• VDSL2/ADSL2+, 1 x configurable GbE WAN/LAN port, dual USB ports for failover and load-balancing
  • Two USB 2.0 ports for connection to two 3.5G/4G LTE USB mobiles, FTP server and network printer

  • 4 x Gigabit LAN ports with multiple subnets and 50,000 NAT sessions
  • Integrated 802.11ac (AC2000) wireless Access Point; dual band; up to 1.7Gbps throughput
  • IPv6 & IPv4
  • Increased IP addresses (1022) and IP subnets (8)
  • VoIP (2 x FXS and 1 x FXO Line Port) for Vigor2862Vac
  • Object-based SPI Firewall and CSM (Content Security Management) for network security
  • 16 x VLANs for secure and efficient workgroup management

  • 32 x VPN tunnels (including 16 x SSL-VPN tunnels) with Load Balance and Redundancy
  • Fast VPN throughput, VPN load-balancing and backup for site-to-site applications
  • High Availability mode
  • Embedded Central VPN Management for 8 remote Vigor routers
  • Central AP Management for deployment of multiple wireless VigorAPs
  • Works with Smart Monitor Network Traffic Analyzer (30-nodes)
  • Supports VigorACS 2 Central Management System for remote management
  • 2 years back to base warranty


The Vigor2862 Series are Security Firewall routers suitable for connecting to ADSL, VDSL and all NBN connection types including FTTN/FTTB, FTTP, FTTC, HFC, Fixed Wireless and Satellite. They also have two USB ports which allow the connection of 3G/4G/LTE USB modems. Other features include a comprehensive firewall and content security management (CSM) to secure the local network, and a central management portal for Vigor APs and Vigor Switches to provide Network Administrators a simpler way to maintain all network devices.

Advanced features

  1. 11ac Wave 2 dual-band wireless (ac/Vac model) providing up to 1.7Gbps.
  2. Supported IP Pool Count up to 1022
  3. Up to 8 IP subnets
  4. Up to 16 VLANs
  5. Fast processor
  6. Fast NAT/Firewall throughput – up to 400 Mbps
  7. Fast VPN throughput

Comprehensive DSL Connectivity

The built-in VDSL/ADSL modem is compatible with various versions of xDSL, including ADSL, ADSL2, ADSL2+, VDSL, and VDSL2.

Multi-WAN Load Balancing & Failover

In addition to the DSL interface, there is also a Gigabit Ethernet WAN port which can be used for any type of Internet connection requiring an Ethernet WAN port including Cable modems, bridged ADSL/VDSL modems and NBN FTTP, FTTC, HFC, Fixed Wireless and Satellite. 3G/4G/LTE USB modems can also be connected to the USB ports of the router, offering wireless Internet connectivity when fixed lines are not available. All of the WAN interfaces can be configured to operate in either Load Balancing mode where all WANs are active all the time, or in Failover mode which brings secondary WANs online only when the primary WAN connection is lost or when under heavy load.

Load Balancing can be set in either IP-based mode, which means packets destined to different IP addresses will be distributed evenly across different WANs, or Session-based mode, which allows packets belonging to different sessions to take different paths. Session-based mode allows a multiple-session connection to be established across multiple WANs, combining the bandwidth of all available WANs simultaneously. Policy-based Load Balancing is also supported so that paths can be specified for particular data packets.

The Vigor2862 Series also features DrayTek High Availability, which allows one or more redundant Vigor2862 routers to be added to the network in standby mode in case of hardware failure.

Flexible LAN Management

The 4-port Gigabit Ethernet switch provides high-speed connectivity for servers and PCs on the local network, and the Virtual LAN (VLAN) feature allows separation of LAN clients into different logical domains to increase network security and efficiency. The Vigor2862 Series supports the 802.1Q standard and can build a Tag-based VLAN system with an 802.1Q-supported switch. Port-based VLAN is also supported so that each LAN port can be configured as a member of a different VLAN, allowing segregation of network segments without the need of a VLAN tag. Up to 8 IP subnets can be configured to allow each VLAN to use different IP addressing spaces.

