Overview |
- Memory:
8GB DDR4 (Vigor3912) 8GB DDR4 + 256GB SSD (Vigor3912S)
The Vigor3912S model comes equipped with a 256GB SSD Memory which has pre-installed Ubuntu OS and Docker applications such as Suricata IDS (Intrusion Detection System)/IPS (Intrusion Prevention System), VigorConnect, etc. to enhance network security.
- 2 x 10G/2.5G/1G SFP+ Fibre configurable WAN/LAN Slots
- 2 x 2.5G/1G/100M/10M Ethernet configurable WAN/LAN ports
- 4 x 1G/100M/10M Ethernet Configurable WAN/LAN ports
- 4 x 1G/100M/10M Ethernet LAN ports with 1 million NAT sessions
- Multi-WAN Load Balancing & Failover
- Quad-Core CPU with 15.6 Gbps NAT throughput**
- 500 x VPN tunnels (including 200 x OpenVPN/ SSL-VPN tunnels) with most security protocols
- Fast VPN throughput, VPN Load Balancing, Failover, and backup for site-to-site applications
- 100 x VLANs for secure and efficient workgroup management
- 1 x RJ-45 console port
- 2 x USB 3.0 ports for external storage (one USB flash drive is supported at any one time)
- High-Availability (with CARP) ensuring 24/7 system uptime
- Object-oriented SPI Firewall
- Multi-subnet WAN/LAN through 802.1Q
- IPv6 & IPv4
- Bandwidth management
- Supports VigorACS 3 Central Management Software for remote management
- SD WAN capability when used with VigorACS 3
- Supports Central AP Management (up to 50 Vigor Access Points) Learn more
- Supports Central Switch Management (up to 30 Vigor Switches) Learn more
- Rack-mountable
- 2 year back to base warranty
** bi-directional(TX+RX) performance |
|
Quad-Core Powerful Enterprise Gateway |
The Vigor3912 series Multi-WAN routers are high-performance enterprise-level broadband routers with 2 x 10Gb SFP+ Fibre configurable WAN/LAN slots, 2 x 2.5GbE configurable WAN/LAN ports, 4 x 1GbE configurable WAN/LAN ports, and 4 x 1GbE fixed LAN ports with 15.6 Gbps max. NAT throughput and Software Acceleration (bi-directional), 1,000k NAT sessions and other enterprise-level features. With the capacity to handle up to 500 VPN tunnels including 200 OpenVPN /SSL-VPN tunnels, and 100 IP subnets simultaneously, Vigor3912 routers are an excellent solution for network applications in corporations, organisations and governments.
The session-based Load Balance feature allows the aggregation of multiple WAN connections to provide a higher speed internet connection. In addition to the Load Balance and Failover multi-WAN functions, the Vigor3912 supports High Availability (Common Address Redundancy Protocol) with hardware redundancy to ensure 24/7 system uptime for all WAN interfaces.
The Central Management feature provides a centralized console to manage your network. It includes AP Management to configure and manage up to 50 DrayTek Access Points, and Switch Management to configure and manage up to 30 DrayTek VigorSwitches.
The Vigor3912S model comes equipped with a 256GB SSD Memory which supports Linux with Docker applications such as Suricata IDS/IPS, VigorConnect, etc. Together with the router’s capacities, these powerful software eliminate the need for additional servers and enforce security options at the door.
|
|
Linux Applications (Vigor3912S Only)
|
The Vigor3912S model comes equipped with a 256GB SSD Memory with pre-installed Ubuntu OS and Docker applications such as Suricata IDS/IPS, VigorConnect, etc. to enhance network security:
- VigorConnect
- Suricata
- Applications on Ubuntu
|
 |
|
 |
|
Linux Application – VigorConnect (Vigor3912S Only) |
The Vigor3912S router supports Docker applications, such as the VigorConnect directly on the device. This capability simplifies network management by allowing the VigorConnect to monitor DrayTek devices without requiring an additional computer. The installation process is straightforward and can be completed through the router’s web user interface (WUI) with just a few clicks. This feature provides a convenient and efficient solution for network administrators to oversee and manage their network infrastructure.
|
 |
|
Linux Application – Suricata (Vigor3912S Only) |
 |
A popular open-source threat detection software for detecting and preventing a wide range of network threats effectively.
Vigor3912S is pre-installed with Linux based application Suricata, an open-source threat detection system that supports more than 60,000 rules, including 6,000+ CVE (Common Vulnerabilities and Exposures) rules, and can detect and prevent a wide range of network threats, such as malware, network intrusions, denial-of-service attacks, data breaches, etc.
