• 1 x Gigabit Ethernet WAN port and 1 x configurable GbE WAN/LAN port for Failover, Load-Balancing and High Availability mode

  • Two USB 2.0 ports for connection to two 3G/4G LTE USB modems, FTP server and network printer
  • 4 x Gigabit LAN ports with multiple subnets and 50,000 NAT sessions
  • 50 x VPN tunnels (including 25 SSL-VPN tunnels) with comprehensive secure protocols
  • Fast VPN throughput, VPN load-balancing and backup for site-to-site applications
  • 16 x VLANs for secure and efficient workgroup management
  • IPv6 & IPv4
  • Up to 1022 IP addresses and 8 IP subnets

  • Integrated IEEE 802.11n wireless Access Point (n model)

  • Integrated IEEE 802.11ac (AC2000) wireless Access Point; dual band; up to 1.7Gbps throughput (ac/Vac model)
  • 2 x FXS and 1 x FXO Line VoIP Port (Vac model)
  • High Availability mode
  • Object-based SPI Firewall and CSM (Content Security Management) for network security
  • Supports VigorACS 2 Central Management System for remote management
  • Central VPN Management for 8 remote Vigor routers
  • Central AP Management for deployment of multiple wireless VigorAPs
  • 2 years back to base warranty

Overview

The Vigor2926 Series provides multi-WAN broadband connectivity to ensure a reliable Internet connection for businesses. Two Gigabit Ethernet WAN ports are featured, which can be configured in either Failover or Load Balancing mode, or alternatively WAN 2 can be configured as an additional LAN port if a second Ethernet WAN connection is not required. Two USB ports are also featured which can work with 3G/4G/LTE USB modems to add wireless Internet access for additional load balancing or failover.

The Vigor2926 Series also have comprehensive security and management features including VLAN, Bandwidth Management, Quality of Service, DNS Control, SPI Firewall, Web Content Filtering and Central Management solutions to provide a reliable and secure business network.

Advanced features

  1. 802.11ac Wave 2 dual-band wireless (ac/Vac models) providing up to 1.7Gbps.
  2. Supported IP Pool Count up to 1022
  3. Up to 8 IP subnets
  4. Up to 16 VLANs
  5. Fast processor
  6. Fast NAT/Firewall throughput – up to 400Mbps.
  7. Fast VPN throughput

WAN Load Balancing & Failover

The Vigor2926 Series feature 1 x Gigabit Ethernet WAN port and 1 x configurable GbE WAN/LAN port that can be used for any type of connection. 3G/4G/LTE USB modems can also be attached to the USB ports of the router, offering wireless Internet connectivity in cases where fixed lines are not available, or just for extra bandwidth or peace of mind. All of the WAN interfaces can be configured to operate in either Load Balancing mode which means they are active all of the time, or in Failover mode which brings extra WANs online only when a loss of connection is detected or when there is heavy load on the primary connection.

Load Balancing can be either IP-based mode, which will distribute the packets destined to different IP address across different WANs evenly, or Session-Based mode, which allows the packets of different sessions to take different paths. This means that a multiple-session connection can be established across multiple WANs, taking advantage of all of the WANs’ bandwidth at the same time. Policy-based Load Balancing is also supported which allows paths to be specified for certain packets.

To increase network reliability, the Vigor2926 Series also offers a High Availability feature which allows one or more Vigor2926 Series routers to be added to the network and operate in standby mode for redundancy.

Flexible LAN Management

The 4-port Gigabit Ethernet switch on the LAN side provides high-speed connectivity for servers and PCs on the local network, and the Virtual LAN (VLAN) feature allows separation of the LAN clients into different logical domains to increase local network security and efficiency. The 802.1Q standard is supported, which can build a Tag-based VLAN system in conjunction with an 802.1Q supported switch. Alternatively, Port-based VLAN is also supported which allows each LAN port to be configured as a member of a different VLAN group to allow network segregation without the use of VLAN tag.

Firewall & Security

The Vigor2926 Series features a Stateful Packet Inspection (SPI) Firewall and flexible filtering rules which can accept or deny packets based on the information in the packet header such as source IP, destination IP, protocol, and port number, or the packet’s application. IP-based restrictions can be set to filter certain HTTP traffic as well as various application software to help prevent employees wasting time and network resources on inappropriate network activities.

