Call us: +61 2 9838 8899
FAX: +61 2 9838 8818

Vigor2862Vac

Multi-WAN VDSL2/ADSL2+ & Gigabit Ethernet WAN Firewall router with 32 x VPN tunnels, 802.11ac (AC2000) Wi-Fi, and VoIP

  • VDSL2/ADSL2+, Gigabit Ethernet WAN port, Dual USB ports for failover and load-balancing
  • Two USB 2.0 ports for connection to two 3.5G/4G LTE USB mobiles, FTP server and network printer
  • 4 x Gigabit LAN ports with multiple subnets and 60,000 NAT sessions
  • Integrated IEEE 802.11ac (AC2000) wireless Access Point; dual band; up to 1.7Gbps throughput
  • Increased IP addresses (1022) and IP subnets (8)
  • VoIP (2 x FXS and 1 x FXO Line Port) for Vigor2862Vac
  • Object-based SPI Firewall and CSM (Content Security Management) for network security
  • 16 x VLANs for secure and efficient workgroup management
  • 32 x VPN and 16 x SSL-VPN tunnels with Load Balance and Redundancy
  • Fast VPN throughput
  • VPN load-balancing and backup for site-to-site applications
  • Embedded Central VPN Management for 8 remote Vigor routers
  • Embedded Central AP Management for multi-deployed Vigor wireless access points
  • Working with Smart Monitor Network Traffic Analyzer (30-nodes)
  • Working with VigorACS 2 Central Management for multi-site deployment
  • Overview
  • Vigor2862 Series is a VDSL2/ADSL2+ Security Firewall router which is compatible with variants of ADSL and VDSL. All the models have an RJ-11 DSL port, and a Gigabit Ethernet WAN port which can be used with a cable-modem to connect to a second line for load balancing or failover, there are also two USB ports which can work with 3G/4G/LTE USB modems to add wireless connectivity. Vigor2862 Series features comprehensive firewall and content security management (CSM) to secure the local network.It can also be a central management portal for Vigor APs and Vigor Switches, providing Network Administrator a simpler way to maintain all the network devices.

    Advanced features

    1. Faster Wi-Fi speed 802.11ac Wave 2 dual-band wireless for speed up to 1.7Gbps (ac/Vac model) compared to 1300 Mbps for the Vigor2860.
    2. Increased number of IP addresses supported IP Pool Count (up to 1022) for LAN1~3 subnet, compared to 253 for Vigor2860
    3. Increased number of IP subnets (8 in Vigor2862 compared to 6 in Vigor2860)
    4. Increased number of VLANS (16 in Vigor2862 compared to 8 in Vigor2860)
    5. Faster processor in Vigor2862
    6. Faster throughput in Vigor2862 compared to Vigor2860 (400 Mbps for 2862 compared to 300 Mbps in 2860)
    7. Faster VPN throughput in Vigor2862
    8. Increase in number of NAT sessions supported (60,000 in Vigor2862 compared to 50,000 in 2860)

    Vigor2862 Series

    ModelVigor2862Vigor2862nVigor2862acVigor2862Vac
    Product
    VDSL2 or ADSL2/2+
    Gigabit WAN
    3G/4G LTEUSBUSBUSBUSB
    Gigabit LAN4444
    VPN Tunnels32323232
    Wireless LAN11n11ac11ac
    VoIP (2xFXS, 1xPSTN)