Suricata, an intrusion detection system (IDS), monitors LAN and WAN traffic through the router. A log is generated if any unusual activity is detected, which can be sent to the network administrator via the router’s Web Notification function.
Blocking can be achieved with the “Smart Action” feature in the router.
This feature monitors network traffic and detect malicious activity in real time. Suricata works by analysing packets and comparing them to a set of rules to determine whether the traffic is legitimate. If it detects suspicious activity, it can raise an alarm. Suricata is highly customisable and can monitor many network environments, from small homes to large enterprise networks.
|
|
Suricata – The Threat Log Generator |
 |
|
Suricata Features (Vigor3912S Only) |
Statistical Graph
Suricata Statistical Graph presents the timing and frequency of threats. When the mouse hovers over the point representing the most frequent threat, a small menu will pop up to display the number of occurrences of that threat. Additionally, a click on the item will display more details (illustrated in the second image) that are crucial for security enhancement.
|
 |
|
Smart Action (Vigor3912 feature) |
 |
Smart Action allows predefined events to trigger predefined actions. Vigor users can pre-configure up to 64 event-to-action profiles. Actions, such as sending alerts, emails, removing a VPN profile, etc., can be programmed for events such as network conditions, occurrence counts, etc., associated with specified time and date.
– Event → Action: A predefined event triggers the predefined action.
– Web Notification.
– Log Keyword Match (syslog log, console log, Suricata log).
|
1 million NAT sessions
Recommended for a network of up to 500+ devices
Up to 8 WANs
including 10G SFP+ and 2.5G Ethernet
|
Quad-Core CPU
provides 15.6 Gbps NAT throughput**
|
500 x VPN tunnels
provides 5.7 Gbps IPsec throughput
|
500 Hosts
Reserve 2048 entries for Bind-IP-to-MAC
|
|
|
Interface
|
 |
- 1 2 x USB 3.0 ports for external storage (one USB flash drive is supported at any one time)
- 2 Factory Reset Button
- 3 RJ-45 Console Port
- 4 2 x 10G/2.5G/1G SFP+ Fibre configurable WAN/LAN Slots*
- 5 2 x 2.5G/1G/100M/10M Ethernet configurable WAN/LAN ports*
- 6 4 x 1G/100M/10M Ethernet Configurable WAN/LAN ports*
- 6 4 x 1G/100M/10M Ethernet LAN ports with 1 million NAT sessions
*WAN/LAN Switchable |
|
Performance Comparison: Vigor3912 vs. Vigor3910
|
NAT throughput (1.9x times faster)
IPSec throughput (2.1 times faster)
SSL-VPN throughput (2.9 times faster)
Wireguard throughput (3.2 times faster)
**bi-directional(TX+RX) performance
|
|
Maximise Performance with Fast NAT and Fast Routing |
Enhance overall network performance with optimised data packet processing and forwarding. This feature improves network efficiency by improving transmission speed, and enhances user experience by minimising network latency, making it ideal for real-time applications such as large file transfers and voice calls.
|
 |
|
Fibre to the Building/Home |
The Vigor3912 is an ideal choice for tier 2/3 ISPs and co-working spaces
|
 |
High Performance with 10Gb SFP+
For both NAT and routing network, and for both 10Gb-WAN and 10Gb-LAN, Vigor3912 is ready to deliver high throughput to your business.
Layer 3 Routing with BGP and OSPF
With the most popular Exterior and Interior Gateway Protocols, Vigor3912 is ideal for ISP deployment.
Layer 2 Security with PPPoE Server and VLAN
With 200 PPPoE user accounts and 100 VLAN/LAN subnets, the Vigor3912 provides 15.6 Gbps (bi-directional; TX+RX) NAT throughput, making network infrastructure segmentation secure and easy. |
|
Configurable WAN/LAN Ports
|
12 Ports in total
8 ports from a total of 12 ports, can be configured as either a LAN port or a WAN interface. For example, the following port options are achievable:
- 8 x WAN interfaces and 4 x LAN Ports or
- 1 x WAN interface and 11 LAN Ports
|
 |
|
Advanced VPN Features
|
VPN from LAN
This feature offers a more secure method for connecting to servers by restricting LAN clients’ access to LAN servers through a VPN only. This ensures that data transmission between LAN clients and servers is encrypted, protecting critical data and enhancing overall security.
