Dual Ethernet WAN Broadband Security Routers for SMBs
The Vigor2927 Series are dual-Ethernet WAN Firewall routers providing Load Balancing and Failover for reliable Internet accesses. Featuring VPN, QoS, Route Policy, Firewall, Content Filtering, Bandwidth Management, Captive Hotspot Portal and a lot more, these are the ultimate routers for SMBs. The series include models with built-in 802.11ax (WiFi 6, AX3000)/ 802.11ac Wi-Fi and a VoIP gateway (Vac model).

Vigor2927ax
802.11ax (WiFi 6, AX3000)

Performance Comparison: Vigor2927 vs. Vigor2926
NAT throughput (1.6 times faster)
Vigor2927 Series
Vigor2926 Series
IPSec throughput (3.6 times faster)
Vigor2927 Series
Vigor2926 Series
SSL-VPN throughput (2.7 times faster)
Vigor2927 Series
Vigor2926 Series
Key Features
Hardware Acceleration
Without sacrificing traffic control features such as QoS, Bandwidth Limit, WAN Budget, Traffic Graph and Data Flow Monitor, Hardware Acceleration enhances performance for:
- NAT & routing connections
- QoS
- IPsec VPN

Hardware NAT & Routing
With Hardware Acceleration and Hardware QoS enabled, the router supports up to 8k NAT and routing connections, and firewall performance reaching 940Mbps on single WAN and 1.8Gbps combined performance on multi-WANs.
Dual WAN (Ethernet + DSL)
2.3x Faster NAT Performance
with Hardware NAT & Routing
without Hardware NAT & Routing
Single Ethernet WAN
1.2x Faster NAT Performance
with Hardware NAT & Routing
without Hardware NAT & Routing
Hardware QoS
Hardware QoS allows prioritization of applications and services on DrayTek routers, to improve performance of critical applications such as VoIP, conferencing and video streaming, etc. Furthermore, it allows flexible bandwidth allocation to suit business requirements.

Dual WAN (Ethernet + DSL)
2.6x Faster QoS Performance
with Hardware QoS
with Software QoS
Single Ethernet WAN
1.3x Faster QoS Performance
with Hardware QoS
with Software QoS
Hardware IPsec
While the Vigor2927 series already has improved IPsec performance over the previous Vigor2862 series, with Hardware Acceleration enabled, IPsec performance can now reach 800 Mbps. The first 16 tunnels are automatically accelerated on a first come first serve basis. If any drops out, a new tunnel will be put into the accelerator automatically to top off 16 accelerated tunnels.
2.7x Faster IPsec Performance
with Hardware IPsec
with Software IPsec

App QoS
Application QoS allows prioritisation of applications and services on DrayTek routers to improve and enhance critical applications such as VoIP, conferencing and video streaming, etc. It also allow flexible bandwidth allocation to suit business requirements.
VoIP First
VoIP is always a top priority! The default VoIP port, UDP 5060 (configurable) has priority out-of-box with QoS.
Improve Experience for Business-Critical Apps
Select your business critical apps, and easily put them into QoS classes.
Flexible Bandwidth Allocation
Bandwidth will be reserved for high-priority classes, and can be used by low-priority classes when available.

New OFDMA Feature for 802.11ax (WiFi 6) – Vigor2927ax only
Higher Transmission Efficiency with OFDMA
OFDMA has been used in LTE for many years, and is now available in 802.11ax for multi-user mode.
With legacy OFDM, each frame is transmitted across the entire channel width. When the transmission rate is low, this causes more latency and jitters and lower the overall efficiency.
OFDMA splits a single frame into groups of subcarriers, and each subcarrier can be sent simultaneously. With multiple access mode, it allows multiple users to transmit at the same time thus improving efficiency and enhancing user experiences in high density environments.
OFDM

OFDMA

802.11ax (WiFi 6) Downlink & Uplink MU-MIMO (Vigor2927ax only)

802.11ax (WiFi 6) BSS Colouring (Vigor2927ax only)
In traditional 802.11 Wi-Fi networks, access points are designed to wait and take turns if other signals of the same frequency are detected from adjacent access points. This sharing of a resource, in this case radio frequencies, is called a basic service set (BSS). 802.11ax adds Colouring to the BSS information being broadcast so that APs can use the same channel at the same time without having to take turns. This increases Wi-Fi efficiency, particularly in high density environments.
In the diagram here, AP1 and AP4 are using Channel 1 simultaneously, which normally means they would have to take turns if transmitting information at the same time. However, using BSS Colouring, the 2 APs can now transmit simultaneously without waiting.
An 802.11ax AP using BSS Colouring has the ability to change its BSS Colour if it detects another AP using the same BSS Colour on the same frequency.