    Vigor2862 Series VS Vigor2860 Series

    ModelVigor2862acVigor2860acVigor2862nVigor2860n
    Product
    CPU Speed720MHz600MHz720MHz600MHz
    Flash128M128M128M128M
    Memory128M128M128M128M
    Wi-Fi2.4GHz: 11b/g/n
    5GHz: 11a/n/ac
    2.4GHz: 11b/g/n
    5GHz: 11a/n/ac
    2.4GHz: 11b/g/n2.4GHz: 11b/g/n
    Wi-Fi Link Rate2.4GHz: 300Mbps
    5GHz: 1733Mbps
    2.4GHz: 300Mbps
    5GHz: 1300Mbps
    2.4GHz: 300Mbps2.4GHz: 300Mbps
    MIMO2.4GHz: 2×2 SU-MIMO
    5GHz: 4×4 SU-/MU-MIMO
    2.4GHz: 2×2 SU-MIMO
    5GHz: 3×3 SU-MIMO
    2.4GHz: 2×2 SU-MIMO2.4GHz: 2×2 SU-MIMO
    Spatial Stream2.4GHz: 2
    5GHz: 4 (SU-MIMO)/3 (MU-MIMO)
    2.4GHz: 2
    5GHz: 3
    2.4GHz: 22.4GHz: 2
    Wi-Fi Channel2.4GHz: 40MHz
    5GHz: 80MHz
    2.4GHz: 40MHz
    5GHz: 80MHz
    2.4GHz: 40MHz2.4GHz: 40MHz
    TX Beam Forming
    QAM2.4GHz: 64 QAM
    5GHz: 256 QAM
    2.4GHz: 64 QAM
    5GHz: 256 QAM
    2.4GHz: 64 QAM2.4GHz: 64 QAM
    NAT Session60K60K60K60K
    LAN Subnet8686
    IP Pool CountUp to 1022 for Subnet 1-3253 per SubnetUp to 1022 for Subnet 1-3253 per Subnet
  • Features
  • Comprehensive DSL Connectivity

    The VDSL/ADSL modem built-in Vigor2862 Series is compatible with various versions of xDSL, including ADSL, ADSL2, ADSL2+, VDSL, and VDSL2, automatically fall back is also supported.

    WAN Load Balancing & Failover

    Except for the DSL interface, there is also a Gigabit Ethernet WAN port that can be used for any types of connection and add an additional connectivity to share the traffic load. 3G/4G/LTE USB modem can also be attached to the USB ports of the router, and offer wireless Internet connectivity in case the fixed lines are not available, In fact, all of the WAN interfaces can be configured to operated in either Load Balancing mode, which will be active all the time, or in Failover mode, which will be active only when detecting connection loss or heavy load on the primary connection.

    On Vigor2862 Series, Load Balancing can be set in either IP-based mode, which means the packets destined to different IP address will be distributed across different WANs, or Session-based mode, which means the packets belong to different sessions can take different paths, this allows a multiple-session connection to be established across multiple WANs, and the maximum data rate will be all the WAN’s bandwidth combined. Policy-based Load Balancing is also supported so that you may specify the path for some certain packets.

    To increase network accessibility more, Vigor2862 Series also support High Availability feature and allows one or more redundant Vigor2862B Series to be added to the network and operated in standby mode.

    Flexible LAN Management

    The 4-port Gigabit Ethernet switch on the LAN side provides high-speed connectivity for the servers and PCs on the local network, and the Virtual LAN (VLAN) features allow you to separate the LAN clients into different logical domains thus to increase the security and network efficiency. Vigor2862 Series support 802.1Q standard and can build a Tag-based VLAN system with an 802.1Q-support switch, Port-based VLAN is also supported that each LAN port can be configured as a member of different VLAN and be isolated from each other without the use of VLAN tag. Moreover, up to 8 IP subnet can be set up on Vigor2862 Series, so each VLAN can use different IP addressing space.

    Vigor2862 Series has implemented an integrated solution to work as a public Wi-Fi hotspot. While providing Internet access to the guest users, the Hotspot Web Portal can be used to collect the users’ information, informing the terms and conditions, and presenting a landing page to them.

    Firewall & Security

    Vigor2862 Series support Stateful Packet Inspection (SPI) Firewall and flexible filtering rules, it can accept or deny packets based on the information in the packet header (such as source IP, destination IP, protocol, and port number) or the packet’s application. IP-based restrictions can be set to filter certain HTTP traffic as well as various application software and help you to prevent time and network resource wasting on inappropriate network activities.

    With an annual subscription to Cyren Web Content Filtering service, you may also filter the websites by their categories, and set up restrictions to block the whole categories of websites (such as Social Networking, Gambling.. etc.) without the need to specify every site you would like to block. The Cyren service is constantly updating the categorization, and a free 30-day trial is included in every new router.