VPN User Isolation
Activating a VPN connection to access a company’s internet for work has become a common routine for many employees.

Teleworkers need to connect to the company’s servers through VPN connections. However, it is often unnecessary for VPN users to access each other, which may pose security risks. By enabling the “Isolate VPN Users from each other” option, you can ensure that each VPN user is isolated and the VPN network is more secure.
2FA with AD/LDAP Server
Enhance the security of remote dial-in VPN connections with two-factor authentication integrated with AD/LDAP servers. DrayTek offers various authentication methods, including TOTP, email, SMS, and URL links. This approach not only adds an extra layer of security but also helps reduce costs associated with SMS messages and official authentication system license fees.

Packet Capture Tool for VPN Tunnel
By either mirroring all packets to the designated LAN port or VPN connection, whether LAN to LAN profile or remote Dial-in users and even downloading PCAP files via WUI remotely and spotting an issue is easier than ever.

|
|
Server Load Balancing
|
For organizations that host multiple servers in their network, a policy of server load balance can be configured, such that the router can distribute the inbound NAT sessions evenly for the servers based on the configured load balance weight. This will avoid excessive load on a single server, prevent server failure due to overloading, and optimise resource usage .
|
 |
|
Port Knocking
|
The Port Redirection function is often used to allow the internal servers to be accessible from the Internet. However, the opened ports present security threats as these can be scanned by hackers and malware. Vigor3912 series employ Port Knocking, a technology that adds an extra layer of protection to the internal servers, by allowing only users with a matching password to open the port and be connected to the server, effectively closing the door for unauthorized accesses.
|
 |
|
All-in-One Management
|
 |
Vigor router provides a management platform for your Vigor devices on the LAN
Auto-Discovery
Automatically discover LAN subnets and add detected VigorSwitch/AP into managed list.
Provisioning
Most-frequent used settings can be pre-defined on the Vigor Router, and provision to the managed VigorSwitch/AP.
Monitoring
Vigor Router provides a centralized view of managing devices, you may always check if the managed Vigor Switch/AP is online.
System Maintenance
Support basic maintenance remotely via Vigor Router. Such as remote reboot, factory reset, configuration backup/restore, etc.
|
Key Features |
Quad-Core Processor Offers excellent performance for bandwidth-demanding enterprise networks.
Hotspot Web Portal Market your business and communicate with the guests while offering hospitality Wi-Fi. Learn more
10G SFP+ Provides 2 x 10G-capable fibre SFP ports for WAN or LAN connection.
Bandwidth Management Control Internet bandwidth usage by users by using the bandwidth limit and session limit policy settings, and prioritise traffic by using the QoS feature.
Load Balancing Maximize throughput and reliability by using multiple Internet connections. Learn more
Firewall & Content Filter Use URL keywords or web categories to filter web pages and block access to insecure or inappropriate content.
VPN (Virtual Private Network) Build a secure and private tunnel from the LAN of Vigor3912 to the remote offices and teleworkers over the Internet. Learn more
DrayDDNS The free DDNS service for you to access the router by a fixed hostname of your choice. Learn more.
SSL VPN SSL VPN works through firewalls providing secure remote access to any network environment. Learn more
Central AP Management Use the Vigor3912 router as a wireless controller to maintain and monitor the VigorAPs. Learn more
PPPoE Server Use Point-to-Point connection on LAN to keep track of individual user’s traffic. Setup Guide
Central Switch Management Set up VLAN easily from the router and get a centralized hierarchy view of the switches. Learn more
VPN 2FA Auth for AD/LDAP Enhance the security for remote VPN connections and eliminate the cost for an official authentication system. Learn more
VPN Matcher Helps routers behind NAT to find each other and establish a LAN-to-LAN VPN. Learn more
|
All-in-One Management |
Vigor Router SWM
|
 |
Central Switch Management
|
- Auto-Discovery
- Auto-Provisioning
- Monitoring
- Centralized Hierarchy View
- Reboot PoE Devices Remotely
- Quick VLAN Configuration
|
|
VigorAP-based APM
|
 |
Central AP Management |
- Auto-Discovery
- Auto-Provisioning
- Monitoring
- Centralized View
- Alarm
- Reboot VigorAP Remotely
- Wi-Fi Client Load Balancing
|
|
Software Management |
VigorACS 3
|
 |
VigorACS 3
|
- Zero Touch Deployment & Provisioning
- Auto VPN
- Interface Quality & SLA
- VoIP Optimization & Monitoring
- Application Visibility
- Application Based SD-WAN Policy
- Customized Hotspot Page with Multilingual
- Hotspot Clients Analytics
- ACS Server Load Balancing / Failover
|
|
In-the-box |
 Power Cord
 Quick Start Guide
|
|
Models |
Vigor3912S |
Octuple-WAN broadband router with Quad-Core CPU and 8G DDR4 memory, 2 x 10Gb SFP+ Fibre WAN/LAN slots, 2 x 2.5GbE WAN/LAN ports, and 4 x fixed GbE LAN ports; support SPI Firewall, 500 x VPN tunnels including 200 x SSL-VPN tunnels. The Vigor3912S model also has 256GB SSD memory for Suricata IDS/IPS and other security apps. |
|
 |
-
Memory: 8GB DDR4 + 256GB SSD
The Vigor3912S model comes equipped with a 256GB SSD Memory which has pre-installed Ubuntu OS and Docker applications such as Suricata IDS (Intrusion Detection System)/IPS (Intrusion Prevention System), VigorConnect, etc. to enhance network security.