AP-Assisted Roaming – built-in in selected Wi-Fi Vigor Routers and all Vigor Access Points

Extend Transmission Range
When a Wi-Fi client moves out of its effective transmission range which is defined by the Basic Rate and/or Received Signal Strength threshold, the AP forces the Wi-Fi client to pick up a nearby access point with stronger signals thereby extending the range.
Improve Data Rates
When the “Minimum RSSI with Adjacent AP” option is set, APs or routers on the same local subnet will exchange client information with each other and switch to the AP or router that has the strongest signal, ensuring that data rates can be as good as possible.
Better User Experience
Instead of ineffective transmission with low basic rates or RSSI, the better links provide better user experience while saving the airtime.
No Controller Required
Assisted Roaming is a built-in feature in all Vigor Access Points and a number of Wi-Fi routers; it saves the need for an ad-hoc wireless controller and is an ideal solution for simple network deployments.
Hotspot Web Portal
Market your business while offering free Wi-Fi
Wi-Fi Marketing
Redirect hotspot guests to the company homepage, online surveys, or display a promotion message.
Grow Customer Mailing List
Require guests to leave contact info or social media accounts before they can use the Internet services.

Various Authentication Types
A variety of login methods are supported to meet your business needs, including Facebook Login, Google Login, SMS PIN, Voucher PIN, and RADIUS.
3rd-Party Service Compliant
Supports external captive portal authentication so you can keep using the Wi-Fi marketing solution you prefer.
Data Quota Management
Bandwidth management is integrated into the Hotspot features to control the bandwidth and session usage of the Hotspot guests.
Management Solution
| All-in-One Management | ||
|---|---|---|
Mesh (ac model) | Central Switch Management | Central AP Management |
|
|
|
| Software Management | |
|---|---|
VigorACS 2 | VigorACS 3 |
|
|
In-the-Box

Vigor2927/ax/ac/Vac

Antenna x 2
(ax/ac/Vac model)

RJ-45 Cable
(Ethernet)