The Vigor2862 Wi-Fi models also have a built-in public Wi-Fi hotspot solution to provide Internet access to guest users. The Hotspot Web Portal can present a landing page to inform users of any terms and conditions and also ask for information from them such as requiring them to log in with Facebook/Google or to receive a PIN via SMS.

Firewall & Security

The Vigor2862 Series models all feature a Stateful Packet Inspection (SPI) Firewall and flexible filtering rules which can accept or deny packets based on information in the packet header such as source IP, destination IP, protocol and port number, or the packet’s application. IP-based restrictions can be set to filter certain HTTP traffic as well as various application software to help prevent time and network resource wasting on inappropriate network activities.

With an annual subscription to Cyren Web Content Filtering service, websites are classified into categories (such as Social Networking, Gambling, etc.) which can then be blocked or allowed, making content filtering a one click process rather than attempting to go through and check every website one by one. The Cyren service is constantly updated and a free 30-day trial is included in every new router.

The Vigor2862 Series firewall also includes DoS (Denial of Service) Defence to protect the network against a variety of attacks.

Comprehensive VPN

The Vigor2862 Series supports up to 32 simultaneous VPN tunnels which can be any combination of LAN-to-LAN or Remote Dial-in VPN tunnels. All industry standard tunnelling protocols are supported, including PPTP, L2TP, IPsec, and GRE, and they’re compatible with 3rd party VPN devices.

SSL VPN tunnels are also featured, which are a type of VPN based on the same encryption method used by HTTPS websites. Where traditional VPN protocols might be blocked by firewall rules and NAT, SSL VPNs will be passed through as long as HTTPS traffic is allowed. DrayTek also provides the Smart VPN Client as a license-free download for Windows, MacOS, iOS and Android.

VPN Trunking is also supported, which allows VPN traffic to be shared over two VPN tunnels to the same remote site using two different WAN interfaces. The two trunked tunnels can be configured in load balancing or failover mode to either increase link capacity and/or reduce the chance of lost data or downtime in the event of an ISP outage or other Internet link failure.

Central Management

A Vigor2862 Series router can act as a Central Management portal for all Vigor devices on a network including VigorAPs, Vigor Switches, and even Vigor Routers. Central Management allows monitoring and device maintenance such as firmware upgrades, configuration backups and restorations all from a single portal within the Web User Interface.

Up to 20 VigorAPs can be managed by the Vigor2862 Series. The traffic history of each AP can be viewed, load balancing rules established, and Automatic Provisioning can be triggered whenever a new VigorAP joins the network, simplifying and speeding up AP deployment.

Central Switch Management allows management of up to 10 Vigor Switches from the web user interface of a Vigor2862 Series router. The status of every port can be directly viewed, VLANs can be configured to match the router’s VLAN settings, and switch hierarchy is automatically determined to greatly simplify the VLAN configuration process.


VDSL2 or ADSL2/2+
Gigabit WAN
Gigabit LAN4444
VPN Tunnels32323232
Wireless LAN
VoIP (2xFXS, 1xPSTN)


Interface (gDisplayOff)

Fixed WAN Port1x RJ-11
LAN/WAN Switchable Port1x Gigabit Ethernet
Fixed LAN Port4x Gigabit Ethernet
USB Port2x USB 2.0 for 3G/4G/LTE USB modem, storage, printer or thermometer
RJ-11 Port for Voice2x FXS + 1x Life Line (Vac model)
2.4G WLAN300Mbps 802.11n (n/ac/Vac model)
5G WLAN1.7Gbps 802.11ac Wave 2 (ac/Vac model)

Performance (gDisplayOff)

NAT Throughput400 Mbps
NAT Throughput w/ Hardware Acceleration900 Mbps
IPsec VPN Performance90 Mbps (AES 256 bits)
SSL VPN Performance45 Mbps
Max. Number of NAT Sessions50,000
Max. Concurrent VPN Tunnels32
Max. Concurrent SSL VPN16

VDSL/ADSL (gDisplayOff)