- 2 x 10G/2.5G/1G SFP+ Fibre configurable WAN/LAN Slots
- 2 x 2.5G/1G/100M/10M Ethernet configurable WAN/LAN ports
- 4 x 1G/100M/10M Ethernet Configurable WAN/LAN ports
- 4 x 1G/100M/10M Ethernet LAN ports with 1 million NAT sessions
- Multi-WAN Load Balancing & Failover
- Quad-Core CPU with 15.6 Gbps NAT throughput**
- 500 x VPN tunnels (including 200 x OpenVPN/ SSL-VPN tunnels) with most security protocols
- Fast VPN throughput, VPN Load Balancing, Failover, and backup for site-to-site applications
- 100 x VLANs for secure and efficient workgroup management
- 1 x RJ-45 console port
- 2 x USB 3.0 ports for external storage (one USB flash drive is supported at any one time)
- High-Availability (with CARP) ensuring 24/7 system uptime
- Object-oriented SPI Firewall
- Multi-subnet WAN/LAN through 802.1Q
- IPv6 & IPv4
- Bandwidth management
- Supports VigorACS 3 Central Management Software for remote management
- SD WAN capability when used with VigorACS 3
- Supports Central AP Management (up to 50 Vigor Access Points) Learn more
- Supports Central Switch Management (up to 30 Vigor Switches) Learn more
- Rack-mountable
- 2 year back to base warranty
** bi-directional(TX+RX) performance |
|
Vigor3912 |
Octuple-WAN broadband router with Quad-Core CPU and 8G DDR4 memory, 2 x 10Gb SFP+ Fibre WAN/LAN slots, 2 x 2.5GbE WAN/LAN ports, and 4 x fixed GbE LAN ports; support SPI Firewall, 500 x VPN tunnels including 200 x SSL-VPN tunnels. |
|
 |
- Memory: 8GB DDR4 (Vigor3912)
- 2 x 10G/2.5G/1G SFP+ Fibre configurable WAN/LAN Slots
- 2 x 2.5G/1G/100M/10M Ethernet configurable WAN/LAN ports
- 4 x 1G/100M/10M Ethernet Configurable WAN/LAN ports
- 4 x 1G/100M/10M Ethernet LAN ports with 1 million NAT sessions
- Multi-WAN Load Balancing & Failover
- Quad-Core CPU with 15.6 Gbps NAT throughput**
- 500 x VPN tunnels (including 200 x OpenVPN/ SSL-VPN tunnels) with most security protocols
- Fast VPN throughput, VPN Load Balancing, Failover, and backup for site-to-site applications
- 100 x VLANs for secure and efficient workgroup management
- 1 x RJ-45 console port
- 2 x USB 3.0 ports for external storage (one USB flash drive is supported at any one time)
- High-Availability (with CARP) ensuring 24/7 system uptime
- Object-oriented SPI Firewall
- Multi-subnet WAN/LAN through 802.1Q
- IPv6 & IPv4
- Bandwidth management
- Supports VigorACS 3 Central Management Software for remote management
- SD WAN capability when used with VigorACS 3
- Supports Central AP Management (up to 50 Vigor Access Points) Learn more
- Supports Central Switch Management (up to 30 Vigor Switches) Learn more
- Rack-mountable
- 2 year back to base warranty
** bi-directional(TX+RX) performance |
|
Config Demo |
 |
|
|
|
|
 |
|
 |
|