Power Adaptor

Quick Start Guide
Note :
The throughput figures are maximum, based on DrayTek internal testing with optimal conditions. The actual performance may vary depending on the different network conditions and applications activated.
Models
| Model | Vigor2927 | Vigor2927ax | Vigor2927ac |
|---|---|---|---|
| Product | ![]() | ![]() | ![]() |
| Gigabit WAN | 1 | 1 | 1 |
| Configurable GbE WAN/LAN port | 1 | 1 | 1 |
| 4G LTE/3G | 2 x USB 2.0 | 2 x USB 2.0 | 2 x USB 2.0 |
| Wireless WAN | 2 | ||
| Gigabit LAN | 5 | 5 | 5 |
| VPN Tunnels | 50 | 50 | 50 |
| Wireless LAN | WiFi 6, AX3000 | WiFi 5, AC1300 | |
| Wi-Fi Antenna | 3dBi for 5GHz 2.5dBi for 2.4GHz | 3dBi for 5GHz 2.5dBi for 2.4GHz | |
| VoIP (2xFXS) |
Specifications
Interface (DISABLE)
| Interface | |
|---|---|
| Fixed WAN Port | 1 x Gigabit Ethernet |
| LAN/WAN Switchable Port | 1 x Gigabit Ethernet |
| Fixed LAN Port | 5 x Gigabit Ethernet |
| USB Port | 2 x USB 2.0 for 3G/4G/LTE USB modem, storage, printer or thermometer |
| RJ-11 Port for Voice | 2 x FXS (V model) |
| Wi-Fi Antenna | 2 x External Dipole Gain: 3 dBi for 5GHz, 2.5 dBi for 2.4GHz (ax/ac/Vac models) |
| 2.4G WLAN | 802.11n 2×2 MIMO 400Mbps (ac/Vac models) 802.11ax 2×2 MIMO 574Mbps (ax model) |
| 5G WLAN | 802.11ac Wave 2 2×2 MU-MIMO 867Mbps (ac/Vac models) 802.11ax Wave 2 2×2 MU-MIMO 2402Mbps (ax model) |
Performance (DISABLE)
| Performance | |
|---|---|
| NAT Throughput | 800 Mbps |
| NAT Throughput with Hardware Acceleration | 940 Mbps (Ethernet WAN) 1.8 Gbps (Dual WAN) |
| IPsec VPN Performance | 290 Mbps (AES 256 bits) |
| SSL VPN Performance | 120 Mbps |
| Max. Number of NAT Sessions | 60,000 |
| Max. Concurrent VPN Tunnels | 50 |
| Max. Concurrent OpenVPN/ SSL-VPN | 25 |
Internet Connection (DISABLE)
| Internet Connection | |
|---|---|
| IPv4 | PPPoE, DHCP, Static IP, PPTP/L2TP |
| IPv6 | PPP, DHCPv6, Static IP, TSPC, AICCU, 6rd, 6in4 Static Tunnel |
| 802.1p/q Multi-VLAN Tagging | |
| Multi-VLAN/PVC | |
| Wireless WAN | 2 (ac/Vac models) |
| 3G/4G/LTE WAN with USB modem | |
| Load Balancing | IP-based, Session-based |
| WAN Active on Demand | Link Failure, Traffic Threshold |
| Connection Detection | ARP, Ping |
| WAN Data Budget | |
| Dynamic DNS | |
| DrayDDNS | |
LAN Management (DISABLE)
| LAN Management | |
|---|---|
| VLAN | 802.1q Tag-based, Port-based |
| Max. Number of VLAN | 16 |
| Number of LAN Subnet | 8 |
| DHCP Server | Multiple IP Subnet, Custom DHCP Options, Bind-IP-to-MAC |
| LAN IP Alias | |
| Wired 802.1x Authentication | |
| Port Mirroring | |
| Local DNS Server | |
| Conditional DNS Forwarding | |
| Hotspot Web Portal | |
| Hotspot Authentication | Click-Through, Social Login, SMS PIN, Voucher PIN, RADIUS, External Portal Server |
Networking (DISABLE)
| Networking | |
|---|---|
| Routing | IPv4 Static Routing, IPv6 Static Routing, Inter-VLAN Routing, RIP, BGP (IPv4) |
| Policy-based Routing | Protocol, IP Address, Port, Domain, Country |
| High Availability | |
| DNS Security (DNSSEC) | |
| IGMP | IGMP v2/v3, IGMP Proxy, IGMP Snooping & Fast Leave |
| Local RADIUS server | |
| SMB File Sharing (Requires external storage) | |
VPN (DISABLE)
| VPN | |
|---|---|
| LAN-to-LAN | |
| Teleworker-to-LAN | |
| Protocols | PPTP, L2TP, IPsec, L2TP over IPsec, SSL, GRE, IKEv2, IKEv2-EAP, IPsec-XAuth, OpenVPN (Host to LAN) |
| User Authentication | Local, RADIUS, LDAP, TACACS+, mOTP |
| IKE Authentication | Pre-Shared Key, X.509 |
| IPsec Authentication | SHA-1, SHA-256 |
| Encryption | MPPE, DES, 3DES, AES |
| VPN Trunk (Redundancy) | Load Balancing, Failover |
| Single-Armed VPN | |
| NAT-Traversal (NAT-T) | |
| DrayTek VPN Matcher | |
Firewall & Content Filtering (DISABLE)
| Firewall & Content Filtering | |
|---|---|
| NAT | Port Redirection, Open Ports, Port Triggering, DMZ Host, UPnP |
| ALG (Application Layer Gateway) | SIP, RTSP, FTP, H.323 |
| VPN Pass-Through | PPTP, L2TP, IPsec |
| IP-based Firewall Policy | |
| Content Filtering | Application, URL, DNS Keyword, Web Features, Web Category (subscription required) |
| DoS Attack Defense | |
| Spoofing Defense | |
Bandwidth Management (DISABLE)
| Bandwidth Management | |
|---|---|
| IP-based Bandwidth Limit | |
| IP-based Session Limit | |
| QoS (Quality of Service) | TOS, DSCP, 802.1p, IP Address, Port, Application |
| VoIP Prioritisation | |
Wireless LAN (wireless model) (DISABLE)
| Wireless LAN (ax/ac/Vac models) | |
|---|---|
| Number of SSID | 4 per radio band |
| Security | WEP, WPA, WPA2, Mixed (WPA+WPA2), WPA3 |
| Authentication | Pre-Shared Key, 802.1x |
| WPS | PIN, PBC |
| WDS | Repeater (5GHz only) |
| Access Control | Access List, Client Isolation, Hide SSID, Wi-Fi Scheduling |
| AirTime Fairness | |
| Band Steering | |
| MU-MIMO | (5GHz only) |
| WMM | |
VoIP Gateway (Vac model) (DISABLE)
| VoIP Gateway (Vac model) | |
|---|---|
| Protocol | SIP, RTP/RTCP, ZRTP |
| SIP Registrars | 12 |
| Dial Plan | Phone Book, Digit Map, Call Barring, Regional |
| Call Features | Call Waiting, Call Transfer, Scheduled DND, Hotline |
| Voice Codec | G.711 A/u law, G.723.1, G.726, G.729 A/B |
| Caller ID | FSK_ETSI, FSK_BELLCORE, DTMF |
Management (DISABLE)
| Management | |
|---|---|
| Local Service | HTTP, HTTPS, Telnet, SSH, TR-069 |
| Config File Export & Import | |
| Config File Compatibility | Vigor2926 Series |
| Firmware Upgrade | TFTP, HTTP, TR-069 |
| 2-Level Administration Privilege | |
| Access Control | Access List, Brute Force Protection |
| Syslog | |
| Notification Alert | SMS, E-mail |
| SNMP | v2, v2c, v3 |
| Managed by VigorACS | |
| Central VPN Management | 8 remote Vigor routers |
| Central AP Management | 20 VigorAPs |
| Mesh Network | 7 VigorAPs (ac/Vac models only) |
| Central Switch Management | 10 VigorSwitches |
Physical (DISABLE)
| Physical | |
|---|---|
| Rack Mountable | Mouting Kit Excluded (DR101) |
| Power Supply | DC 12V @ 2A |
| Max. Power Consumption | 24 watts (ac model) |
| Dimension | 241mm x 165mm x 44mm |
| Weight | 630g (ac model) |
| Operating Temperature | 0 to 45°C |
| Storage Temperature | -25 to 70°C |
| Operating Humidity (non-condensing) | 10 to 90% |
| Certificate | |
Note :
- All specifications are subject to change without notice.
- The throughput figures are maximum, based on DrayTek internal testing with optimal conditions. The actual performance may vary depending on the different network conditions and applications activated.
DrayTek Vigor2927ax Review Published in APC Magazine – Xmas 2022

