for departmental or multi-occupancy applications. Reliable & High-Performance Wi Fi ('n' models only) The Vigor 2860n features 802.11n wireless LAN
Specification & has been certified by the Wi Fi alliance for cross compatibility & Wi Fi compliance (including WPA/WPA2 & WMM). The Vigor 2860n Includes:: a hardware co-processor for Wi Fi to ensure best performance & encryption processing. 802.11n provides a total wireless bandwidth of up to 200 Mb/s using new methods such as packet aggregation & channel bonding. Real-world throughput depends on your own environment (factors such as obstructions, number of hosts & distance all make a significant difference), but actual transfer speeds of over 100 Mb/s are achievable (based on our real world tests). In addition, 802.11n provides greater coverage & resilience to interference compared to previous wireless standards thanks to the MIMO technology & the Vigor's antennae diversity arrangement. Wireless Security The Vigor 2860n provides several independent levels of security including encryption (up to WPA2), authentication (802.11x) & methods such as MAC address locking & DHCP fixing to restrict access to authorised users only. The Web interface lets you see how many & which clients are currently connected as well as their current bandwidth usage. An 'instant' block lets you disconnect a wireless user temporarily in case of query. The Wireless VLAN facility means that you can isolate wireless clients from each other or from the 'wired' LAN. The Vigor 2860n also allow guest access with password protection so that visitors can use your Wi Fi access, but only with a password which you set for them. When the user connects to your wireless LAN, they are firstly presented with your login screen before any Internet access is permitted. This is in addition to any encryption system you have running. The Multiple SSID features enables you to have up to four distinct or common virtual wireless access points. For example, you could have one for company usage, with access to your company LAN & another for public access which allows internet surfing only. Setting up wireless security is made easier thanks to the WPS feature (Wi Fi protected setup) whereby your client PC can get its security keys by pressing a button on the front of the router. For specialist or more demanding coverage applications, optional aerials can be used with the Vigor 2860n to potentially increase the range of wireless coverage (depending on enviroment) or provide directional coverage in order that your wireless transmission is focussed & concentrated into one direction only, for example into a room or across open space. With the increasing popularity of wireless LANs, you will want to choose the least congested wireless channel (Nos. 1-13) for yours so the Vigor can scan & provide a list of all devices in the vicinity so that you can choose the best channel 802.11n Compliant Hardware wireless co-processor for increased throughput 'MIMO' Technology with three aerials (2T2R) for diversity Packet Aggregation & Channel Bonding Optional Higher Gain or directional aerials available - Click Here. 200 Mb/s Total Wireless bandwidth Backward compatible with 802.11b & 802.11g Standards Active Client list in Web Interface Wireless LAN Isolation (from each other and/or wired LAN) 64/128-bit WEP Encryption WPA/WPA2 Encryption WPS - Wi Fi Protected Setup for client security setup Switchable Hidden SSID Restricted access list for clients (by MAC address) Time Scheduling (WLAN can be disabled at certain times of day) Access Point Discovery WDS (Wireless Distribution system) for Bridging & Repeating 802.1x Radius Authentication Wireless Rate-Control Automatic Power Management 802.11e WMM (Wi-Fi Multimedia) Wireless LAN WDS Facility Vigor 2860n supports WDS (Wireless Distribution System) which enables you to use the wireless capability to bridge to another network, within wireless range. You need an additional compatible wireless router for this of course. With WDS bridging, both networks should be within the same logical IP subnet (IP address range). Once set up, all of the PCs on both sides of the link can access each other, across the wireless bridge. Local wireless devices such as a laptop can continue to use their local access point. An additional mode called 'repeating' means that you can set up a third station. User Management/ Authentication The Vigor 2860n has built-in user management which means that you can provide internet access to users based on their own unique login. Accounts can be restricted by schedules or maximum usage times but also any other aspect of the firewall or content filtering can be applied on a user-by-user basis. For example, a sales department might not be allowed access to social networking sites except at lunch time, or in a school, teachers & staff have more access permitted than pupils. This works with Wireless (Wi Fi – ‘n’ & ‘ Vn’ models only) clients too so is ideal for guest or temporary access as users can be isolated from the rest of the company LAN. 3G/4G Cellular Data Features The Vigor 2860n Series' USB (Universal Serial Bus) port can host a compatible 3G modem for access to the cellular network for full Internet Access. All UK networks provide high speed HSDPA data connections & some are starting to roll out 4G. The 3G/4G connection can be used as your primary/only Internet access, or as backup to your main ADSL line connection. This facility is ideal for homes or offices which don't want to pay fixed line + broadband rental & also for temporary locations, or those to where fixed lines aren't available but for businesses, having 3G as a failover to your main connectivity means that your business stays online when your broadband doesn't! Please check with us for the latest USB (Universal Serial Bus) modem compatibility; the phone companies (Vodafone, EE, O2, 3 etc.) continuously introduce new models, so additional Modem Support is added continuously. If you have a new modem, not yet supported, it is possible to obtain logs for our engineers to assess. The Vigor 2860n & 3G/4G cellular modem setup is ideal for: Backup to your primary Internet feed (ADSL, cable etc.) Providing lower cost broadband than a fixed line solution Areas without fixed line broadband access Compatible with a wide range of 3G modems/phones Temporary Locations Mobile Homes Locations on the move - coaches, trains Fairgrounds & temporary exhibitions Outdoor locations (the router & modem itself must be indoors!) Disaster Planning & High Availability Network Attached Storage (NAS) The Vigor 2860n's USB2.0 port can also be used to add storage memory to the unit in the form of a USB (Universal Serial Bus) memory key (as shown right) or for higher capacity a USB (Universal Serial Bus) hard drive (normally requires its own power). The Vigor 2860n then provides FTP access file uploading/downloading which can be from the local LAN or from anywhere on the Internet - ideal for a simple to deploy file depository. Access can be 'public' or using usernames & passwords, each of which can have their own directories and/or file access rights. As well as FTP, file sharing is available as a Windows 'network drive'. You can also use Windows Explorer to view & access the contents of the USB (Universal Serial Bus) drive. If you do have a USB (Universal Serial Bus) memory key connected, you can also have the router save it's system logs (syslog) to that memory instead of to a connecting computer; useful for technical personnel (Sys Admins). The NAS facility uses any FAT32 formatted device ( Includes: USB (Universal Serial Bus) memory sticks, USB (Universal Serial Bus) hard drives etc.) & supports a transfer rate of 12 Mb/s so ideal for occasional or remote storage. ...
