|
| Overview | ||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||
| 10-Gigabit High-Speed Multi-WAN Security VPN Routers | ||||||||||||||||||||||||||||||||||||||||||||
Apart from the Gigabit Ethernet WAN port (P1) for broadband services that use an Ethernet interface (such as UFB in New Zealand or FTTP, FTTC, HFC, Satellite, and Fixed Wireless in Australia), all models feature a triple-combo port with two additional WAN options: a 10GbE SFP+ WAN slot (P2), a 10GbE Ethernet WAN/LAN port (P3), and a 10GbE SFP+ LAN slot (P4). Any two of these three ports can be used simultaneously, and port P3 can also be configured as a high-speed LAN port when not serving as the WAN. 4G LTE connectivity is also featured (via an attached 4G USB modem), and all WAN interfaces can be configured for use in Load Balance mode or Failover mode. Equipped with an object-oriented SPI Firewall, IPv6, 50 simultaneous IPsec/OpenVPN/WireGuard VPN tunnels, Tag-based VLAN, multiple subnets and a set of traffic management features, these routers are an excellent choice for SOHO to business markets. Central Management features provide a centralised console to manage networks, including Virtual AP Controller to configure and to manage up to 20 DrayTek wireless Access Points, and Virtual Switch Controller to configure and to manage up to 10 DrayTek switches. These routers can be mounted using a 1RU rack mount bracket (DR101) on a standard 19” rack or cabinet. | ||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||
| Interface | ||||||||||||||||||||||||||||||||||||||||||||
![]() | ||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||
| *Only two of these ports can be active at the same time, and P2 & P3 cannot both act as WAN | ||||||||||||||||||||||||||||||||||||||||||||
| 10 Gigabit for Next-Generation Connectivity | ||||||||||||||||||||||||||||||||||||||||||||
| The Vigor2928 is a high-performance Multi-WAN VPN router, delivering ultra-fast 10GbE connectivity through three versatile interfaces. It features advanced capabilities including VPN, QoS, route policy, web content filtering, and a hotspot web portal, making it an ideal solution for modern business networks. | ||||||||||||||||||||||||||||||||||||||||||||
![]() | ||||||||||||||||||||||||||||||||||||||||||||
| *VPN acceleration future supported | ||||||||||||||||||||||||||||||||||||||||||||
| Multiple 10GbE WAN Load Balancing | ||||||||||||||||||||||||||||||||||||||||||||
WAN Load BalancingVigor2928 offers high throughput with load balancing, making it ideal for fibre and 10 Gigabit Internet. All active WAN interfaces join the Load Balance Pool to optimise bandwidth utilisation Seamless FailoverSupports automatic WAN failover to maintain seamless internet connectivity during ISP outages, reducing downtime and associated costs. Policy-Based RoutingRouting policies allows user to assign specific WAN interfaces to applications, VoIP, or traffic by source or destination, enhancing network efficiency and performance. | ||||||||||||||||||||||||||||||||||||||||||||
![]() | ||||||||||||||||||||||||||||||||||||||||||||
| Effortless and Secure VPN Access with EasyVPN | ||||||||||||||||||||||||||||||||||||||||||||
![]() | ||||||||||||||||||||||||||||||||||||||||||||
Setting up a VPN can often be complex, involving protocol selection, manual configurations, and troubleshooting, especially for non-technical users. While Vigor routers support advanced VPN protocols such as IPsec, WireGuard, and OpenVPN, traditional setup methods can be time-consuming and daunting. EasyVPN simplifies this process by offering a streamlined, hassle-free solution for secure remote connectivity. With EasyVPN, users can quickly establish encrypted connections without the need to:
By automating these steps, EasyVPN delivers a fast, secure, and intuitive VPN experience—perfect for businesses and users who want robust protection without the technical complexity.