DrayTek Vigor2927ac Review Published in APC Magazine – Jun 2021

Multi-subnets

The Vigor2926 supports up to 8 LAN IP subnets, an IP Routed subnet and a DMZ port.
The 8 LAN IP subnets can be assigned to 16 VLANS allowing the creation of logical workgroups to provide additional security and traffic management within an organisation.
For example, within a building each tenant or workgroup can be assigned their own IP network. In addition, workgroups can also be located in different physical locations or floors within a building. For example, a Sales Department may be located on the 1st floor of a building, but some of the sales people are located on the second floor and still be part of the sales VLAN.
The IEEE 802.1q VLAN trunk feature means that only a single LAN cable connection is required between the router and the VigorSwitch, create a number of VLANs for different departments.
The VLAN Tag Priority setting can be used to prioritise traffic for certain VLANS or workgroups.
Multi-site business deployment

Increase remote access security to your office by combining both VPN and Firewall features in the Vigor2926.
The Vigor2926 supports up to 50 simultaneous VPN tunnels (such as IPSec/PPTP/L2TP/SSL protocols) for secure data exchange and communication. In addition, 25 SSL VPN tunnels are available for teleworkers to access the office LAN. Teleworkers can be authenticated directly with your LDAP server if preferred. The SSL technology is same as the encryption used for secure web sites such as online banking.
Security is enhanced by utilising firewall features such as web content and URL filtering in addition to restricting access to P2P traffic and Instant Messaging applications.
The Vigor2926 series is equipped with two Gigabit Ethernet ports and two USB WAN ports for WAN load-balancing and backup. This allows backup VPN tunnels to be created to branch office networks to ensure maximum VPN connectivity uptime. In addition, the VPN Trunking feature can be used to set up dual VPN tunnel links to branch office networks to increase bandwidth and provide redundancy and backup to prevent downtime due to one of the WAN connections failing.
Comprehensive Firewall

The comprehensive firewall in the Vigor2926 router protects your network by using Stateful Packet Inspection (SPI) and extensive firewall filtering rules. Stateful Packet Inspection monitors incoming and outgoing data packets at layer 3. It maintains a table of open connections and inspects the payload to determine its data will be passed or blocked by matching known active legitimate connections.
The DoS (Denial of Service) Defense also protects your network against a number of attacks from the Internet.
The URL and Web content filters are also available to restrict access to certain websites (such as Social Networking, Gambling, etc.) for some users and it can be enforced according to a time schedule.
The DMZ Host feature allows you to place a server in the DMZ so it can be access from the Internet but not exposing your main network to the Internet.
USB Thermometer

The optional USB thermometer can be attached to the Vigor2926 to provide logging of the ambient temperature in the server room. Upper and lower temperature thresholds can be set and when the temperature exceeds these thresholds and alarm is generated. This alarm can be sent to the network administrator via email or SMS to alert them of the environmental issue.
802.11ac Wave 2 (for ac/Vac model)
802.11ac Wave 2 can simultaneously stream to multiple users to maximise bandwidth utilisation.

Vigor2926ac routers now operate 802.11ac Wave 2 Wi-Fi with support for MU-MIMO, TX Beam Forming, 1733Mb/s Link Rate and up to 4 spatial streams. This allows up to 4 wireless clients such as laptops or smartphones to have simultaneous access to a Wi-Fi channel. The result is an increased performance of the Wi-Fi network.
Central Management – AP / Switch / VPN Management

The central management features allow the network administrator to monitor and configure Vigor devices including VigorAPs, Vigor Switches, and even Vigor Routers from a central management console built into the Vigor2926 series router. Maintenance tasks such as firmware upgrades, configuration backup and restoration as well as and monitoring be done from a single portal.
Three options are available in Central Management. These are:
- VPN Management
- AP Management
- Switch Management
VPN management supports 8 external CPE devices and allows the creation and management of IPSec, PPTP or SSL VPN tunnels from the central Vigor2926 router to the remote routers.
The AP Management feature allows the monitoring and auto-configuration of up to 20 DrayTek Access Points connected to the Vigor2926 LAN. Automatic Provisioning can be triggered when a new Access point is connected to the LAN. Other features include client or traffic history of the AP and configuration of load balancing rules for the Access Points.
Switch Management allows you to manage up to 10 VigorSwitches. It simplifies the task of configuring VLANS in attached VigorSwitches matching the router’s VLAN settings. It also displays the switch status as well as the network topology through the switch hierarchy feature.
Flexible Installation with Rackmount