With an annual subscription to Cyren Web Content Filtering service, websites are classified into categories such as Social Networking, gambling and so on, which can then be blocked or allowed, making content filtering a one click process rather than attempting to go through and check every website one by one. The Cyren service is constantly updated and a free 30-day trial is included in every new router.

The Vigor2926 Series firewall also includes DoS (Denial of Service) Defence to protect the network against variants of attacks.

Comprehensive VPN

The Vigor2926 Series supports up to 50 simultaneous VPN tunnels which can be any combination of LAN-to-LAN or Remote Dial-in VPN tunnels. All industry standard tunnelling protocols are supported, including PPTP, L2TP, IPsec, and GRE, and they’re compatible with 3rd party VPN devices.

Up to 25 SSL VPN tunnels are also featured, which are a type of VPN based on the same encryption method used by HTTPS websites. Where traditional VPN protocols might be blocked by firewall rules and NAT, SSL VPNs will be passed through as long as HTTPS traffic is allowed. DrayTek also provides the Smart VPN Client as a license-free download for Windows, MacOS, iOS and Android.

VPN Trunking is also supported, which allows VPN traffic to be shared over two VPN tunnels to the same remote site using two different WAN interfaces. The two trunked tunnels can be configured in load balancing or failover mode to either increase link capacity and/or reduce the chance of lost data or downtime in the event of an ISP outage or other Internet link failure.

Centralised Management

A Vigor2926 Series router can act as a Central Management portal for all Vigor devices on a network including VigorAPs, Vigor Switches, and even Vigor Routers. Central Management allows monitoring and device maintenance such as firmware upgrades, configuration backups and restorations all from a single portal within the Web User Interface. The Vigor2926 Series also features CVM (Central VPN Management), an easier way for Network administrators to establish and manage VPN connections between several CPEs (VPN Client).

The Vigor2926 Series routers support the TR-069 protocol, allowing them to be remotely managed and monitored by network administrators using the TR-069-based VigorACS system, reducing the need for many on-site visits.

Models

ModelVigor2926Vigor2926nVigor2926acVigor2926Vac
Product
Gigabit WAN2222
3G/4G LTEUSBUSBUSBUSB
Gigabit LAN4444
VPN Tunnels50505050
Wireless LAN
11n11ac (AC2000)11ac (AC2000)
VoIP (2xFXS, 1xFXO)