Vigor 2866 Router\n\n\n\n Key Specifications:\n\n G.fast (Ultrafast Fibre), VDSL2 (Superfast Fibre), ADSL & Ethernet Router\n Multi-WAN Gigabit Performance Router with Load-Balancing & Failover\n Up to 950 Mbps Firewall Throughput for Ethernet WAN\n 5+1 Gigabit RJ-45 LAN Ports\n Up to 800 Mbps VPN Throughput with IPsec acceleration\n 32 LAN-to-LAN & Remote Teleworker VPN Tunnels\n 16 Dray Tek SSL VPN or Open VPN Tunnels\n 8 LAN Subnets with VLANs (Port-based / 802.1q)\n SPI Firewall & Content Filtering\n Optional Vigor Care Available\n Can be centrally Managed by Vigor ACS\n\n\n\n\n\n\n Description:\n\n\n\n G.fast & Ethernet Load Balancer\n\n\n\n The Vigor 2866 is a G.fast, VDSL2/ADSL2+ & Ethernet WAN router featuring VPN, advanced routing features, firewall, content filtering, bandwidth management & more. Connect the Vigor 2866 to Superfast Fibre with its integrated G.fast & VDSL modem. Or connect to Virgin Media Cable & Ultrafast FTTP with Ethernet WAN.\n\n Featuring high throughput with Load Balancing & Failover connectivity, suitable for handling Fibre to the Premises (FTTP) & Gigabit Internet connections. Offering up to 950 Mbps per-WAN of Hardware Accelerated throughput while retaining its full feature set.\n\n\n\n Route Policy - Powerful Routing Management\n\n\n\n The Vigor 2866 series provides full policy-based control of where & how outbound traffic is routed with Route Policy:\n\n\n\n\n VPN Routing\n\n Send all or select traffic through VPN services.\n\n\n\n Hostname Routing\n\n Route access to individual websites, Internet domains (i.e. www.bbc.co.uk) & hostnames through a VPN tunnel or a specific WAN.\n\n\n\n Service Routing\n\n Push specific services or ports, such as DNS, through a set WAN, an alternative Gateway or VPN Tunnel.\n\n\n\n Failover & Failback\n\n Extensive control of Failover with multiple Failover rules & paths. Manage how connections are moved back to the primary connection after a failover has occurred with Failback settings.\n\n\n\n\n\n\n\n\n\n Ideal VPN router for SMB\n\n\n\n A feature central to Dray Tek routers is its VPN (Virtual Private Networking) capabilities. A VPN enables you to link remote offices & branch offices back to HQ, or home-based/mobile teleworkers back to your office.\n\n The Vigor 2866 is an ideal VPN router, with 300 Mbps standard IPsec VPN throughput & up to 50 concurrently active VPN tunnels.\n\n I Psec Hardware Acceleration boosts performance, up to 800 Mbps for 16 VPN tunnels, allowing securely encrypted tunnels between sites to make full use of high-speed Internet connections.\n\n\n\n It supports all common industry-standard VPN protocols, for it to connect to VPN services, link remote offices & handle connections from all types of VPN clients. Supporting IPsec IKEv 1 & IKEv 2 protocols with EAP & XAuth authentication, Dray Tek's SSL VPN & L2TP for both LAN to LAN & Dial-In teleworker VPNs. In addition, teleworkers can connect to the router with Open VPN.\n\n User management for Dial-In Teleworkers is managed through the router's web interface, with m OTP 2-factor authentication available for IPsec, L2TP & SSL VPN Teleworker connections. Alternatively, authentication for Dial-In Teleworker connections can be forwarded to your Active Directory (LDAP) or RADIUS or TACACS+ server.\n\n\n\n\n Connect VPNs from behind NAT with Dray Tek's VPN Matcher\n\n\n\n A typical requirement for connecting a VPN tunnel between two points is that the VPN server must be directly accessible on the public Internet. Sometimes this can be achieved with NAT Port Forwarding if the router is located behind another router, but if the router is connected to 4G Mobile Broadband or is behind Carrier-Grade NAT (CG-NAT), connecting to that VPN server may be impossible.\n\n\n\n\n Dray Tek's new VPN Matcher service helps Dray Tek routers behind NAT to allow Dial-In Teleworkers to connect, or connect two Dray Tek VPN routers that are behind NAT & could not normally establish a VPN tunnel.\n\n Connect an Open VPN Teleworker to a Dray Tek router behind NAT\n\n Connect two Dray Tek router's behind NAT with a LAN-to-LAN VPN\n\n\n\n\n\n\n Connecting Remote Sites with LAN to LAN VPN\n\n\n\n Supporting up to 32 concurrently active VPN tunnels, the Vigor 2866 series is ideal for connecting multiple sites or home offices together with fast & secure IPsec VPN tunnels.\n\n Once connected, they have access to your office/remote resources through a secure encrypted tunnel allowing remote desktop, file sharing & seamless access to other resources & devices.\n\n\n\n\n\n\n Dray Tek SSL VPN for Dial-In Teleworkers & LAN to LAN\n\n\n\n The Vigor 2866 supports up to 16 active Dray Tek SSL VPN tunnel connections. These are encrypted tunnels linking your teleworkers or remote Dray Tek Vigor routers back to your main office using SSL/TLS technology - the same encryption that you use for secure websites such as your bank.\n\n Teleworkers can easily create a secure SSL VPN tunnel to the Dray Tek Vigor 2866 using the free Dray Tek Smart VPN Client app. Available for Windows, mac OS, Apple i OS (iPad, iPhone) & Android devices.\n\n\n\n\n\n\n 5+1 Gigabit LAN Ports with VLANs\n\n\n\n The Vigor 2866 series provides up to 6 Gigabit LAN ports for wired links to Computers, Servers & Network Attached Storage.\n\n With 5 dedicated LAN ports & one flexible LAN/WAN port, the Vigor 2866 can connect up to 6 devices directly with a single Ethernet WAN configuration, or 5 devices with a dual Ethernet WAN configuration.\n\n With Multiple LAN subnets & VLANs, the Vigor 2866 can manage up to 8 separate networks. For instance, an internal network with a separate network for Guests to use, completely separate from the private network. Each network with its own Content Filtering, Firewall, Quality of Service & Route Policy applied.\n\n The router has full support for 802.1Q VLAN tagging so that these subnets can be passed to other devices that support VLAN tags, such as the Dray Tek Vigor Switch G1080 8-port switch, for additional network ports.\n\n\n\n The Wireless LAN also links to these VLANs, making the same Guest & Private networks possible simply using different wireless SSIDs. Or connect up a Dray Tek Vigor AP wireless access point, such as the Vigor AP 903 to do the same, spanning the router's own wireless & any connected wireless APs.\n\n\n\n\n Designed for Central Management\n\n\n\n The Vigor 2866 series (along with most other Dray Tek routers, Access points & switches) can be centrally managed by our Vigor ACS central management platform.