The Vigor2926 series router can be rack mounted into a standard 19’ rack or cabinet. The 1RU rack mounting kit allows the front panel of the router to be easily accessible as well as keeping it secure in the communications rack.
Resources
Overview
The Vigor2926 Series provides multi-WAN broadband connectivity to ensure a reliable Internet connection for businesses. Two Gigabit Ethernet WAN ports are featured, which can be configured in either Failover or Load Balancing mode, or alternatively WAN 2 can be configured as an additional LAN port if a second Ethernet WAN connection is not required. Two USB ports are also featured which can work with 3G/4G/LTE USB modems to add wireless Internet access for additional load balancing or failover.
The Vigor2926 Series also have comprehensive security and management features including VLAN, Bandwidth Management, Quality of Service, DNS Control, SPI Firewall, Web Content Filtering and Central Management solutions to provide a reliable and secure business network.
Dual Ethernet WAN Broadband Security Routers for SMBs
The Vigor2927 Series are dual-Ethernet WAN Firewall routers providing Load Balancing and Failover for reliable Internet accesses. Featuring VPN, QoS, Route Policy, Firewall, Content Filtering, Bandwidth Management, Captive Hotspot Portal and a lot more, these are the ultimate routers for SMBs. The series include models with built-in 802.11ax (WiFi 6, AX3000)/ 802.11ac Wi-Fi and a VoIP gateway (Vac model).

Vigor2927ax
802.11ax (WiFi 6, AX3000)

- Wireless Antenna (ax/ac/Vac models)
- Reset Button
- WLAN/WPS Button (ax/ac/Vac models)
- LED Indicator
- 2 x USB 2.0 ports for connection to 3G/4G LTE USB modems, FTP server, network printer and thermometer
- Fixed WAN Port: 1x GbE RJ-45
- WAN/LAN Switchable Port: 1x GbE RJ-45
- Fixed LAN Port: 5x GbE RJ-45
- 2x FXS for VoIP (Vac model)
- Power On/Off Switch
- Power Input
Performance Comparison: Vigor2927 vs. Vigor2926
NAT throughput (1.6 times faster)
Vigor2927 Series
Vigor2926 Series
IPSec throughput (3.6 times faster)
Vigor2927 Series
Vigor2926 Series
SSL-VPN throughput (2.7 times faster)
Vigor2927 Series
Vigor2926 Series
Key Features
Hardware Acceleration
Without sacrificing traffic control features such as QoS, Bandwidth Limit, WAN Budget, Traffic Graph and Data Flow Monitor, Hardware Acceleration enhances performance for:
- NAT & routing connections
- QoS
- IPsec VPN

Hardware NAT & Routing
With Hardware Acceleration and Hardware QoS enabled, the router supports up to 8k NAT and routing connections, and firewall performance reaching 940Mbps on single WAN and 1.8Gbps combined performance on multi-WANs.
Dual WAN (Ethernet + DSL)
2.3x Faster NAT Performance
with Hardware NAT & Routing
without Hardware NAT & Routing
Single Ethernet WAN
1.2x Faster NAT Performance
with Hardware NAT & Routing
without Hardware NAT & Routing
Hardware QoS
Hardware QoS allows prioritization of applications and services on DrayTek routers, to improve performance of critical applications such as VoIP, conferencing and video streaming, etc. Furthermore, it allows flexible bandwidth allocation to suit business requirements.

Dual WAN (Ethernet + DSL)
2.6x Faster QoS Performance
with Hardware QoS
with Software QoS
Single Ethernet WAN
1.3x Faster QoS Performance
with Hardware QoS
with Software QoS
Hardware IPsec
While the Vigor2927 series already has improved IPsec performance over the previous Vigor2862 series, with Hardware Acceleration enabled, IPsec performance can now reach 800 Mbps. The first 16 tunnels are automatically accelerated on a first come first serve basis. If any drops out, a new tunnel will be put into the accelerator automatically to top off 16 accelerated tunnels.
2.7x Faster IPsec Performance
with Hardware IPsec
with Software IPsec

App QoS
Application QoS allows prioritisation of applications and services on DrayTek routers to improve and enhance critical applications such as VoIP, conferencing and video streaming, etc. It also allow flexible bandwidth allocation to suit business requirements.
VoIP First
VoIP is always a top priority! The default VoIP port, UDP 5060 (configurable) has priority out-of-box with QoS.
Improve Experience for Business-Critical Apps
Select your business critical apps, and easily put them into QoS classes.
Flexible Bandwidth Allocation
Bandwidth will be reserved for high-priority classes, and can be used by low-priority classes when available.

New OFDMA Feature for 802.11ax (WiFi 6) – Vigor2927ax only
Higher Transmission Efficiency with OFDMA
OFDMA has been used in LTE for many years, and is now available in 802.11ax for multi-user mode.
With legacy OFDM, each frame is transmitted across the entire channel width. When the transmission rate is low, this causes more latency and jitters and lower the overall efficiency.
OFDMA splits a single frame into groups of subcarriers, and each subcarrier can be sent simultaneously. With multiple access mode, it allows multiple users to transmit at the same time thus improving efficiency and enhancing user experiences in high density environments.
OFDM

OFDMA

802.11ax (WiFi 6) Downlink & Uplink MU-MIMO (Vigor2927ax only)

802.11ax (WiFi 6) BSS Colouring (Vigor2927ax only)
In traditional 802.11 Wi-Fi networks, access points are designed to wait and take turns if other signals of the same frequency are detected from adjacent access points. This sharing of a resource, in this case radio frequencies, is called a basic service set (BSS). 802.11ax adds Colouring to the BSS information being broadcast so that APs can use the same channel at the same time without having to take turns. This increases Wi-Fi efficiency, particularly in high density environments.
In the diagram here, AP1 and AP4 are using Channel 1 simultaneously, which normally means they would have to take turns if transmitting information at the same time. However, using BSS Colouring, the 2 APs can now transmit simultaneously without waiting.
An 802.11ax AP using BSS Colouring has the ability to change its BSS Colour if it detects another AP using the same BSS Colour on the same frequency.