    The Vigor2862 Series firewall also includes DoS (Denial of Service) Defense to protect the network against variants of attacks.

    Comprehensive VPN

    Vigor2862 Series support both LAN-to-LAN VPN and Remote Dial-in VPN, up to 32 VPN tunnels can be set up simultaneously. All the industry standard tunneling protocols are supported, including PPTP, L2TP, IPsec, and GRE, and it’s compatible with 3rd party VPN devices.

    Vigor2862 Series also support SSL VPN – a type of VPN based on the very common encryption method which is used by all the HTTPS websites. While the traditional VPN protocols might be filtered by the firewall and NAT of public networks, SSL VPN will be passed as long as the HTTPS is allowed. DrayTek also offers free official client App for Windows, iOS, and Android.

    VPN Trunking is also supported by Vigor2862 Series, this allows you establish two VPN tunnels to the same remote site but through different WAN interfaces. The two trunking tunnels can be set up in load balancing or failover mode.

    Central Management

    Vigor2862 Series can act as a Central Management portal for all the Vigor devices on the network, including VigorAPs, Vigor Switches, and even Vigor Routers. With Central Management feature, device maintenance (such as firmware upgrading, configuration backup and restore) and monitoring can all be done from a single portal, which is the Web User Interface of Vigor2862 Series.

    Vigor2862 Series can manage up to 20 VigorAP on its LAN. Automatic Provisioning can be triggered when a VigorAP newly join the network and this makes AP deployment much faster. You may also get the client or traffic history of all the AP from Vigor2862B Series, and set up load balancing rules for the AP.

    Central Switch Management allows you to manage up to 10 Vigor Switches from Vigor2862 Series, the status of every port can be directly viewed from the router. Vigor2862 Series also support VLAN configuration for the switches, setting that matches the router’s VLAN settings and the switch hierarchy is automatically provided which makes the VLAN configuration much simplified.