\n\n This scalable solution provides visibility, control & reporting of your entire Dray Tek product estate, ideal for dealers/SIs managing customers' devices or any user who wants to know what's going on with their devices. Vigor ACS also provides features like automated/bulk firmware updates, VPN management & alarms for connectivity or other issues.\n\n\n\n\n\n\n Robust & Comprehensive IPv 4 / IPv 6 Firewall\n\n\n\n Security is always taken seriously with Dray Tek routers. The firewall protects against attacks including Do S (Denial of Service) attacks, IP-based attacks & access by unauthorised remote systems. Wireless, Ethernet & VPN are also protected by various protection systems.\n\n The Dray Tek object-based firewall enables you to create combinations of Firewall rules & Content Filtering to suit a home or small office environment, applying Content Filtering to the whole network, only specified devices or just the network that guests can connect to.\n\n The Vigor 2866 supports both IPv 4 & IPv 6 with Dual-Stack IPv 4/IPv 6. Advanced networking features, such as the object-based Firewall, Quality of Service, Content Filtering & VLANs support both IPv 4 & IPv 6 networks.\n\n\n\n\n\n\n Web Content Filtering with DNS Filter\n\n\n\n The content control features of the Vigor 2866 allow you to set restrictions on website access, blocking the download of certain files or data types, blocking specific websites with whitelists or blacklists, blocking IM/P2P applications or other potentially harmful or wasteful content. Restrictions can be per user, per PC or universal & according to time schedules.\n\n Content filtering can also block sites using HTTPS/SSL where URLs are encrypted (and normal routers cannot block).\n\n Using the Global View service, you can block whole categories of websites (e.g. gambling, adult sites etc.), subject to an annual subscription, which is continuously updated with new or changed site categorisations or sites that have become compromised (such as infected with Malware). A free 30-day trial is included with your new router.\n\n\n\n\n\n\n High Availability - Hardware Failover\n For even greater resilience, the Vigor 2866 series provides High Availability (HA), with both a primary & secondary router able to provide connectivity to your network & subnets.\n\n In the event of the primary unit failing, the secondary unit will take its place on the network, automatically switching over to resume Internet, routing & VPN connectivity with no intervention required. This can remove the possibility of a single point of failure within your routers.\n\n\n\n With Config Sync, the two routers are managed as a single unit, so that any changes made to the primary router will automatically propagate to the secondary router, ensuring it&153;s ready to take over at any time.\n\n\n\n\n Dray DDNS - Dray Tek Dynamic DNS Address\n Dray Tek provides a free Dynamic DNS address to each Vigor 2866 router, allowing you to link the router's current IP address to a memorable "drayddns.com" hostname, such as "myrouter.drayddns.com".\n\n\n\n This address automatically updates whenever the Internet connection's IP changes, so if one WAN&153;s IP address allocation is dynamic, or the IP changes when switching from the primary WAN connection to a backup, you can easily locate & access your Vigor 2866 router. Just use the hostname to access the router's VPN services, management & any other services you have made accessible through the router.\n\n The Vigor 2866 can also authenticate your Dray DDNS hostname with free SSL/TLS certificates provided by Lets Encrypt, the router manages & automates the certificate process. Keeping the certificate up to date & ready for use with SSL VPN & other services.\n\n\n\n\n\n\n Manage Guest Wi Fi with Hotspot Web Portal\n\n\n\n Dray Tek routers make it easy to manage Guest Wireless with Hotspot Web Portal. The fully customisable captive portal can be applied to the router's LAN / VLAN interfaces, for use with wireless access points.\n\n Authentication can be handled by Google/ Facebook or an external web Portal service such as violet Wi Fi with RADIUS.\n\n Upon connecting to the wireless network, users are presented with your company's branding & information. From there, depending on what you've set, they can simply click-through, provide their details or enter a PIN with Voucher generated by the router.\n\n Once connected, the router can allow access until a user reaches their"a limit of time connected or bandwidth used.\n\n\n\n\n\n\n\n Quality of Service & Bandwidth Control\n\n\n\n Prioritise latency-sensitive applications on your network with Quality of Service.\n\n App Qo S simplifies setting up Quality of Service significantly, simply select which applications or services to prioritise, such as Zoom & Skype.\n\n Use 4 separate queues to give priority to servers & PCs (IP address), services such as Vo IP or DNS, or packet tagging used by IP phones with 802.1p & DSCP support\n\n Auto Voice VLAN allows the router to automatically prioritise Vo IP calls as they pass through the router without additional configuration.\n\n Control throughput with Bandwidth Limit, by setting speed limits for all clients individually, groups of IPs, or a shared bandwidth limit for a whole subnet, such as a Guest network.\n\n\n\n\n\n\n Central AP & Switch Management\n\n\n\n The Vigor 2866 manages Dray Tek Vigor AP access points & Vigor Switch switches connected locally to the router. This enables you to centrally control, manage & administer multiple AP & Switch devices installed around your building/campus from just one router.\n Central AP Management\n The Dray Tek router operating as the wireless controller can provision up to 20 Dray Tek Vigor AP access points with Central AP Management profiles, with an option to Auto Provision - auto-configuring newly installed Vigor AP access points with the Auto Provisioning profile, upon initial connection to the Dray Tek Vigor router's network.\n Central Switch Management\n Dray Tek Vigor Switch switches can be provisioned & managed through the router with Dray Tek&153;s Central Switch Management system, which allows you to:\n\n Easily provision VLAN configuration & other port settings directly from the router.\n Set bandwidth rate limits & schedules for individual ports.\n Log switch events for alert notifications if network problems occur\n At a glance see the devices connected on your network with a virtual topology.\n\n\n\n\n\n\n\n\n\n\n Technical