AP-Assisted Roaming – built-in in selected Wi-Fi Vigor Routers and all Vigor Access Points

Extend Transmission Range
When a Wi-Fi client moves out of its effective transmission range which is defined by the Basic Rate and/or Received Signal Strength threshold, the AP forces the Wi-Fi client to pick up a nearby access point with stronger signals thereby extending the range.
Improve Data Rates
When the “Minimum RSSI with Adjacent AP” option is set, APs or routers on the same local subnet will exchange client information with each other and switch to the AP or router that has the strongest signal, ensuring that data rates can be as good as possible.
Better User Experience
Instead of ineffective transmission with low basic rates or RSSI, the better links provide better user experience while saving the airtime.
No Controller Required
Assisted Roaming is a built-in feature in all Vigor Access Points and a number of Wi-Fi routers; it saves the need for an ad-hoc wireless controller and is an ideal solution for simple network deployments.
Hotspot Web Portal
Market your business while offering free Wi-Fi
Wi-Fi Marketing
Redirect hotspot guests to the company homepage, online surveys, or display a promotion message.
Grow Customer Mailing List
Require guests to leave contact info or social media accounts before they can use the Internet services.

Various Authentication Types
A variety of login methods are supported to meet your business needs, including Facebook Login, Google Login, SMS PIN, Voucher PIN, and RADIUS.
3rd-Party Service Compliant
Supports external captive portal authentication so you can keep using the Wi-Fi marketing solution you prefer.
Data Quota Management
Bandwidth management is integrated into the Hotspot features to control the bandwidth and session usage of the Hotspot guests.
Management Solution
| All-in-One Management |
|---|
Mesh (ac/Vac models)Up to 7 APs |
|
Central AP ManagementUp to 2 APs |
|
| Software Management |
|---|
VigorACS 2 |
|
VigorACS 3 |
|
In-the-Box

Vigor2927/ax/ac/Vac

Antenna x 2
(ax/ac/Vac model)

RJ-45 Cable
(Ethernet)