  • Specifications
    1. Hardware Interface
      • 1 x ADSL2/VDSL2, RJ-11 (WAN-1)
      • 1 x 10/100/1000Base-TX, RJ-45 (WAN-2) (for standard )
      • 4 x 10/100/1000Base-TX LAN, RJ-45, Configurable Physical DMZ on Port4
      • 2 x USB Host 2.0
      • 1 x Factory Reset Button
      • 2 x Detachable Antennas (n model)
      • 4 x Detachable Antennas (ac/Vac model)
      • 1 x Wireless On/ Off/ WPS Button (n/ac/Vac model)
      • Dimension : L241*W165*H44 (mm)
    2. Wi-Fi Frequency
      • 11b/g/n :
        • 2.412 ~ 2.462GHz (USA)
        • 2.412 ~ 2.472GHz (Europe ETSI)
      • 11a/n/ac :
        • 5.150 – 5.250 & 5.725 – 5.825 GHz (USA)
        • 5.150 – 5.250 & 5.470 – 5.725GHz (Europe ETSI)
    3. Wireless Transmit Power
      • 2.4 GHz Max : 19 dBm
      • 5 GHz Max : 29 dBm
    4. Operating Requirement
      • Operating: 0°C ~ 45°C
      • Storage: -25°C ~ 70°C
      • Humidity: 10%~90% (non-condensing)
      • Power: DC 12V @ 1.5A~2A
      • Power Consumption:19~24 watt
    5. ADSL
      • ANSI T1.413 (ADSL)
      • ITU G.992.1 G.dmt (ADSL)
      • ITU G.992.2 G.lite (ADSL)
      • ITU G.992.3 (ADSL2)
      • ITU G.992.3 Annex M/J (ADSL2)
      • ITU G.992.5 (ADSL2+)
      • AITU G.992.5 Annex M/J (ADSL2+)
    6. VDSL
      • ITU G.993.1 (VDSL), ITU-T G997.1
      • ITU G.993.2 (VDSL2)
      • VDSL Band Plan: 997, 998
      • VDSL2 Profile: 8a, 8b, 8c, 8d, 12a, 12b, 17a, 30a
    7. WAN
      • Support fallback to ADSL2/2+ when fail to connect in VDSL2
      • xDSL WAN:
        • DHCP Client
        • Static IP
        • PPPoE (and pass through)
        • PPPoA
        • MPoA
        • 802.1p/q VLAN Tagging
        • Default VLAN/PVC profile by region
      • Giga Ethernet WAN:
        • DHCP Client
        • Static IP
        • PPPoE
        • PPTP
        • L2TP
        • 802.1q VLAN Tagging
      • USB WAN:
        • Support PPP / DHCP mode (for 3G/4G)
    8. Dual WAN
      • Load Balance and Route Policy : 50 profiles
      • WAN connection failover
      • Multiple-VLAN
    9. LAN
      • Support IPv6 LAN
      • Port-based / Tag-based VLAN
      • Bind IP to MAC Address:
        • Disable / Enable / Strict Bind
        • IP Bind list: 1024 entries
      • LAN Port Mirror
      • Wired 802.1x
      • Web Portal
      • Support IP Pool Count more than 253 (up to 1022) for LAN1~3 subnet
      • 8 x Multiple Subnet LAN
    10. Firewall
      • NAT:
        • DMZ Host (for DSL / GbE / Backup WAN)
        • Port-Redirection (40 profiles)
        • Open Port (40 profiles)
        • Port Trigger (20 profiles)
      • Object-based Firewall (v3)
      • SPI (Stateful Packet Inspection) (Flow Track)
      • DoS Defense
      • E-Mail alert (DoS Attack/APPE) and logging via syslog
      • Time Schedule Control
      • User Management:
        • User-based / Rule-based
        • Up to 200 Profiles
        • Support external authentication by LDAP/RADIUS/TACACS+
        • Support Data-base & Time-base Quota
        • Schedule Control to delete or disable account automatically
    11. GSM
      • Service Activation Wizard
      • APP Enforcement (IM/P2P Application v3):
        • Up to 32 Profile
        • APPE Signature Upgrade
      • URL Content Filter:
        • URL Access Control (Keyword Blocking)
        • Pass / Block Web Feature(Cookie, Proxy, Upload File extension)
        • Support File Extension Object: Image, Video, Audio, Java, Active X, Compression, Execution, P2P
      • WEB Content Filter:
        • Service activation wizard in main bar
        • Support Cyren/BBjM
        • White/Black list for Keyword Object/Group
      • DNS Filter for WCF/UCF
    12. VPN
      • 32 Simultaneous VPN
      • Protocol: PPTP, IPsec, L2TP, L2TP over IPsec
      • Encryption: MPPE and Hardware-based AES/DES/3DES
      • Authentication: MDS, SHA-1
      • IKE Authentication: Pre-shared Key and Digital Signature (X.509)
      • LAN-to-LAN, Teleworker-to-LAN(Remote Dial-in User)
      • DHCP over IPSec
      • IPSec NAT-Traversal (NAT-T)
      • Dead Peer Detection (DPD)
      • VPN Pass-Through
      • VPN Wizard
      • mOTP
      • SSL VPN: 16 Tunnels
      • Support TLS/SSL Encryption v3.0
      • VPN Trunk with Load Balance / Backup