VDSL StandardsITU-T G.993.1 (VDSL), G.997.1, G.993.2 (VDSL2)
VDSL2 Profile8a, 8b, 8c, 8d, 12a, 12b, 17a, 30a
VDSL Band Plan997, 998
ADSL StandardsANSI T1.413, ITU-T G.992.1(G.dmt), G.992.2 (G.lite)
ADSL2 StandardsITU-T G.992.3, G.992.3 Annex J
ADSL2+ StandardsITU-T G.992.5, G.992.5 Annex M
DSL ForumTR-114, TR-048/67, TR-100

Internet Connection (gDisplayOff)

Internet Connection
IPv6PPP, DHCPv6, Static IP, TSPC, AICCU, 6rd, 6in4 Static Tunnel
Wireless WAN (n/ac/Vac)
3G/4G/LTE WAN with USB modem2
Load BalancingIP-based, Session-based
WAN Active on DemandLink Failure, Traffic Threshold
Connection DetectionARP, Ping
WAN Data Budget
Dynamic DNS

LAN Management (gDisplayOff)

LAN Management
VLAN802.1q Tag-based, Port-based
Max. Number of VLAN16
DHCP ServerMultiple IP Subnet, Custom DHCP Options, Bind-IP-to-MAC
LAN IP Alias
Wired 802.1x Authentication
Port Mirroring
Local DNS Server
Conditional DNS Forwarding
Hotspot Web Portal
Hotspot AuthenticationClick-Through, Social Login, SMS PIN, RADIUS

Networking (gDisplayOff)

RoutingIPv4 Static Routing, IPv6 Static Routing, Inter-VLAN Routing, RIP, BGP
Policy-based RoutingProtocol, IP Address, Port, Domain, Country
High Availability
DNS Security (DNSSEC)
MulticastIGMP Proxy, IGMP Snooping & Fast Leave, Bonjour
Local RADIUS server
SMB File Sharing (Requires external storage)

VPN (gDisplayOff)

ProtocolsPPTP, L2TP, IPsec, L2TP over IPsec, SSL, GRE, IKEv2, IKEv2-EAP, OpenVPN
User AuthenticationLocal, RADIUS, LDAP, TACACS+, mOTP
IKE AuthenticationPre-Shared Key, X.509
IPsec AuthenticationSHA1, SHA256, MD5
VPN RedundancyLoad Balancing, Failover
Single-Armed VPN
NAT-Traversal (NAT-T)

Firewall & Content Filtering (gDisplayOff)

Firewall & Content Filtering
NATPort Redirection, Open Ports, Port Triggering, DMZ Host, UPnP
ALG (Application Layer Gateway)SIP, RTSP, FTP, H.323
VPN Pass-ThroughPPTP, L2TP, IPsec
IP-based Firewall Policy
Content FilteringApplication, URL, DNS Keyword, Web Features, Web Category* (*: subscription required)
DoS Attack Defence

Bandwidth Management (gDisplayOff)

Bandwidth Management
IP-based Bandwidth Limit
IP-based Session Limit
QoS (Quality of Service)TOS, DSCP, 802.1p, IP Address, Port, Application
VoIP Prioritization

Wireless LAN (n/ac/Vac model) (gDisplayOff)

Wireless LAN (n/ac/Vac model)
Number of SSID4 per radio band
SecurityWEP, WPA, WPA2, WPS
AuthenticationPre-Shared Key, 802.1x
AirTime Fairness
Band Steering (ac model)
WDSBridge, Repeater
Access ControlAccess List, Client Isolation, Hide SSID, Wi-Fi Scheduling

VoIP Gateway (V model) (gDisplayOff)

VoIP Gateway (V model)
SIP Registrars12
Dial PlanPhone Book, Digit Map, Call Barring, Regional
Call FeaturesCall Waiting, Call Transfer, Scheduled DND, Hotline
Voice CodecG.711 A/u law, G.723.1, G.726, G.729 A/B

Management (gDisplayOff)

Local ServiceHTTP, HTTPS, Telnet, SSH, TR-069
Config File Export & Import
Config File CompatibilityVigor2860
Firmware UpgradeTFTP, HTTP, TR-069
2-Level Administration Privilege
Access ControlAccess List, Brute Force Protection
Notification AlertSMS, E-mail
SNMPv2, v2c, v3
Managed by VigorACS
Central AP Management20 VigorAP
Central Switch Management10 VigorSwitch

Physical (gDisplayOff)

Power SupplyDC 12V @ 1.5-2A
Dimension241mm x 166mm x 46mm
Operating Temperature0 to 45°C
Storage Temperature-25 to 70°C
Operating Humidity (non-condensing)10 to 90%

DrayTek Vigor2862Vac Review Published in APC Magazine Issue 455, June 2018

It’s been a while since DrayTek last updated its line of small business DSL modem routers, but the new Vigor is a worthy update, modernising many of the features of the Vigor2860 series without departing dramatically from that baseline.