Specification (UK Hardware Spec.):\n Physical Interfaces\n\n WAN1: G.fast / VDSL2 / VDSL2 35b / ADSL2+, RJ-11\n WAN2/LAN Switchable Port: 1x Gigabit Ethernet (1G/100M/10M), RJ-45\n LAN Ports: 5x Gigabit Ethernet (1G/100M/10M), RJ-45\n 2x USB (Universal Serial Bus) 2.0 Ports for 3G/4G Modem, thermometer or Printer)\n Recessed Factory Reset button\n\n Performance\n\n NAT Performance:\n\n 1.3 Gb/s Max Sync Rate with G.fast (dependant on ISP & Exchange equipment)\n 100 Mb/s Max Sync Rate with VDSL2\n 300 Mb/s Max Sync Rate with VDSL2 35b\n 950 Mb/s NAT Throughput for Ethernet WAN with Hardware Acceleration\n 1.8 Gb/s Total Multi-WAN NAT Throughput\n 700 Mb/s NAT Throughput per WAN without Hardware Acceleration\n 60, 000 NAT Sessions\n 8000 Hardware Accelerated NAT Sessions\n\n\n VPN Performance:\n\n 300 Mb/s IPsec (AES256) VPN Performance\n 800 Mb/s Hardware Accelerated IPsec VPN Performance - New!\n 130 Mb/s SSL VPN Performance\n Max. 32 Concurrent VPN Tunnels\n Max. 16 Concurrent SSL VPN / Open VPN Tunnels\n\n\n\n WAN Interfaces\n\n WAN1: G.fast / VDSL2 / VDSL2 35b / ADSL2+\n WAN2: Gigabit Ethernet\n WAN5: 4G/LTE USB (Universal Serial Bus) Modem (not included)\n WAN6: 4G/LTE USB (Universal Serial Bus) Modem (not included)\n\n Internet Connection\n\n Load Balancing: IP-based, Session-based\n Hardware Acceleration\n 802.1p/q Multi-VLAN Tagging\n Multi-VLAN/PVC\n WAN Active on Demand: Link Failure, Traffic Threshold\n Connection Detection: PPP, ARP Detect, Ping Detect\n WAN Data Budget\n Dynamic DNS\n Dray DDNS " with automated Lets Encrypt Certificates\n Full Feature-set Hardware Acceleration:\n\n Hardware Accelerated Quality of Service\n Multi-WAN Data Budget\n Traffic Graph & Data Flow Monitor\n Bandwidth Limit\n\n\n IPv 4 Connection Types: PPPo A, PPPo E, MPo A, DHCP, Static IP, PPTP/L2TP (Ethernet WAN only)\n IPv 6 Connection Types:\n\n Ethernet: PPP, DHCPv 6, Static IPv 6, TSPC, AICCU, 6rd, 6in 4 Static Tunnel\n USB (Universal Serial Bus) 4G/LTE Modem: TSPC, AICCU\n\n\n\n G.fast, VDSL & ADSL Features\n\n BT Infinity Option 1 & Option 2 Compatible\n Compliant with Openreach SIN 527 & SIN 498\n Auto Detection of G.fast, VDSL & ADSL line modes\n Support for G.INP & Vectoring\n G.fast Standards:\n\n ITU-T G.9700, G.9701 G.fast\n Profile: 212 M Hz & 106 M Hz\n\n\n VDSL Standards:\n\n ITU-T G.993.1 VDSL\n ITU-T G.993.2, G.997.1 VDSL2\n Band Plan: G.998, G.997\n Annex A, Annex B, Annex C\n VDSL2 Profile: 8a, 8b, 8c, 8d, 12a, 12b, 17a, 35b\n OLR, UPBO, DPBO Supported\n US0 Supported\n Loop Diagnostic Mode\n DSL Forum WT-114\n\n\n ADSL Standards: \n\n Annex A\n ANSI T1.413 Issue 2\n ITU-T G.992.1 G.dmt (ADSL)\n ITU-T G.992.2 G.lite\n ITU-T G.992.3 ADSL2\n ITU-T G.992.5 ADSL2+\n\n\n ATM Protocols:\n\n RFC-2684/RFC-1483 Multiple Protocol over AAL5\n RFC-2516 PPP over Ethernet\n RFC-2364 PPP over AAL5\n Support for RFC4638 for MTU up to 1500\n\n\n\n Firewall & Content Filtering\n\n IP-based or User-based Firewall Policy\n User-based Time"a\n Do S Attack Defence\n Spoofing Defence\n Content Filtering:\n\n Application Content Filter\n URL Content Filter\n DNS Keyword Filter\n Web Features\n Web Category Filter (requires Global View subscription)\n\n\n\n NAT Features\n\n NAT Port Redirection\n Open Ports\n Port Triggering\n DMZ Host\n UPn P\n ALG (Application Layer Gateway): SIP, RTSP, FTP, H.323\n VPN Pass-Through: PPTP, L2TP, IPsec\n\n LAN Management\n\n 802.1q Tag-based, Port-based VLAN\n Up to 8 LAN Subnets (NAT or Routing mode selectable per LAN interface)\n Up to 16 VLANs\n DMZ Port\n DHCP Server:\n\n Multiple IP Subnet\n Custom DHCP Options\n Bind-IP-to-MAC\n DHCP Pool Count up to 1022 addresses for LANs 1-3\n DHCP Pool Count up to 253 addresses for LANs 4-8\n DHCP Relay per LAN\n\n\n LAN IP Alias\n Wired 802.1x Port Authentication\n Port Mirroring\n Local DNS Server\n Conditional DNS Forwarding\n Hotspot Web Portal\n Hotspot Authentication: Click-Through, Social Login, SMS PIN, Voucher PIN, RADIUS, External Portal Server\n\n Networking Features\n\n Policy-based Routing: Protocol, IP Address, Port, Domain/ Hostname, Country\n High Availability: Active-Standby, Hot-Standby\n DNS Security (DNSSEC)\n Local RADIUS server\n SMB File Sharing (Requires external storage)\n Multicast: IGMP Proxy, IGMP Snooping & Fast Leave, Bonjour\n Routing Features: IPv 4 & IPv 6 Static Routing, Inter-VLAN Routing, RIP v 1/v 2/ng, BGP\n\n VPN\n\n Up to 32 active VPN tunnels - including up to 16 SSL VPN or Open VPN Tunnels\n Up to 16 Hardware Accelerated 800 Mb/s IPsec tunnels " New!\n LAN-to-LAN - Dial-In VPN Server & Dial-Out VPN Client\n Teleworker-to-LAN " Dial-In VPN Server\n User Authentication: Local, RADIUS, LDAP, TACACS+, m OTP\n IKE Authentication: Pre-Shared Key & Digital Signature (X.509)\n Encryption: MPPE, DES, 3DES, AES (128/192/256)\n Authentication: SHA-256, SHA-1\n VPN Trunk (Redundancy): Load Balancing, Failover\n Dead Peer Detection (DPD)\n IPsec NAT-Traversal (NAT-T)\n Virtual IP Mapping " Resolve VPN IP subnet/range conflicts\n DHCP over IPsec\n Dray Tek VPN Matcher " Connect to a VPN router that&153;s behind NAT/CG-NAT - New!\n VPN Protocols:\n\n IPsec IKEv 1, IKEv 2, IKEv 2 EAP\n IPsec-XAuth\n Dray Tek SSL VPN\n Open VPN (Remote Dial-In User only)\n GRE over IPsec\n PPTP\n L2TP, L2TP over IPsec\n\n\n\n Bandwidth Management\n\n IP-based Bandwidth Limit\n IP-based Session Limit\n User-based Data"a\n\n Quality of Service (Qo S)\n\n Classify via TOS, DSCP, 802.1p, IP Address, Service Type\n 4 Priority Queues\n App Qo S\n Vo IP Prioritization\n Class-based Outbound Traffic Tagging: DSCP & IP Precedence\n\n Management\n\n Local Service: HTTP, HTTPS, Telnet, SSH, FTP, TR-069\n Config File Export & Import\n Import Config from Vigor 2862 & Vigor 2860\n Auto Backup Config to USB (Universal Serial Bus) Storage " New!\n Firmware Upgrade via TFTP, HTTP, TR-069\n 2-Level Administration Privilege\n Access Control Features: Access List, Brute Force Protection\n Syslog\n SMS, E-mail Notification Alert\n SNMP: v 1, v 2c, v 3\n Managed by Vigor ACS\n\n Router Central Management Features\n\n AP Management: Up to 20 Vigor AP access points\n Switch Management: Up to 10 Vigor Switch network switches\n VPN Management: Up to 8 Vigor routers\n\n Operating Requirements\n\n Rack-Mountable (Optional Vigor RM1 mounting bracket required)\n Wall or Shelf Mountable with included fittings\n Temperature Operating: 0 &176;C ~ 45 &176;C\n Storage: -25 &176;C ~ 70 &176;C\n Humidity 10% ~ 90% (non-condensing)\n Power Consumption: 22.8 watts maximum\n Operating Power: DC 12V (via external PSU, supplied)\n Power Requirements: 100-240VAC\n Weight: 620g\n Dimensions:\n\n 241mm Width\n 165mm Depth\n 44mm Height\n\n\n\n Warranty\n\n Two (2) Year Manufacturer's RTB\n Optional Vigor Care Enhanced Warranty Available\n\n Vigor Care B3 3 Year Subscription: VCARE-B3\n Vigor Care B5 5 Year Subscription: VCARE-B5\n\n\n\n Box Contents\n\n Vigor 2866 router\n Quick Start Guide\n Screws & wall plugs for wall mounting\n 2m Cat-5e RJ-45 Network Cable\n DC 12V Power Supply with UK Plug\n\n\n ...