    13. Routing
      • Static Route (IPv4 up-to 30 entries / IPv6 up-to 40 entries)
      • RIPv2
      • Policy-based Routing
      • Inter-VLAN Routing
    14. Bandwidth Management
      • Bandwidth Limitation
      • Session Limitation (Up to 20 lists)
      • QoS (Quality of Service):
        • Guaranteed bandwidth for VoIP
        • Class-based Bandwidth Guaranteed by user-defined traffic categories
        • DiffServ Code Point classifying
        • 4-level priority for each direction (Inbound/Outbound)
      • Layer-3 (TOS/DSCP) QoS Mapping
      • APP QoS
    15. Central Management
      • AP Management: 20 (independent with External Device feature)
      • VPN Management: 8
      • External Devices: 30
    16. Network Feature
      • Packet Forwarding Acceleration (Default is disabled)
      • DHCP Client/Relay/Server
      • DHCP Option: 1, 3, 6, 51, 53, 54, 58, 59, 60, 61, 66, 125
      • IGMP Proxy V2/V3
      • IGMP Snooping
      • Dynamic DNS
      • LAN DNS/DNS Forwarding
      • DNSSEC
      • NTP client
      • Call Scheduling
      • RADIUS/TACACS+ client
      • Internal RADIUS server
      • Active Directory/LDAP compatible (client)
      • DNS Cache/Proxy
      • UPnP 50 sessions
      • Wake on LAN
      • Bonjour service
      • Support SmartMonitor (Up to 30 PCs)
    17. System Management
      • Web-based user interface (HTTP/HTTPS)
      • Quick Start Wizard
      • Dashboard
      • CLI (Command Line Interface, Telnet/SSH)
      • Administration access control
      • Login Page Greeting
      • Configuration backup/restore
      • Built-in diagnostic function
      • Firmware upgrade via TFTP/FTP/HTTP/TR-069
      • Logging via syslog
      • SNMP V2/V2c/V3
      • Data Flow Monitor
      • Support SMS/E-mail Alert
      • External Device (Master Mode)
      • TR-069
      • TR-104
      • Support Multi-Firmware Upgrade Utility
      • Two-level management (admin/user mode)
    18. USB
      • Printer Sharing
      • File System:
        • Support FAT32 file system
        • Support FTP function for file sharing
        • File explorer
        • Support Samba for file sharing (DrayTek’s own SMB protocol stack)
      • Support USB Temperature Sensor
      • Support USB Device Status for Disk, Modem, Printer and Sensor
      • 3.5G (HSDPA) and 4G (LTE) as WAN3/WAN4 by using USB dongle
    19. Wireless AP (for n/ac/Vac model)
      • Support Single 2.4G (for n model)
      • Support Simultaneous 2.4G/5G Dual-Band (for ac/Vac model)
      • Auto channel selection
      • Multiple SSID
      • Hidden SSID
      • Wireless LAN Isolation
      • Wireless Rate-Control
      • 64/128-bit WEP
      • WPA/WPA2
      • MAC Address Access Control (Total 64 entries)
      • WPS
      • WDS (Wireless Distribution System)
      • WMM
      • Access Point Discovery
      • 802.1x Authentication
      • Station List/Control
      • Wireless Wizard
      • SSID VLAN grouping with LAN port (Port-based VLAN)
    20. VoIP (for Vac model)
      • Protocol: SIP, RTP/RTCP
      • VoIP Wizard
      • VoIP Status
      • 12 SIP Registrars
      • G.168 Line Echo-cancellation
      • Automatic Gain control
      • Jitter Buffer
      • Voice codec:
        • G.711
        • G.723.1
        • G.726
        • G.729 A/B
        • VAD/CNG
      • DTMF Tone:
        • Inband
        • Outband (RFC-2833)
        • SIP Info
      • FAX/Modem Support:
        • Tone Detection
        • G.711 Pass-through
        • T.38 for FAX
      • Supplemental Services:
        • Internal Call (dial 10 or 20 for Phone 1 or Phone 2. Only for debug usage)
        • Call Hold/Retrieve/Waiting
        • Call Waiting
        • Call Waiting with Caller ID
        • Call Transfer
        • Call Forwarding (Always, Busy and No Answer)
        • CLIR (Calling Line Identification Restriction)
        • Call Barring (Incoming/Outgoing)
        • DND (Do Not Disturb)
        • MWI (Message Waiting Indicator) (RFC-3842)
        • Hotline
        • ZRTP
      • PSTN Loop-through When Power Failure
      • Dial Plan:
        • Phone Book
        • Digit Map
        • Call Barring
        • Regional
        • PSTN Setup
  • Deployment Examples
  • Multi-subnets