Specifications

Interface
Fixed WAN Port1x Gigabit Ethernet
LAN/WAN Switchable Port1x Gigabit Ethernet
Fixed LAN Port4x Gigabit Ethernet
USB Port2x USB 2.0 for 3G/4G/LTE USB modem, storage, printer or thermometer
RJ-11 Port for Voice2x FXS + 1x Life Line (Vac model)
2.4G WLAN300Mbps 802.11n (n/ac/Vac model)
5G WLAN1.7Gbps 802.11ac Wave 2 (ac/Vac model)
Performance
NAT Throughput500 Mbps
NAT Throughput w/ Hardware Acceleration900 Mbps
IPsec VPN Performance80 Mbps (AES 256 bits)
SSL VPN Performance45 Mbps
Max. Number of NAT Sessions50,000
Max. Concurrent VPN Tunnels50
Max. Concurrent OpenVPN + SSL VPN25
Internet Connection
IPv4PPPoE, DHCP, Static IP, PPTP/L2TP
IPv6PPP, DHCPv6, Static IP, TSPC, AICCU, 6rd, 6in4 Static Tunnel
Multi-VLAN/PVC
Wireless WAN (n/ac/Vac model)
3G/4G/LTE WAN with USB modem2
Load BalancingIP-based, Session-based
WAN Active on DemandLink Failure, Traffic Threshold
Connection DetectionARP, Ping
WAN Data Budget
Dynamic DNS
DrayDDNS
LAN Management
VLAN802.1q Tag-based, Port-based
Max. Number of VLAN16
DHCP ServerMultiple IP Subnet, Custom DHCP Options, Bind-IP-to-MAC
LAN IP Alias
PPPoE Server
Port Mirroring
Local DNS Server
Conditional DNS Forwarding
Hotspot Web Portal
Hotspot AuthenticationClick-Through, Social Login, SMS PIN, RADIUS
Networking
RoutingIPv4 Static Routing, IPv6 Static Routing, Inter-VLAN Routing, RIP, BGP
Policy-based RoutingProtocol, IP Address, Port, Domain, Country
High Availability
DNS Security (DNSSEC)
MulticastIGMP Proxy, IGMP Snooping & Fast Leave, Bonjour
Local RADIUS server
SMB File Sharing (Requires external storage)
VPN
LAN-to-LAN
Teleworker-to-LAN
ProtocolsPPTP, L2TP, IPsec, L2TP over IPsec, SSL, GRE, IKEv2, IKEv2-EAP, OpenVPN
User AuthenticationLocal, RADIUS, LDAP, TACACS+, mOTP
IKE AuthenticationPre-Shared Key, X.509
IPsec AuthenticationSHA1, SHA256, MD5
VPN RedundancyLoad Balancing, Failover
Single-Armed VPN
NAT-Traversal (NAT-T)
Firewall & Content Filtering
NATPort Redirection, Open Ports, Port Triggering, DMZ Host, UPnP
ALG (Application Layer Gateway)SIP, RTSP, FTP, H.323
VPN Pass-ThroughPPTP, L2TP, IPsec
IP-based Firewall Policy
Content FilteringApplication, URL, DNS Keyword, Web Features, Web Category (subscription required)
DoS Attack Defense
Bandwidth Management
IP-based Bandwidth Limit
IP-based Session Limit
QoS (Quality of Service)TOS, DSCP, 802.1p, IP Address, Port, Application
VoIP Prioritisation
Wireless LAN (n/ac/Vac model)
Number of SSID4 per radio band
SecurityWEP, WPA, WPA2, WPS
AuthenticationPre-Shared Key, 802.1x
AirTime Fairness
Band Steering (ac/Vac model)
WMM
WDSBridge, Repeater
Access ControlAccess List, Client Isolation, Hide SSID, Wi-Fi Scheduling
VoIP Gateway (Vac model)
ProtocolSIP, RTP/RTCP, ZRTP
SIP Registrars12
Dial PlanPhone Book, Digit Map, Call Barring, Regional
Call FeaturesCall Waiting, Call Transfer, Scheduled DND, Hotline
Voice CodecG.711 A/u law, G.723.1, G.726, G.729 A/B
Caller IDFSK_ETSI, FSK_BELLCORE, DTMF
Management
Local ServiceHTTP, HTTPS, Telnet, SSH, TR-069
Config File Export & Import
Config File CompatibilityVigor2925 Series
Firmware UpgradeTFTP, HTTP, TR-069
2-Level Administration Privilege
Access ControlAccess List, Brute Force Protection
Syslog
Notification AlertSMS, E-mail
SNMPv2, v2c, v3
Managed by VigorACS
Central AP Management20 VigorAP
Central Switch Management10 VigorSwitch
Physical
Rack Mountable Mouting Kit Excluded (DR101)
Power SupplyDC 12V @ 1.5-2A
Dimension241mm x 166mm x 46mm
Operating Temperature0 to 45°C
Storage Temperature-25 to 70°C
Operating Humidity (non-condensing)10 to 90%
CertificateQuick Start Guide (Wireless)” target=”_blank” rel=”noopener noreferrer”> Quick Start Guide (Wireless)” target=”_blank” rel=”noopener noreferrer”> Quick Start Guide (Wireless)” target=”_blank” rel=”noopener noreferrer”>

DrayTek Vigor2926 Series – Dual WAN Gigabit broadband firewall router review published on techradar.com

CLICK HERE TO READ THE FULL REVIEW

Multi-subnets

The Vigor2926 supports up to 8 LAN IP subnets, an IP Routed subnet and a DMZ port.

The 8 LAN IP subnets can be assigned to 16 VLANS allowing the creation of logical workgroups to provide additional security and traffic management within an organisation.

For example, within a building each tenant or workgroup can be assigned their own IP network. In addition, workgroups can also be located in different physical locations or floors within a building. For example, a Sales Department may be located on the 1st floor of a building, but some of the sales people are located on the second floor and still be part of the sales VLAN.