Vigor 2866 Router\n\n\n\n Key Specifications:\n\n G.fast (Ultrafast Fibre), VDSL2 (Superfast Fibre), ADSL & Ethernet Router\n Multi-WAN Gigabit Performance Router with Load-Balancing & Failover\n Up to 950 Mbps Firewall Throughput for Ethernet WAN\n 5+1 Gigabit RJ-45 LAN Ports\n Up to 800 Mbps VPN Throughput with IPsec acceleration\n 32 LAN-to-LAN & Remote Teleworker VPN Tunnels\n 16 Dray Tek SSL VPN or Open VPN Tunnels\n 8 LAN Subnets with VLANs (Port-based / 802.1q)\n SPI Firewall & Content Filtering\n Optional Vigor Care Available\n Can be centrally Managed by Vigor ACS\n\n\n\n\n\n\n Description:\n\n\n\n G.fast & Ethernet Load Balancer\n\n\n\n The Vigor 2866 is a G.fast, VDSL2/ADSL2+ & Ethernet WAN router featuring VPN, advanced routing features, firewall, content filtering, bandwidth management & more. Connect the Vigor 2866 to Superfast Fibre with its integrated G.fast & VDSL modem. Or connect to Virgin Media Cable & Ultrafast FTTP with Ethernet WAN.\n\n Featuring high throughput with Load Balancing & Failover connectivity, suitable for handling Fibre to the Premises (FTTP) & Gigabit Internet connections. Offering up to 950 Mbps per-WAN of Hardware Accelerated throughput while retaining its full feature set.\n\n\n\n Route Policy - Powerful Routing Management\n\n\n\n The Vigor 2866 series provides full policy-based control of where & how outbound traffic is routed with Route Policy:\n\n\n\n\n VPN Routing\n\n Send all or select traffic through VPN services.\n\n\n\n Hostname Routing\n\n Route access to individual websites, Internet domains (i.e. www.bbc.co.uk) & hostnames through a VPN tunnel or a specific WAN.\n\n\n\n Service Routing\n\n Push specific services or ports, such as DNS, through a set WAN, an alternative Gateway or VPN Tunnel.\n\n\n\n Failover & Failback\n\n Extensive control of Failover with multiple Failover rules & paths. Manage how connections are moved back to the primary connection after a failover has occurred with Failback settings.\n\n\n\n\n\n\n\n\n\n Ideal VPN router for SMB\n\n\n\n A feature central to Dray Tek routers is its VPN (Virtual Private Networking) capabilities. A VPN enables you to link remote offices & branch offices back to HQ, or home-based/mobile teleworkers back to your office.\n\n The Vigor 2866 is an ideal VPN router, with 300 Mbps standard IPsec VPN throughput & up to 50 concurrently active VPN tunnels.\n\n I Psec Hardware Acceleration boosts performance, up to 800 Mbps for 16 VPN tunnels, allowing securely encrypted tunnels between sites to make full use of high-speed Internet connections.\n\n\n\n It supports all common industry-standard VPN protocols, for it to connect to VPN services, link remote offices & handle connections from all types of VPN clients. Supporting IPsec IKEv 1 & IKEv 2 protocols with EAP & XAuth authentication, Dray Tek's SSL VPN & L2TP for both LAN to LAN & Dial-In teleworker VPNs. In addition, teleworkers can connect to the router with Open VPN.\n\n User management for Dial-In Teleworkers is managed through the router's web interface, with m OTP 2-factor authentication available for IPsec, L2TP & SSL VPN Teleworker connections. Alternatively, authentication for Dial-In Teleworker connections can be forwarded to your Active Directory (LDAP) or RADIUS or TACACS+ server.\n\n\n\n\n Connect VPNs from behind NAT with Dray Tek's VPN Matcher\n\n\n\n A typical requirement for connecting a VPN tunnel between two points is that the VPN server must be directly accessible on the public Internet. Sometimes this can be achieved with NAT Port Forwarding if the router is located behind another router, but if the router is connected to 4G Mobile Broadband or is behind Carrier-Grade NAT (CG-NAT), connecting to that VPN server may be impossible.\n\n\n\n\n Dray Tek's new VPN Matcher service helps Dray Tek routers behind NAT to allow Dial-In Teleworkers to connect, or connect two Dray Tek VPN routers that are behind NAT & could not normally establish a VPN tunnel.\n\n Connect an Open VPN Teleworker to a Dray Tek router behind NAT\n\n Connect two Dray Tek router's behind NAT with a LAN-to-LAN VPN\n\n\n\n\n\n\n Connecting Remote Sites with LAN to LAN VPN\n\n\n\n Supporting up to 32 concurrently active VPN tunnels, the Vigor 2866 series is ideal for connecting multiple sites or home offices together with fast & secure IPsec VPN tunnels.\n\n Once connected, they have access to your office/remote resources through a secure encrypted tunnel allowing remote desktop, file sharing & seamless access to other resources & devices.\n\n\n\n\n\n\n Dray Tek SSL VPN for Dial-In Teleworkers & LAN to LAN\n\n\n\n The Vigor 2866 supports up to 16 active Dray Tek SSL VPN tunnel connections. These are encrypted tunnels linking your teleworkers or remote Dray Tek Vigor routers back to your main office using SSL/TLS technology - the same encryption that you use for secure websites such as your bank.\n\n Teleworkers can easily create a secure SSL VPN tunnel to the Dray Tek Vigor 2866 using the free Dray Tek Smart VPN Client app. Available for Windows, mac OS, Apple i OS (iPad, iPhone) & Android devices.\n\n\n\n\n\n\n 5+1 Gigabit LAN Ports with VLANs\n\n\n\n The Vigor 2866 series provides up to 6 Gigabit LAN ports for wired links to Computers, Servers & Network Attached Storage.\n\n With 5 dedicated LAN ports & one flexible LAN/WAN port, the Vigor 2866 can connect up to 6 devices directly with a single Ethernet WAN configuration, or 5 devices with a dual Ethernet WAN configuration.\n\n With Multiple LAN subnets & VLANs, the Vigor 2866 can manage up to 8 separate networks. For instance, an internal network with a separate network for Guests to use, completely separate from the private network. Each network with its own Content Filtering, Firewall, Quality of Service & Route Policy applied.\n\n The router has full support for 802.1Q VLAN tagging so that these subnets can be passed to other devices that support VLAN tags, such as the Dray Tek Vigor Switch G1080 8-port switch, for additional network ports.\n\n\n\n The Wireless LAN also links to these VLANs, making the same Guest & Private networks possible simply using different wireless SSIDs. Or connect up a Dray Tek Vigor AP wireless access point, such as the Vigor AP 903 to do the same, spanning the router's own wireless & any connected wireless APs.\n\n\n\n\n Designed for Central Management\n\n\n\n The Vigor 2866 series (along with most other Dray Tek routers, Access points & switches) can be centrally managed by our Vigor ACS central management platform.\n\n This scalable solution provides visibility, control & reporting of your entire Dray Tek product estate, ideal for dealers/SIs managing customers' devices or any user who wants to know what's going on with their devices. Vigor ACS also provides features like automated/bulk firmware updates, VPN management & alarms for connectivity or other issues.\n\n\n\n\n\n\n Robust & Comprehensive IPv 4 / IPv 6 Firewall\n\n\n\n Security is always taken seriously with Dray Tek routers. The firewall protects against attacks including Do S (Denial of Service) attacks, IP-based attacks & access by unauthorised remote systems. Wireless, Ethernet & VPN are also protected by various protection systems.