Power Adaptor

Quick Start Guide
Note :
The throughput figures are maximum, based on DrayTek internal testing with optimal conditions. The actual performance may vary depending on the different network conditions and applications activated.
Specifications
Interface (DISABLE)
| Interface | |
|---|---|
| Fixed WAN Port: 1 x Gigabit Ethernet | |
| LAN/WAN Switchable Port: 1 x Gigabit Ethernet | |
| Fixed LAN Port: 5 x Gigabit Ethernet | |
| USB Port: 2 x USB 2.0 for 3G/4G LTE USB modem, storage, printer or thermometer | |
| RJ-11 Port for Voice: 2x FXS (V model) | |
| Wi-Fi Antenna: 2 x External Dipole Gain: 3 dBi for 5GHz, 2.5 dBi for 2.4GHz (ax/ac/Vac models) | |
| 2.4G WLAN: 802.11n 2×2 MIMO 400Mbps (ac/Vac models) 802.11ax 2×2 MIMO 574Mbps (ax model) | |
| 5G WLAN: 802.11ac Wave 2 2×2 MU-MIMO 867Mbps (ac/Vac models) 802.11ax Wave 2 2×2 MU-MIMO 2402Mbps (ax model) |
Performance (DISABLE)
| Performance | |
|---|---|
| NAT Throughput: 800 Mbps | |
| NAT Throughput with Hardware Acceleration: 940 Mbps (Single WAN) 1.8 Gbps (Dual WAN) | |
| IPsec VPN Performance: 290 Mbps (AES 256 bits) | |
| SSL VPN Performance: 120 Mbps | |
| Max. Number of NAT Sessions: 60,000 | |
| Max. Concurrent VPN Tunnels: 50 | |
| Max. Concurrent OpenVPN / SSL-VPN: 25 |
Internet Connection (DISABLE)
| Internet Connection | |
|---|---|
| IPv4: PPPoE, DHCP, Static IP, PPTP/L2TP | |
| IPv6: PPP, DHCPv6, Static IP, TSPC, AICCU, 6rd, 6in4 Static Tunnel | |
| 802.1p/q Multi-VLAN Tagging | |
| Multi-VLAN/PVC | |
| Wireless WAN: 2 (ac/Vac models) | |
| 3G/4G/LTE WAN with USB modem | |
| Load Balancing: IP-based, Session-based | |
| WAN Active on Demand: Link Failure, Traffic Threshold | |
| Connection Detection: ARP, Ping | |
| WAN Data Budget | |
| Dynamic DNS | |
| DrayDDNS | |
LAN Management (DISABLE)
| LAN Management | |
|---|---|
| VLAN: 802.1q Tag-based, Port-based | |
| Max. Number of VLAN: 16 | |
| Number of LAN Subnet: 8 | |
| DHCP Server: Multiple IP Subnet, Custom DHCP Options, Bind-IP-to-MAC | |
| LAN IP Alias | |
| Wired 802.1x Authentication | |
| Port Mirroring | |
| Local DNS Server | |
| Conditional DNS Forwarding | |
| Hotspot Web Portal | |
| Hotspot Authentication: Click-Through, Social Login, SMS PIN, Voucher PIN, RADIUS, External Portal Server | |
Networking (DISABLE)
| Networking | |
|---|---|
| Routing: IPv4 Static Routing, IPv6 Static Routing, Inter-VLAN Routing, RIP, BGP (IPv4) | |
| Policy-based Routing: Protocol, IP Address, Port, Domain, Country | |
| High Availability | |
| DNS Security (DNSSEC) | |
| Multicast: IGMP Proxy, IGMP Snooping & Fast Leave, Bonjour | |
| Local RADIUS server | |
| SMB File Sharing (Requires external storage) | |
VPN (DISABLE)
| VPN | |
|---|---|
| LAN-to-LAN | |
| Teleworker-to-LAN | |
| Protocols: PPTP, L2TP, IPsec, L2TP over IPsec, SSL, GRE, IKEv2, IKEv2-EAP, IPsec-XAuth, OpenVPN (Host to LAN) | |
| User Authentication: Local, RADIUS, LDAP, TACACS+, mOTP | |
| IKE Authentication: Pre-Shared Key, X.509 | |
| IPsec Authentication: SHA-1, SHA-256 | |
| Encryption: MPPE, DES, 3DES, AES | |
| VPN Trunk (Redundancy): Load Balancing, Failover | |
| Single-Armed VPN | |
| NAT-Traversal (NAT-T) | |
| DrayTek VPN Matcher | |
Firewall & Content Filtering (DISABLE)
| Firewall & Content Filtering | |
|---|---|
| NAT: Port Redirection, Open Ports, Port Triggering, DMZ Host, UPnP | |
| ALG (Application Layer Gateway): SIP, RTSP, FTP, H.323 | |
| VPN Pass-Through: PPTP, L2TP, IPsec | |
| IP-based Firewall Policy | |
| Content Filtering: Application, URL, DNS Keyword, Web Features, Web Category (subscription required) | |
| DoS Attack Defense | |
| Spoofing Defense | |
Bandwidth Management (DISABLE)
| Bandwidth Management | |
|---|---|
| IP-based Bandwidth Limit | |
| IP-based Session Limit | |
| QoS (Quality of Service): TOS, DSCP, 802.1p, IP Address, Port, Application | |
| VoIP Prioritisation | |
Wireless LAN (wireless model) (DISABLE)
| Wireless LAN (ax/ac/Vac models) | |
|---|---|
| Number of SSID: 4 per radio band | |
| Security: WEP, WPA, WPA2, Mixed (WPA+WPA2), WPA3 | |
| Authentication: Pre-Shared Key, 802.1x | |
| WPS: PIN, PBC | |
| WDS: Repeater (5GHz only) | |
| Access Control: Access List, Client Isolation, Hide SSID, Wi-Fi Scheduling | |
| AirTime Fairness | |
| Band Steering | |
| MU-MIMO (5GHz only) | |
| WMM | |
VoIP Gateway (Vac model) (DISABLE)
| VoIP Gateway (Vac model) | |
|---|---|
| Protocol: SIP, RTP/RTCP, ZRTP | |
| SIP Registrars: 12 | |
| Dial Plan: Phone Book, Digit Map, Call Barring, Regional | |
| Call Features: Call Waiting, Call Transfer, Scheduled DND, Hotline | |
| Voice Codec: G.711 A/u law, G.723.1, G.726, G.729 A/B | |
| Caller ID: FSK_ETSI, FSK_BELLCORE, DTMF |
Management (DISABLE)
| Management | |
|---|---|
| Local Service: HTTP, HTTPS, Telnet, SSH, TR-069 | |
| Config File Export & Import | |
| Config File Compatibility: Vigor2926 Series | |
| Firmware Upgrade: TFTP, HTTP, TR-069 | |
| 2-Level Administration Privilege | |
| Access Control: Access List, Brute Force Protection | |
| Syslog | |
| Notification Alert: SMS, E-mail | |
| SNMP: v2, v2c, v3 | |
| Managed by VigorACS | |
| Central VPN Management: 8 remote Vigor routers | |
| Central AP Management: 20 VigorAPs | |
| Mesh Network: 7 VigorAPs (ac/Vac models only) | |
| Central Switch Management: 10 VigorSwitches | |
Physical (DISABLE)
| Physical | |
|---|---|
| Rack Mountable Mouting Kit Excluded (DR101) | |
| Power Supply: DC 12V @ 2A | |
| Max. Power Consumption: 24 watts (ac model) | |
| Dimension: 241mm x 165mm x 44mm | |
| Weight: 630g (ac model) | |
| Operating Temperature: 0 to 45°C | |
| Storage Temperature: -25 to 70°C | |
| Operating Humidity (non-condensing): 10 to 90% | |
| Certificate: | |
Note :
- All specifications are subject to change without notice.
- The throughput figures are maximum, based on DrayTek internal testing with optimal conditions. The actual performance may vary depending on the different network conditions and applications activated.
DrayTek Vigor2927ax Review Published in APC Magazine – Xmas 2022