The IEEE 802.1q VLAN trunk feature means that only a single LAN cable connection is required between the router and the VigorSwitch, create a number of VLANs for different departments.

The VLAN Tag Priority setting can be used to prioritise traffic for certain VLANS or workgroups.

Multi-site business deployment

Increase remote access security to your office by combining both VPN and Firewall features in the Vigor2926.

The Vigor2926 supports up to 50 simultaneous VPN tunnels (such as IPSec/PPTP/L2TP/SSL protocols) for secure data exchange and communication. In addition, 25 SSL VPN tunnels are available for teleworkers to access the office LAN. Teleworkers can be authenticated directly with your LDAP server if preferred. The SSL technology is same as the encryption used for secure web sites such as online banking.

Security is enhanced by utilising firewall features such as web content and URL filtering in addition to restricting access to P2P traffic and Instant Messaging applications.

The Vigor2926 series is equipped with two Gigabit Ethernet ports and two USB WAN ports for WAN load-balancing and backup. This allows backup VPN tunnels to be created to branch office networks to ensure maximum VPN connectivity uptime. In addition, the VPN Trunking feature can be used to set up dual VPN tunnel links to branch office networks to increase bandwidth and provide redundancy and backup to prevent downtime due to one of the WAN connections failing.

Comprehensive Firewall

The comprehensive firewall in the Vigor2926 router protects your network by using Stateful Packet Inspection (SPI) and extensive firewall filtering rules. Stateful Packet Inspection monitors incoming and outgoing data packets at layer 3. It maintains a table of open connections and inspects the payload to determine its data will be passed or blocked by matching known active legitimate connections.

The DoS (Denial of Service) Defense also protects your network against a number of attacks from the Internet.

The URL and Web content filters are also available to restrict access to certain websites (such as Social Networking, Gambling, etc.) for some users and it can be enforced according to a time schedule.

The DMZ Host feature allows you to place a server in the DMZ so it can be access from the Internet but not exposing your main network to the Internet.

USB Thermometer

The optional USB thermometer can be attached to the Vigor2926 to provide logging of the ambient temperature in the server room. Upper and lower temperature thresholds can be set and when the temperature exceeds these thresholds and alarm is generated. This alarm can be sent to the network administrator via email or SMS to alert them of the environmental issue.

802.11ac Wave 2 (for ac/Vac model)

802.11ac Wave 2 can simultaneously stream to multiple users to maximise bandwidth utilisation.

Vigor2926ac routers now operate 802.11ac Wave 2 Wi-Fi with support for MU-MIMO, TX Beam Forming, 1733Mb/s Link Rate and up to 4 spatial streams. This allows up to 4 wireless clients such as laptops or smartphones to have simultaneous access to a Wi-Fi channel. The result is an increased performance of the Wi-Fi network.

Central Management – AP / Switch / VPN Management

The central management features allow the network administrator to monitor and configure Vigor devices including VigorAPs, Vigor Switches, and even Vigor Routers from a central management console built into the Vigor2926 series router. Maintenance tasks such as firmware upgrades, configuration backup and restoration as well as and monitoring be done from a single portal.

Three options are available in Central Management. These are:

  • VPN Management
  • AP Management
  • Switch Management

VPN management supports 8 external CPE devices and allows the creation and management of IPSec, PPTP or SSL VPN tunnels from the central Vigor2926 router to the remote routers.

The AP Management feature allows the monitoring and auto-configuration of up to 20 DrayTek Access Points connected to the Vigor2926 LAN. Automatic Provisioning can be triggered when a new Access point is connected to the LAN. Other features include client or traffic history of the AP and configuration of load balancing rules for the Access Points.

Switch Management allows you to manage up to 10 VigorSwitches. It simplifies the task of configuring VLANS in attached VigorSwitches matching the router’s VLAN settings. It also displays the switch status as well as the network topology through the switch hierarchy feature.

Flexible Installation with Rackmount

The Vigor2926 series router can be rack mounted into a standard 19’ rack or cabinet. The 1RU rack mounting kit allows the front panel of the router to be easily accessible as well as keeping it secure in the communications rack.