\n\n The Dray Tek object-based firewall enables you to create combinations of Firewall rules & Content Filtering to suit a home or small office environment, applying Content Filtering to the whole network, only specified devices or just the network that guests can connect to.\n\n The Vigor 2866 supports both IPv 4 & IPv 6 with Dual-Stack IPv 4/IPv 6. Advanced networking features, such as the object-based Firewall, Quality of Service, Content Filtering & VLANs support both IPv 4 & IPv 6 networks.\n\n\n\n\n\n\n Web Content Filtering with DNS Filter\n\n\n\n The content control features of the Vigor 2866 allow you to set restrictions on website access, blocking the download of certain files or data types, blocking specific websites with whitelists or blacklists, blocking IM/P2P applications or other potentially harmful or wasteful content. Restrictions can be per user, per PC or universal & according to time schedules.\n\n Content filtering can also block sites using HTTPS/SSL where URLs are encrypted (and normal routers cannot block).\n\n Using the Global View service, you can block whole categories of websites (e.g. gambling, adult sites etc.), subject to an annual subscription, which is continuously updated with new or changed site categorisations or sites that have become compromised (such as infected with Malware). A free 30-day trial is included with your new router.\n\n\n\n\n\n\n High Availability - Hardware Failover\n For even greater resilience, the Vigor 2866 series provides High Availability (HA), with both a primary & secondary router able to provide connectivity to your network & subnets.\n\n In the event of the primary unit failing, the secondary unit will take its place on the network, automatically switching over to resume Internet, routing & VPN connectivity with no intervention required. This can remove the possibility of a single point of failure within your routers.\n\n\n\n With Config Sync, the two routers are managed as a single unit, so that any changes made to the primary router will automatically propagate to the secondary router, ensuring it&153;s ready to take over at any time.\n\n\n\n\n Dray DDNS - Dray Tek Dynamic DNS Address\n Dray Tek provides a free Dynamic DNS address to each Vigor 2866 router, allowing you to link the router's current IP address to a memorable "drayddns.com" hostname, such as "myrouter.drayddns.com".\n\n\n\n This address automatically updates whenever the Internet connection's IP changes, so if one WAN&153;s IP address allocation is dynamic, or the IP changes when switching from the primary WAN connection to a backup, you can easily locate & access your Vigor 2866 router. Just use the hostname to access the router's VPN services, management & any other services you have made accessible through the router.\n\n The Vigor 2866 can also authenticate your Dray DDNS hostname with free SSL/TLS certificates provided by Lets Encrypt, the router manages & automates the certificate process. Keeping the certificate up to date & ready for use with SSL VPN & other services.\n\n\n\n\n\n\n Manage Guest Wi Fi with Hotspot Web Portal\n\n\n\n Dray Tek routers make it easy to manage Guest Wireless with Hotspot Web Portal. The fully customisable captive portal can be applied to the router's LAN / VLAN interfaces, for use with wireless access points.\n\n Authentication can be handled by Google/ Facebook or an external web Portal service such as violet Wi Fi with RADIUS.\n\n Upon connecting to the wireless network, users are presented with your company's branding & information. From there, depending on what you've set, they can simply click-through, provide their details or enter a PIN with Voucher generated by the router.\n\n Once connected, the router can allow access until a user reaches their"a limit of time connected or bandwidth used.\n\n\n\n\n\n\n\n Quality of Service & Bandwidth Control\n\n\n\n Prioritise latency-sensitive applications on your network with Quality of Service.\n\n App Qo S simplifies setting up Quality of Service significantly, simply select which applications or services to prioritise, such as Zoom & Skype.\n\n Use 4 separate queues to give priority to servers & PCs (IP address), services such as Vo IP or DNS, or packet tagging used by IP phones with 802.1p & DSCP support\n\n Auto Voice VLAN allows the router to automatically prioritise Vo IP calls as they pass through the router without additional configuration.\n\n Control throughput with Bandwidth Limit, by setting speed limits for all clients individually, groups of IPs, or a shared bandwidth limit for a whole subnet, such as a Guest network.\n\n\n\n\n\n\n Central AP & Switch Management\n\n\n\n The Vigor 2866 manages Dray Tek Vigor AP access points & Vigor Switch switches connected locally to the router. This enables you to centrally control, manage & administer multiple AP & Switch devices installed around your building/campus from just one router.\n Central AP Management\n The Dray Tek router operating as the wireless controller can provision up to 20 Dray Tek Vigor AP access points with Central AP Management profiles, with an option to Auto Provision - auto-configuring newly installed Vigor AP access points with the Auto Provisioning profile, upon initial connection to the Dray Tek Vigor router's network.\n Central Switch Management\n Dray Tek Vigor Switch switches can be provisioned & managed through the router with Dray Tek&153;s Central Switch Management system, which allows you to:\n\n Easily provision VLAN configuration & other port settings directly from the router.\n Set bandwidth rate limits & schedules for individual ports.\n Log switch events for alert notifications if network problems occur\n At a glance see the devices connected on your network with a virtual topology.\n\n\n\n\n\n\n\n\n\n\n Technical
Specification (UK Hardware Spec.):\n Physical Interfaces\n\n WAN1: G.fast / VDSL2 / VDSL2 35b / ADSL2+, RJ-11\n WAN2/LAN Switchable Port: 1x Gigabit Ethernet (1G/100M/10M), RJ-45\n LAN Ports: 5x Gigabit Ethernet (1G/100M/10M), RJ-45\n 2x USB (Universal Serial Bus) 2.0 Ports for 3G/4G Modem, thermometer or Printer)\n Recessed Factory Reset button\n\n Performance\n\n NAT Performance:\n\n 1.3 Gb/s Max Sync Rate with G.fast (dependant on ISP & Exchange equipment)\n 100 Mb/s Max Sync Rate with VDSL2\n 300 Mb/s Max Sync Rate with VDSL2 35b\n 950 Mb/s NAT Throughput for Ethernet WAN with Hardware Acceleration\n 1.8 Gb/s Total Multi-WAN NAT Throughput\n 700 Mb/s NAT Throughput per WAN without Hardware Acceleration\n 60, 000 NAT Sessions\n 8000 Hardware Accelerated NAT Sessions\n\n\n VPN Performance:\n\n 300 Mb/s IPsec (AES256) VPN Performance\n 800 Mb/s Hardware Accelerated IPsec VPN Performance - New!