| ||||||||||||||||||||||||||||||||||||||||||||
| IAM (Identity and Access Management) | ||||||||||||||||||||||||||||||||||||||||||||
| Vigor2928 with the new DrayOS 5 is Zero Trust ready! | ||||||||||||||||||||||||||||||||||||||||||||
Precise Device Authentication | ||||||||||||||||||||||||||||||||||||||||||||
| Leverages each device’s unique IP and MAC address to establish accurate, reliable identification and authentication. | ||||||||||||||||||||||||||||||||||||||||||||
Role-Based Access Control | ||||||||||||||||||||||||||||||||||||||||||||
| IAM assigns access permissions based on user roles, enabling IT teams to enforce secure access policies aligned with departments, authority levels, and responsibilities. | ||||||||||||||||||||||||||||||||||||||||||||
Holistic Security | ||||||||||||||||||||||||||||||||||||||||||||
| Combines user, device, and session-based policies to deliver layered protection, strengthening security without reliance on a single factor. | ||||||||||||||||||||||||||||||||||||||||||||
Enhanced Incident Response | ||||||||||||||||||||||||||||||||||||||||||||
| When a security incident occurs, you can quickly identify affected devices and take prompt, targeted action. | ||||||||||||||||||||||||||||||||||||||||||||
![]() | ||||||||||||||||||||||||||||||||||||||||||||
| IAM – Hotspot Web Portal | ||||||||||||||||||||||||||||||||||||||||||||
| Vigor2928 with the new DrayOS 5 is Zero Trust ready! | ||||||||||||||||||||||||||||||||||||||||||||
IAM Integration with Hotspot Web Portal | ||||||||||||||||||||||||||||||||||||||||||||
| Running on DrayOS 5, the Vigor2928 delivers built-in IAM and advanced security capabilities, making it ready for Zero Trust deployments. | ||||||||||||||||||||||||||||||||||||||||||||
Role-Based Access Control | ||||||||||||||||||||||||||||||||||||||||||||
| IAM assigns access permissions based on user roles, enabling IT teams to enforce secure policies aligned with departments, authority levels, and responsibilities. | ||||||||||||||||||||||||||||||||||||||||||||
Holistic Security | ||||||||||||||||||||||||||||||||||||||||||||
| Combines user-, device-, and session-based policies to provide layered protection without relying on a single factor. | ||||||||||||||||||||||||||||||||||||||||||||
Enhanced Incident Response | ||||||||||||||||||||||||||||||||||||||||||||
| Allows rapid identification of affected devices, enabling quick and targeted action when security incidents occur. | ||||||||||||||||||||||||||||||||||||||||||||
![]() | ||||||||||||||||||||||||||||||||||||||||||||
| Stealth Security Protection with Port Knocking | ||||||||||||||||||||||||||||||||||||||||||||
DrayTek’s Port Knocking technology adds an advanced stealth security layer by keeping critical network services completely invisible to unauthorised users. Instead of exposing management ports or VPN services to the public internet, Port Knocking requires a predefined “knock” sequence before access is granted, ensuring that only trusted users can discover and use these services. By integrating three powerful functions, Port Knocking provides robust protection against port scanning, brute-force attacks, and unauthorised access. Port Redirection
VPN Service Control (WAN Binding)
How It Works
With DrayTek Port Knocking, your network operates in stealth mode, invisible to attackers yet instantly accessible to authorised administrators and remote users. It is the ideal solution for organisations that demand high-level security without compromising accessibility. | ||||||||||||||||||||||||||||||||||||||||||||
| URL Reputation | ||||||||||||||||||||||||||||||||||||||||||||
URL Reputation is a cloud-based threat intelligence service that adds an extra layer of security to protect LAN clients during their online activities. With a total of 82 content categories, including 10 security-focused ones, it provides comprehensive and up-to-date protection for both home and business networks. These categories cover a wide range of areas—from malware, spyware, and adware, to parental controls, business productivity, and social networking—helping to create a safer online environment, enhance employee productivity, and support efficient bandwidth management. | ||||||||||||||||||||||||||||||||||||||||||||
![]() | ||||||||||||||||||||||||||||||||||||||||||||
| IP Reputation | ||||||||||||||||||||||||||||||||||||||||||||
Every internet communication involves source and destination IP addresses. Cybercriminals often exploit known malicious IPs to launch attacks using various techniques, including:
| ||||||||||||||||||||||||||||||||||||||||||||
![]() | ||||||||||||||||||||||||||||||||||||||||||||
| IP Reputation helps identify and block traffic from these high-risk IP addresses, adding an essential layer of network protection against cyber threats. | ||||||||||||||||||||||||||||||||||||||||||||