DrayTek Vigor2927ac Review Published in APC Magazine – Jun 2021

Multi-subnets

The Vigor2926 supports up to 8 LAN IP subnets, an IP Routed subnet and a DMZ port.
The 8 LAN IP subnets can be assigned to 16 VLANS allowing the creation of logical workgroups to provide additional security and traffic management within an organisation.
For example, within a building each tenant or workgroup can be assigned their own IP network. In addition, workgroups can also be located in different physical locations or floors within a building. For example, a Sales Department may be located on the 1st floor of a building, but some of the sales people are located on the second floor and still be part of the sales VLAN.
The IEEE 802.1q VLAN trunk feature means that only a single LAN cable connection is required between the router and the VigorSwitch, create a number of VLANs for different departments.
The VLAN Tag Priority setting can be used to prioritise traffic for certain VLANS or workgroups.
Multi-site business deployment

Increase remote access security to your office by combining both VPN and Firewall features in the Vigor2926.
The Vigor2926 supports up to 50 simultaneous VPN tunnels (such as IPSec/PPTP/L2TP/SSL protocols) for secure data exchange and communication. In addition, 25 SSL VPN tunnels are available for teleworkers to access the office LAN. Teleworkers can be authenticated directly with your LDAP server if preferred. The SSL technology is same as the encryption used for secure web sites such as online banking.
Security is enhanced by utilising firewall features such as web content and URL filtering in addition to restricting access to P2P traffic and Instant Messaging applications.
The Vigor2926 series is equipped with two Gigabit Ethernet ports and two USB WAN ports for WAN load-balancing and backup. This allows backup VPN tunnels to be created to branch office networks to ensure maximum VPN connectivity uptime. In addition, the VPN Trunking feature can be used to set up dual VPN tunnel links to branch office networks to increase bandwidth and provide redundancy and backup to prevent downtime due to one of the WAN connections failing.
Comprehensive Firewall

The comprehensive firewall in the Vigor2926 router protects your network by using Stateful Packet Inspection (SPI) and extensive firewall filtering rules. Stateful Packet Inspection monitors incoming and outgoing data packets at layer 3. It maintains a table of open connections and inspects the payload to determine its data will be passed or blocked by matching known active legitimate connections.
The DoS (Denial of Service) Defense also protects your network against a number of attacks from the Internet.
The URL and Web content filters are also available to restrict access to certain websites (such as Social Networking, Gambling, etc.) for some users and it can be enforced according to a time schedule.
The DMZ Host feature allows you to place a server in the DMZ so it can be access from the Internet but not exposing your main network to the Internet.
USB Thermometer

The optional USB thermometer can be attached to the Vigor2926 to provide logging of the ambient temperature in the server room. Upper and lower temperature thresholds can be set and when the temperature exceeds these thresholds and alarm is generated. This alarm can be sent to the network administrator via email or SMS to alert them of the environmental issue.
802.11ac Wave 2 (for ac/Vac model)
802.11ac Wave 2 can simultaneously stream to multiple users to maximise bandwidth utilisation.

Vigor2926ac routers now operate 802.11ac Wave 2 Wi-Fi with support for MU-MIMO, TX Beam Forming, 1733Mb/s Link Rate and up to 4 spatial streams. This allows up to 4 wireless clients such as laptops or smartphones to have simultaneous access to a Wi-Fi channel. The result is an increased performance of the Wi-Fi network.
Central Management – AP / Switch / VPN Management

The central management features allow the network administrator to monitor and configure Vigor devices including VigorAPs, Vigor Switches, and even Vigor Routers from a central management console built into the Vigor2926 series router. Maintenance tasks such as firmware upgrades, configuration backup and restoration as well as and monitoring be done from a single portal.
Three options are available in Central Management. These are:
- VPN Management
- AP Management
- Switch Management
VPN management supports 8 external CPE devices and allows the creation and management of IPSec, PPTP or SSL VPN tunnels from the central Vigor2926 router to the remote routers.
The AP Management feature allows the monitoring and auto-configuration of up to 20 DrayTek Access Points connected to the Vigor2926 LAN. Automatic Provisioning can be triggered when a new Access point is connected to the LAN. Other features include client or traffic history of the AP and configuration of load balancing rules for the Access Points.
Switch Management allows you to manage up to 10 VigorSwitches. It simplifies the task of configuring VLANS in attached VigorSwitches matching the router’s VLAN settings. It also displays the switch status as well as the network topology through the switch hierarchy feature.
Flexible Installation with Rackmount

The Vigor2926 series router can be rack mounted into a standard 19’ rack or cabinet. The 1RU rack mounting kit allows the front panel of the router to be easily accessible as well as keeping it secure in the communications rack.
Mesh 