\n 130 Mb/s SSL VPN Performance\n Max. 32 Concurrent VPN Tunnels\n Max. 16 Concurrent SSL VPN / Open VPN Tunnels\n\n\n\n WAN Interfaces\n\n WAN1: G.fast / VDSL2 / VDSL2 35b / ADSL2+\n WAN2: Gigabit Ethernet\n WAN5: 4G/LTE USB (Universal Serial Bus) Modem (not included)\n WAN6: 4G/LTE USB (Universal Serial Bus) Modem (not included)\n\n Internet Connection\n\n Load Balancing: IP-based, Session-based\n Hardware Acceleration\n 802.1p/q Multi-VLAN Tagging\n Multi-VLAN/PVC\n WAN Active on Demand: Link Failure, Traffic Threshold\n Connection Detection: PPP, ARP Detect, Ping Detect\n WAN Data Budget\n Dynamic DNS\n Dray DDNS " with automated Lets Encrypt Certificates\n Full Feature-set Hardware Acceleration:\n\n Hardware Accelerated Quality of Service\n Multi-WAN Data Budget\n Traffic Graph & Data Flow Monitor\n Bandwidth Limit\n\n\n IPv 4 Connection Types: PPPo A, PPPo E, MPo A, DHCP, Static IP, PPTP/L2TP (Ethernet WAN only)\n IPv 6 Connection Types:\n\n Ethernet: PPP, DHCPv 6, Static IPv 6, TSPC, AICCU, 6rd, 6in 4 Static Tunnel\n USB (Universal Serial Bus) 4G/LTE Modem: TSPC, AICCU\n\n\n\n G.fast, VDSL & ADSL Features\n\n BT Infinity Option 1 & Option 2 Compatible\n Compliant with Openreach SIN 527 & SIN 498\n Auto Detection of G.fast, VDSL & ADSL line modes\n Support for G.INP & Vectoring\n G.fast Standards:\n\n ITU-T G.9700, G.9701 G.fast\n Profile: 212 M Hz & 106 M Hz\n\n\n VDSL Standards:\n\n ITU-T G.993.1 VDSL\n ITU-T G.993.2, G.997.1 VDSL2\n Band Plan: G.998, G.997\n Annex A, Annex B, Annex C\n VDSL2 Profile: 8a, 8b, 8c, 8d, 12a, 12b, 17a, 35b\n OLR, UPBO, DPBO Supported\n US0 Supported\n Loop Diagnostic Mode\n DSL Forum WT-114\n\n\n ADSL Standards: \n\n Annex A\n ANSI T1.413 Issue 2\n ITU-T G.992.1 G.dmt (ADSL)\n ITU-T G.992.2 G.lite\n ITU-T G.992.3 ADSL2\n ITU-T G.992.5 ADSL2+\n\n\n ATM Protocols:\n\n RFC-2684/RFC-1483 Multiple Protocol over AAL5\n RFC-2516 PPP over Ethernet\n RFC-2364 PPP over AAL5\n Support for RFC4638 for MTU up to 1500\n\n\n\n Firewall & Content Filtering\n\n IP-based or User-based Firewall Policy\n User-based Time"a\n Do S Attack Defence\n Spoofing Defence\n Content Filtering:\n\n Application Content Filter\n URL Content Filter\n DNS Keyword Filter\n Web Features\n Web Category Filter (requires Global View subscription)\n\n\n\n NAT Features\n\n NAT Port Redirection\n Open Ports\n Port Triggering\n DMZ Host\n UPn P\n ALG (Application Layer Gateway): SIP, RTSP, FTP, H.323\n VPN Pass-Through: PPTP, L2TP, IPsec\n\n LAN Management\n\n 802.1q Tag-based, Port-based VLAN\n Up to 8 LAN Subnets (NAT or Routing mode selectable per LAN interface)\n Up to 16 VLANs\n DMZ Port\n DHCP Server:\n\n Multiple IP Subnet\n Custom DHCP Options\n Bind-IP-to-MAC\n DHCP Pool Count up to 1022 addresses for LANs 1-3\n DHCP Pool Count up to 253 addresses for LANs 4-8\n DHCP Relay per LAN\n\n\n LAN IP Alias\n Wired 802.1x Port Authentication\n Port Mirroring\n Local DNS Server\n Conditional DNS Forwarding\n Hotspot Web Portal\n Hotspot Authentication: Click-Through, Social Login, SMS PIN, Voucher PIN, RADIUS, External Portal Server\n\n Networking Features\n\n Policy-based Routing: Protocol, IP Address, Port, Domain/ Hostname, Country\n High Availability: Active-Standby, Hot-Standby\n DNS Security (DNSSEC)\n Local RADIUS server\n SMB File Sharing (Requires external storage)\n Multicast: IGMP Proxy, IGMP Snooping & Fast Leave, Bonjour\n Routing Features: IPv 4 & IPv 6 Static Routing, Inter-VLAN Routing, RIP v 1/v 2/ng, BGP\n\n VPN\n\n Up to 32 active VPN tunnels - including up to 16 SSL VPN or Open VPN Tunnels\n Up to 16 Hardware Accelerated 800 Mb/s IPsec tunnels " New!\n LAN-to-LAN - Dial-In VPN Server & Dial-Out VPN Client\n Teleworker-to-LAN " Dial-In VPN Server\n User Authentication: Local, RADIUS, LDAP, TACACS+, m OTP\n IKE Authentication: Pre-Shared Key & Digital Signature (X.509)\n Encryption: MPPE, DES, 3DES, AES (128/192/256)\n Authentication: SHA-256, SHA-1\n VPN Trunk (Redundancy): Load Balancing, Failover\n Dead Peer Detection (DPD)\n IPsec NAT-Traversal (NAT-T)\n Virtual IP Mapping " Resolve VPN IP subnet/range conflicts\n DHCP over IPsec\n Dray Tek VPN Matcher " Connect to a VPN router that&153;s behind NAT/CG-NAT - New!\n VPN Protocols:\n\n IPsec IKEv 1, IKEv 2, IKEv 2 EAP\n IPsec-XAuth\n Dray Tek SSL VPN\n Open VPN (Remote Dial-In User only)\n GRE over IPsec\n PPTP\n L2TP, L2TP over IPsec\n\n\n\n Bandwidth Management\n\n IP-based Bandwidth Limit\n IP-based Session Limit\n User-based Data"a\n\n Quality of Service (Qo S)\n\n Classify via TOS, DSCP, 802.1p, IP Address, Service Type\n 4 Priority Queues\n App Qo S\n Vo IP Prioritization\n Class-based Outbound Traffic Tagging: DSCP & IP Precedence\n\n Management\n\n Local Service: HTTP, HTTPS, Telnet, SSH, FTP, TR-069\n Config File Export & Import\n Import Config from Vigor 2862 & Vigor 2860\n Auto Backup Config to USB (Universal Serial Bus) Storage " New!\n Firmware Upgrade via TFTP, HTTP, TR-069\n 2-Level Administration Privilege\n Access Control Features: Access List, Brute Force Protection\n Syslog\n SMS, E-mail Notification Alert\n SNMP: v 1, v 2c, v 3\n Managed by Vigor ACS\n\n Router Central Management Features\n\n AP Management: Up to 20 Vigor AP access points\n Switch Management: Up to 10 Vigor Switch network switches\n VPN Management: Up to 8 Vigor routers\n\n Operating Requirements\n\n Rack-Mountable (Optional Vigor RM1 mounting bracket required)\n Wall or Shelf Mountable with included fittings\n Temperature Operating: 0 &176;C ~ 45 &176;C\n Storage: -25 &176;C ~ 70 &176;C\n Humidity 10% ~ 90% (non-condensing)\n Power Consumption: 22.8 watts maximum\n Operating Power: DC 12V (via external PSU, supplied)\n Power Requirements: 100-240VAC\n Weight: 620g\n Dimensions:\n\n 241mm Width\n 165mm Depth\n 44mm Height\n\n\n\n Warranty\n\n Two (2) Year Manufacturer's RTB\n Optional Vigor Care Enhanced Warranty Available\n\n Vigor Care B3 3 Year Subscription: VCARE-B3\n Vigor Care B5 5 Year Subscription: VCARE-B5\n\n\n\n Box Contents\n\n Vigor 2866 router\n Quick Start Guide\n Screws & wall plugs for wall mounting\n 2m Cat-5e RJ-45 Network Cable\n DC 12V Power Supply with UK Plug\n\n\n ...
Vigor 300B Quad-WAN Load Balancer Overiew The Vigor 300B is a high-performance quad-WAN load balancer. The Vigor 300B provides high performance with Dray Tek's traditional ease of use & a comprehensive feature set with robust firewalling, flexible content filtering & multiple monitoring methods. Load Balancing & WAN Backup The four Gigabit WAN ports can provide load balancing or WAN failover. In failover mode, additional WAN connections are activated only when your primary or additional normal connectivity if interrupted. The failover/backup connections kick in automatically, keeping you online. In load balanced mode, up to four of the WAN fees are used all of the time, but your load (connections) is spread across all of the active connections, making the best use of your connectivity. Alternatively, the Vigor 300B can be set with load balance policies so that different traffic types use specific connections, for example reserving one connection for latency-sensitive or high priority data, or forcing low-priority data down your slowest connection. Extensive Qo S & VLAN facilities on the Vigor 300B help keep your network efficiency & online productivity at its best. The Vigor 300B can be rack-mounted (brackets provided) or used standalone. ...
