• 1 x Gigabit Ethernet WAN port and 1 x configurable GbE WAN/LAN port for Failover, Load-Balancing and High Availability mode

  • Two USB 2.0 ports for connection to two 3G/4G LTE USB modems, FTP server and network printer
  • 4 x Gigabit LAN ports with multiple subnets and 50,000 NAT sessions
  • 50 x VPN tunnels (including 25 SSL-VPN tunnels) with comprehensive secure protocols
  • Fast VPN throughput, VPN load-balancing and backup for site-to-site applications
  • 16 x VLANs for secure and efficient workgroup management
  • IPv6 & IPv4
  • Up to 1022 IP addresses and 8 IP subnets

  • Integrated IEEE 802.11n wireless Access Point (n model)

  • Integrated IEEE 802.11ac (AC2000) wireless Access Point; dual band; up to 1.7Gbps throughput (ac/Vac model)
  • 2 x FXS and 1 x FXO Line VoIP Port (Vac model)
  • High Availability mode
  • Object-based SPI Firewall and CSM (Content Security Management) for network security
  • Supports VigorACS 2 Central Management System for remote management
  • Central VPN Management for 8 remote Vigor routers
  • Central AP Management for deployment of multiple wireless VigorAPs
  • 2 years back to base warranty

  • 1 x Gigabit Ethernet WAN port and 1 x configurable GbE WAN/LAN port for Failover, Load-Balancing and High Availability mode

  • Two USB 2.0 ports for connection to two 3G/4G LTE USB modems, FTP server, network printer and thermometer
  • 5 x Gigabit LAN ports with multiple subnets and 60,000 NAT sessions
  • 50 x VPN tunnels (including 25 SSL-VPN tunnels) with comprehensive secure protocols
  • Fast VPN throughput, VPN load-balancing and backup for site-to-site applications
  • 16 x VLANs for secure and efficient workgroup management

  • IPv6 & IPv4
  • Up to 1022 IP addresses and 8 IP subnets

  • Integrated IEEE 802.11ac (AC1300) wireless Access Point; dual band; up to 867 Mbps throughput (ac/Vac model)
  • 2 x FXS VoIP ports (Vac model)
  • High Availability mode
  • Object-based SPI Firewall and CSM (Content Security Management) for network security
  • Supports VigorACS 2 and VigorACS 3 Central Management Systems for remote management
  • SD WAN capability when used with VigorACS 3
  • Central VPN Management for 8 remote Vigor routers
  • Central AP Management for deployment of multiple wireless VigorAPs
  • 2 years back to base warranty

  • 1 x fixed GbE WAN port and 1 x configurable GbE WAN/LAN port for Failover, Load Balancing and High Availability mode

  • Two USB 2.0 ports for connection to two 3G/4G LTE USB modems, FTP server, network printer and thermometer
  • 5 x Gigabit LAN ports with multiple subnets and 60,000 NAT sessions
  • 50 x VPN tunnels (including 25 x OpenVPN/ SSL-VPN tunnels) with comprehensive secure protocols

  • Fast VPN throughput, VPN Load Balancing and backup for site-to-site VPN applications

  • Hardware Acceleration and Hardware QoS for up to 8k NAT and routing connections, and 940Mbps (Single WAN) or 1.8Gbps (Multi-WAN) Firewall speed

  • 16 x VLANs for secure and efficient workgroup management

  • Integrated IEEE 802.11ax (WiFi 6, AX3000) wireless Access Point; dual band; up to 2402 Mbps throughput (ax model)

  • Integrated IEEE 802.11ac (AC1300) wireless Access Point; dual band; up to 867 Mbps throughput (ac/Vac models)

  • IPv6 & IPv4

  • Up to 1022 IP addresses and 8 IP subnets

  • 2 x FXS VoIP ports (Vac model)
  • High Availability mode
  • Object-based SPI Firewall and CSM (Content Security Management) for network security
  • Supports VigorACS 2 and VigorACS 3 Central Management Software for remote management

  • SD WAN capability when used with VigorACS 3
  • Central VPN Management for up to 8 remote Vigor routers Learn More
  • Central AP Management for up to 20 Vigor Access Points Learn more
  • Central Switch Management for up to 10 VigorSwitches Learn More
  • Supports Web Content Filter (content security management software)
  • 2 years back to base warranty

Dual Ethernet WAN Broadband Security Routers for SMBs

The Vigor2927 Series are dual-Ethernet WAN Firewall routers providing Load Balancing and Failover for reliable Internet accesses. Featuring VPN, QoS, Route Policy, Firewall, Content Filtering, Bandwidth Management, Captive Hotspot Portal and a lot more, these are the ultimate routers for SMBs. The series include models with built-in 802.11ax (WiFi 6, AX3000)/ 802.11ac Wi-Fi and a VoIP gateway (Vac model).