    The Vigor2862 supports up to 8 LAN IP subnets, an IP Routed subnet and a DMZ port.

    The 8 LAN IP subnets can be assigned to 16 VLANS allowing the creation of logical workgroups to provide additional security and traffic management within an organisation.

    For example, within a building each tenant or workgroup can be assigned their own IP network. In addition, workgroups can also be located in different physical locations or floors within a building. For example, a Sales Department may be located on the 1st floor of a building, but some of the sales people are located on the second floor and still be part of the sales VLAN.

    The IEEE 802.1q VLAN trunk feature means that only a single LAN cable connection is required between the router and the VigorSwitch, create a number of VLANs for different departments.

    The VLAN Tag Priority setting can be used to prioritise traffic for certain VLANS or workgroups.

    Multi-site business deployment


    Increase remote access security to your office by combining both VPN and Firewall features in the Vigor2862.

    The Vigor2862 supports up to 32 simultaneous VPN tunnels (such as IPSec/PPTP/L2TP/SSL protocols) for secure data exchange and communication. In addition, 16 SSL-VPN tunnels are available for teleworkers to access the office LAN. Teleworkers can be authenticated directly with your LDAP server if preferred. The SSL technology is same as the encryption used for secure web sites such as online banking.

    Security is enhanced by utilising firewall features such as web content and URL filtering in addition to restricting access to P2P traffic and Instant Messaging applications.

    The Vigor2862 series is equipped with ADSL2+/VDSL2 and one Gigabit Ethernet port and two USB WAN ports for WAN load-balancing and backup. This allows backup VPN tunnels to be created to branch office networks to ensure maximum VPN connectivity uptime. In addition, the VPN Trunking feature can be used to set up dual VPN tunnel links to branch office networks to increase bandwidth and provide redundancy and backup to prevent downtime due to one of the WAN connections failing.

    Central Management – AP / Switch / VPN Management


    The Central Management features allow the network administrator to monitor and configure Vigor devices including VigorAPs, Vigor Switches, and even Vigor Routers from a central management console built into the Vigor2862 series router. Maintenance tasks such as firmware upgrades, configuration backup and restoration as well as and monitoring be done from a single portal.

    Three options are available in Central Management. These are:

    • VPN Management
    • AP Management
    • Switch Management

    VPN management supports 8 external CPE devices and allows the creation and management of IPSec, PPTP or SSL-VPN tunnels from the central Vigor2862 router to the remote routers.

    The AP Management feature allows the monitoring and auto-configuration of up to 20 DrayTek Access Points connected to the Vigor2862 LAN. Automatic Provisioning can be triggered when a new Access point is connected to the LAN. Other features include client or traffic history of the AP and configuration of load balancing rules for the Access Points.

    Switch Management allows you to manage up to 10 Vigor Switches. It simplifies the task of configuring VLANS in attached VigorSwitches matching the router’s VLAN settings. It also displays the switch status as well as the network topology through the switch hierarchy feature.

    USB Thermometer


    The optional USB thermometer can be attached to the Vigor2862 to provide logging of the ambient temperature in the server room. Upper and lower temperature thresholds can be set and when the temperature exceeds these thresholds and alarm is generated. This alarm can be sent to the network administrator via email or SMS to alert them of the environmental issue.

    802.11ac Wave 2 (for ac/Vac model)

    802.11ac Wave 2 can simultaneously stream to multiple users to maximize bandwidth utilization.


    Vigor2862ac routers now operate 802.11ac Wave 2 Wi-Fi with support for MU-MIMO, TX Beam Forming, 1733Mb/s Link Rate and up to 4 spatial streams. This allows up to 4 wireless clients such as laptops or smartphones to have simultaneous access to a Wi-Fi channel. The result is an increased performance of the Wi-Fi network.

    Flexible Installation with Rackmount


    The Vigor2862 series router can be rack mounted into a standard 19’ rack or cabinet. The 1RU rack mounting kit allows the front panel of the router to be easily accessible as well as keeping it secure in the communications rack.

  • Web Demo
  • Open Link in New Tab http://eu.draytek.com:12862/