Aesthetically, the router is consistent with DrayTek’s previous routers: no frills, with LAN, USB, WAN, DSL and phone ports up front for easy access. Only the power plugs into the back of the router. This isn’t pretty when it’s all plugged in – it’s more like a rack mount in miniature than what you might have come to expect from more consumer focused routers – but the DrayTek…


DrayTek Vigor2862Vac Review Published in PC & Tech Authority Magazine Issue Apr 2018



The Vigor2862 supports up to 8 LAN IP subnets, an IP Routed subnet and a DMZ port.

The 8 LAN IP subnets can be assigned to 16 VLANS allowing the creation of logical workgroups to provide additional security and traffic management within an organisation.

For example, within a building each tenant or workgroup can be assigned their own IP network. In addition, workgroups can also be located in different physical locations or floors within a building. For example, a Sales Department may be located on the 1st floor of a building, but some of the sales people are located on the second floor and still be part of the sales VLAN.

The IEEE 802.1q VLAN trunk feature means that only a single LAN cable connection is required between the router and the VigorSwitch, create a number of VLANs for different departments.

The VLAN Tag Priority setting can be used to prioritise traffic for certain VLANS or workgroups.

Multi-site business deployment

Increase remote access security to your office by combining both VPN and Firewall features in the Vigor2862.

The Vigor2862 supports up to 32 simultaneous VPN tunnels (such as IPSec/PPTP/L2TP/SSL protocols) for secure data exchange and communication. In addition, 16 SSL-VPN tunnels are available for teleworkers to access the office LAN. Teleworkers can be authenticated directly with your LDAP server if preferred. The SSL technology is same as the encryption used for secure web sites such as online banking.

Security is enhanced by utilising firewall features such as web content and URL filtering in addition to restricting access to P2P traffic and Instant Messaging applications.

The Vigor2862 series is equipped with ADSL2+/VDSL2 and one Gigabit Ethernet port and two USB WAN ports for WAN load-balancing and backup. This allows backup VPN tunnels to be created to branch office networks to ensure maximum VPN connectivity uptime. In addition, the VPN Trunking feature can be used to set up dual VPN tunnel links to branch office networks to increase bandwidth and provide redundancy and backup to prevent downtime due to one of the WAN connections failing.

Central Management – AP / Switch / VPN Management

The Central Management features allow the network administrator to monitor and configure Vigor devices including VigorAPs, Vigor Switches, and even Vigor Routers from a central management console built into the Vigor2862 series router. Maintenance tasks such as firmware upgrades, configuration backup and restoration as well as and monitoring be done from a single portal.

Three options are available in Central Management. These are:

  • VPN Management
  • AP Management
  • Switch Management

VPN management supports 8 external CPE devices and allows the creation and management of IPSec, PPTP or SSL-VPN tunnels from the central Vigor2862 router to the remote routers.

The AP Management feature allows the monitoring and auto-configuration of up to 20 DrayTek Access Points connected to the Vigor2862 LAN. Automatic Provisioning can be triggered when a new Access point is connected to the LAN. Other features include client or traffic history of the AP and configuration of load balancing rules for the Access Points.

Switch Management allows you to manage up to 10 VigorSwitches. It simplifies the task of configuring VLANS in attached VigorSwitches matching the router’s VLAN settings. It also displays the switch status as well as the network topology through the switch hierarchy feature.

USB Thermometer

The optional USB thermometer can be attached to the Vigor2862 to provide logging of the ambient temperature in the server room. Upper and lower temperature thresholds can be set and when the temperature exceeds these thresholds and alarm is generated. This alarm can be sent to the network administrator via email or SMS to alert them of the environmental issue.