Blocking communication with malicious IP addresses is critical for network security. However, relying on static blocklists is no longer effective, as they lack the real-time, predictive intelligence needed to combat evolving threats. The IP Reputation Service addresses this challenge by delivering dynamic, real-time scoring and classification of IP addresses. It enables the automatic blocking of:
The system evaluates IPs based on multiple factors, including infection history, protocol behaviour, and attack frequency. Each IP is assigned a reputation score, which determines whether it should be trusted, monitored, or blocked, ensuring proactive and intelligent network protection. | ||||||||||||||||||||||||||||||||||||||||||||
You can purchase a URL Reputation A card for your Vigor2928 series
| ||||||||||||||||||||||||||||||||||||||||||||
| Unified Mesh & AP Management | ||||||||||||||||||||||||||||||||||||||||||||
| The Virtual Controller offers two deployment modes, providing flexible and efficient network management. | ||||||||||||||||||||||||||||||||||||||||||||
![]() | ||||||||||||||||||||||||||||||||||||||||||||
Mesh Mode | ||||||||||||||||||||||||||||||||||||||||||||
| Automatically forms a self-healing wireless mesh network, with the Vigor2928 as the Root AP and up to 7 Node APs, delivering easy, scalable, and reliable Wi-Fi coverage. | ||||||||||||||||||||||||||||||||||||||||||||
AP Management Mode | ||||||||||||||||||||||||||||||||||||||||||||
| For networks with more than 8 APs, the Virtual Controller switches to AP Management mode, allowing centralised control of up to 20 APs directly through the router’s interface. | ||||||||||||||||||||||||||||||||||||||||||||
| Seamless Mesh Role Assignment | ||||||||||||||||||||||||||||||||||||||||||||
| When powered on, devices automatically discover each other and assign roles as Root or Node Aps, no manual setup required. This streamlined process enables rapid mesh network formation with optimised coverage and self-healing reliability. | ||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||
| Key Features | ||||||||||||||||||||||||||||||||||||||||||||
Supports 10G-capable fibre SFP+ ports for high-speed fibre WAN or LAN connectivity.
| ||||||||||||||||||||||||||||||||||||||||||||
| Central Switch Manager (SWM) | ||||||||||||||||||||||||||||||||||||||||||||
The Central Switch Manager (SWM) provides a comprehensive solution for simplifying network administration. It automatically detects and manages all compatible VigorSwitches from a single, centralised interface, eliminating the need to configure each device individually. Administrators can efficiently push configurations to multiple switches and monitor their real-time status to ensure network stability. SWM also streamlines advanced management tasks, allowing easy implementation of VLAN segmentation and Quality of Service (QoS) policies. This consolidated approach reduces maintenance time and boosts the overall efficiency and reliability of your network infrastructure | ||||||||||||||||||||||||||||||||||||||||||||
| SWM | ||||||||||||||||||||||||||||||||||||||||||||
![]() | ||||||||||||||||||||||||||||||||||||||||||||
| The Vigor2928 Series can function as a master controller, managing and monitoring up to 5 switches. It also provides full visibility into powered devices (PDs) connected behind the switches, such as IP cameras and access points. | ||||||||||||||||||||||||||||||||||||||||||||
| Device Management | ||||||||||||||||||||||||||||||||||||||||||||
![]() | ||||||||||||||||||||||||||||||||||||||||||||
| Monitor the status, firmware version, and uptime of all managed switches in real time. | ||||||||||||||||||||||||||||||||||||||||||||
| Port Profile | ||||||||||||||||||||||||||||||||||||||||||||
![]() | ||||||||||||||||||||||||||||||||||||||||||||
| Create multiple port profiles to easily configure PoE, VLAN, QoS, and other settings across selected switches. | ||||||||||||||||||||||||||||||||||||||||||||
| Maintenance | ||||||||||||||||||||||||||||||||||||||||||||
![]() | ||||||||||||||||||||||||||||||||||||||||||||
| Easily perform configuration backups and restores, remote reboots, or factory resets. | ||||||||||||||||||||||||||||||||||||||||||||
| Software Management | ||||||||||||||||||||||||||||||||||||||||||||
VigorACS 3 | ||||||||||||||||||||||||||||||||||||||||||||
![]() | ||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||
| In-the-box | ||||||||||||||||||||||||||||||||||||||||||||
Note: The throughput figures are maximum, based on DrayTek internal testing with optimal conditions. The actual performance may vary depending on the different network conditions and applications activated. | ||||||||||||||||||||||||||||||||||||||||||||
| Config Demo | ||||||||||||||||||||||||||||||||||||||||||||
![]() | ||||||||||||||||||||||||||||||||||||||||||||
Click below for the Config Demo Page: | ||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||
![]() |




