Vigor AP-710 Wireless Access Point\n The Dray Tek Vigor AP-710 is a standalone wireless access point, ideal for adding wireless connectivity to an existing LAN, or for expanding the range of an existing wireless LAN by using the WDS features.\n\n As an access point, the Vigor AP-710 connects to your existing ethernet switch or router. Wireless users can then connect to your LAN. You can restrict access to specific devices by locking in their hardware 'MAC address' & if you have a radius server, user access can be further limited requiring unique login using 802.1x authentication (MD5/PEAP mode).\n\n Where you wish to provide wireless access over a larger area, or throughout a larger building, you could install several AP-710's, each wired back to your central network. The AP-710 also supports limited functions within Dray Tek's Wireless management system.\n\n In addition, the AP-710 can operate in several other wireless modes:\n\n Access Point - Standard Operation, as described above\n Universal Repeater - The AP-710 acts as both a wireless client & access point simultaneously, effectively increasing the range of an existing access point.\n Bridge - Using two AP-710's, each connected to a separate wired LAN, a wireless bridge can be formed connecting the two LANs. Ideal where a physical link (cable) isn't possible, for example, across a road.\n Station - The AP-710 acts as a wireless client to another wireless access point. Ideal for games consoles or PCs which need a self-contained 'intelligent' wireless interface with connectivity provided via their Ethernet point.\n ...
Draytek Vigor AP 903 Overview:\n Vigor AP 903 is a high-performance Mesh Wireless solution, designed to expand the wireless coverage, eliminate Wi-Fi dead zones & significantly reduce the cost of network deployments. It can also be used as a traditional access point either managed or stand alone so has the flexibility to be used how you need it.\n\n The Vigor AP 903 is a dual-band 802.11ac Wave 2 Mesh Wireless solution, designed to eliminate wireless drop outs, stuttering videos, slow download speeds, poor signal & Wi-Fi dead zones. One access point acts as the controller (Mesh root) & in total up to 8 access points create an easy to manage wireless mesh. Extend coverage without running expensive cabling.\n Dray Tek Vigor AP 903 Specification:\n Physical Interfaces/ Controls\n\n 5 x Gigabit Ethernet LAN Ports\n USB (Universal Serial Bus) 2.0 Port\n WLAN On/ Off & WPS Button\n Factory Reset Button\n 2 x Dual-Band Omni-directional RP-SMA Antennae\n \n Wireless Performance\n\n AC1300 Class Wireless Access Point\n 5 G Hz: PHY Rate 866 Mb/s\n 2.4 G Hz: PHY Rate 400 Mb/s\n\n\n \n Wireless LAN Compatibility\n\n IEEE 802.11ac (Wave 1 & 2) / a / b / g / n\n Frequency Band 2.4 GHz & 5.8 Ghz - Simultaneous Operation\n Up to 64 clients per radio\n\n\n \n 2.4 G Hz Wireless LAN Features\n\n\n 802.11b, 802.11g, 802.11n\n 20 / 40 MHz\n Up to 400 Mb/s total Wi-Fi throughput (PHY Rate):\n\n 802.11b/g/n: 300 Mb/s PHY rate (150 Mb/s per Spatial Stream)\n 256-QAM: 400 Mb/s PHY rate (200 Mb/s per Spatial Stream)\n\n\n\n\n \n 5 Ghz Wireless LAN Features\n\n\n 802.11ac (Wave 1 & 2) / 802.11n / 802.11a\n 20 / 40 / 80 MHz\n Extended 5 Ghz Band - Channels 36-48, 52-64, 100-140\n DFS/TPC Support\n Multi-User MIMO - New!\n Up to 866 Mb/s total Wi-Fi throughput (PHY Rate):\n\n 802.11a/n: 300 Mb/s PHY rate (150 Mb/s per Spatial Stream)\n 802.11ac: 866 Mb/s PHY rate (433 Mb/s per Spatial Stream)\n\n\n\n\n \n Security Features\n\n Wireless Encryption: WPA2 (802.11i) Encryption\n\n also supports WPA/WEP (Not recommended)\n\n\n Built in 802.1x server (PEAP / EAP-TLS)\n 802.1x RADIUS Proxy (PEAP / EAP-TLS)\n PMK Caching & Pre-authentication\n Wireless Client Isolation\n Control Isolation of 2.4 G Hz & 5 G Hz bands\n Hidden SSIDs (Selectable)\n WPS - Wi Fi Protected Setup\n MAC Address Filtering (ACL) - Up to 256 entries\n Mobile Device Management\n EAPOL Key Retry - New! - Disable EAPOL Key Retry to protect unpatched WLAN clients from KRACK\n\n\n \n Wireless Control Features\n\n Wireless Client Status List in WUI\n Client Limit per radio\n Client Limit per SSID - New! \n Up to four distinct SSIDs (for VLANs) for each frequency band (2.4/5 Ghz)\n MAC Cloning\n Built-in DHCP Server & DHCP Relay\n Trusted DHCP Server IP for WLAN - New! - Only specifed DHCP server IP can assign IP addresses to WLAN clients\n 802.1q VLAN\n Station Control - Time limit wireless connectivity per Station (e.g. 1 hour) & set allowed Reconnection time (e.g. 1 day)\n\n\n \n Wireless Performance Optimisation\n\n Airtime Fairness\n Band Steering\n AP-Assisted Client Mobility\n WMM (Wireless Multi Media)\n Bandwidth Management (Per Station / Per SSID)\n\n\n \n Diagnostic Features\n\n System Log\n Speed Test\n Traffic Graph - AP Traffic & Per Station\n Data Flow Monitor - View live traffic usage per WLAN client\n Wireless LAN Statistics\n Interference Monitor - Built-in Site Surveyor\n\n\n \n Management\n\n Web Interface (HTTP/HTTPS)\n DHCP Client\n TR-069 Control (For Vigor ACS or other TR-069 platform)\n CLI (Command Line Interface) - Telnet\n Firmware upgrade by TR-069/HTTP\n Central AP Management (from compatible Dray Tek router/controller)\n SNMP v 2, v 2c, v 3\n Management VLAN\n LED Control (enable/disable/schedule)\n Configuration File Export (with password) & Import\n Wireless Auto On/ Off - New! - Sound alert / Disable Wireless if Vigor AP is unable to ping specified host\n\n\n \n Power Requirements\n\n Maximum Power Consumption: 12 Watt\n DC 12V via external 100-240v AC/DC PSU (supplied)\n 802.3af Po E via LAN port A1. Requires Po E injector or a Po E switch such as the Vigor Switch P2121 \n\n\n \n Environmental & Physical\n\n Operating Temperature: 0 &176; C to 45 &176; C\n Operating Humidity: 10% to 90% (Non-condensing)\n Physical Dimensions: 107mm (W) x 167mm (H) x 45mm (D)\n Physical
Dimensions with Aerials: 107mm (W) x 305mm (H) x 45mm (D)\n Weight: 370g\n Fitting: Wall Mountable or Free Standing\n Pack Contents: Vigor AP 903 access point, two RP-SMA Omnidirectional aerials, Quick Start Guide, DC 12V PSU\n Warranty: Two (2) Years RTB\n\n\n ...
Available
Draytek Vigor 2927 Dual Ethernet Gigabit WAN Router
Draytek Vigor 2927 Dual Ethernet Gigabit WAN router
We are a provider of IT and networking equipment at competitive prices with friendly and knowledgeable customer service. Our products include PCs, laptops, tablets, routers, network storage and CCTV, including top brands such as HP, Cisco and Apple.
Page Updated: 2022-11-11 12:11:34
Community Generated Product Tags
Oh No! The productWIKI community hasn't generated any tags for this product yet!