Vigor2927ax

802.11ax (WiFi 6, AX3000)

Performance Comparison: Vigor2927 vs. Vigor2926

NAT throughput (1.6 times faster)

800 Mbps

Vigor2927 Series

500 Mbps

Vigor2926 Series

IPSec throughput (3.6 times faster)

290 Mbps

Vigor2927 Series

80 Mbps

Vigor2926 Series

SSL-VPN throughput (2.7 times faster)

120 Mbps

Vigor2927 Series

45 Mbps

Vigor2926 Series

Key Features

Hardware Acceleration

Without sacrificing traffic control features such as QoS, Bandwidth Limit, WAN Budget, Traffic Graph and Data Flow Monitor, Hardware Acceleration enhances performance for:

  • NAT & routing connections
  • QoS
  • IPsec VPN

Hardware NAT & Routing

With Hardware Acceleration and Hardware QoS enabled, the router supports up to 8k NAT and routing connections, and firewall performance reaching 940Mbps on single WAN and 1.8Gbps combined performance on multi-WANs.

Dual WAN (Ethernet + DSL)

2.3x Faster NAT Performance

1.8 Gbps

with Hardware NAT & Routing

800 Mbps

without Hardware NAT & Routing

Single Ethernet WAN

1.2x Faster NAT Performance

940 Mbps

with Hardware NAT & Routing

800 Mbps

without Hardware NAT & Routing

Hardware QoS

Hardware QoS allows prioritization of applications and services on DrayTek routers, to improve performance of critical applications such as VoIP, conferencing and video streaming, etc. Furthermore, it allows flexible bandwidth allocation to suit business requirements.

Dual WAN (Ethernet + DSL)

2.6x Faster QoS Performance

1.8 Gbps

with Hardware QoS

700 Mbps

with Software QoS

Single Ethernet WAN

1.3x Faster QoS Performance

940 Mbps

with Hardware QoS

700 Mbps

with Software QoS

Hardware IPsec

While the Vigor2927 series already has improved IPsec performance over the previous Vigor2862 series, with Hardware Acceleration enabled, IPsec performance can now reach 800 Mbps. The first 16 tunnels are automatically accelerated on a first come first serve basis. If any drops out, a new tunnel will be put into the accelerator automatically to top off 16 accelerated tunnels.

2.7x Faster IPsec Performance

800 Mbps

with Hardware IPsec

300 Mbps

with Software IPsec

App QoS

Application QoS allows prioritisation of applications and services on DrayTek routers to improve and enhance critical applications such as VoIP, conferencing and video streaming, etc. It also allow flexible bandwidth allocation to suit business requirements.

VoIP First

VoIP is always a top priority! The default VoIP port, UDP 5060 (configurable) has priority out-of-box with QoS.

Improve Experience for Business-Critical Apps

Select your business critical apps, and easily put them into QoS classes.

Flexible Bandwidth Allocation

Bandwidth will be reserved for high-priority classes, and can be used by low-priority classes when available.

New OFDMA Feature for 802.11ax (WiFi 6) – Vigor2927ax only

Higher Transmission Efficiency with OFDMA

OFDMA has been used in LTE for many years, and is now available in 802.11ax for multi-user mode.

With legacy OFDM, each frame is transmitted across the entire channel width. When the transmission rate is low, this causes more latency and jitters and lower the overall efficiency.

OFDMA splits a single frame into groups of subcarriers, and each subcarrier can be sent simultaneously. With multiple access mode, it allows multiple users to transmit at the same time thus improving efficiency and enhancing user experiences in high density environments.

OFDM

OFDMA

802.11ax (WiFi 6) Downlink & Uplink MU-MIMO (Vigor2927ax only)

802.11ax (WiFi 6) BSS Colouring (Vigor2927ax only)

In traditional 802.11 Wi-Fi networks, access points are designed to wait and take turns if other signals of the same frequency are detected from adjacent access points. This sharing of a resource, in this case radio frequencies, is called a basic service set (BSS). 802.11ax adds Colouring to the BSS information being broadcast so that APs can use the same channel at the same time without having to take turns. This increases Wi-Fi efficiency, particularly in high density environments.

In the diagram here, AP1 and AP4 are using Channel 1 simultaneously, which normally means they would have to take turns if transmitting information at the same time. However, using BSS Colouring, the 2 APs can now transmit simultaneously without waiting.

An 802.11ax AP using BSS Colouring has the ability to change its BSS Colour if it detects another AP using the same BSS Colour on the same frequency.

AP-Assisted Roaming – built-in in selected Wi-Fi Vigor Routers and all Vigor Access Points

Extend Transmission Range

When a Wi-Fi client moves out of its effective transmission range which is defined by the Basic Rate and/or Received Signal Strength threshold, the AP forces the Wi-Fi client to pick up a nearby access point with stronger signals thereby extending the range.

Improve Data Rates

When the “Minimum RSSI with Adjacent AP” option is set, APs or routers on the same local subnet will exchange client information with each other and switch to the AP or router that has the strongest signal, ensuring that data rates can be as good as possible.

Better User Experience

Instead of ineffective transmission with low basic rates or RSSI, the better links provide better user experience while saving the airtime.

No Controller Required

Assisted Roaming is a built-in feature in all Vigor Access Points and a number of Wi-Fi routers; it saves the need for an ad-hoc wireless controller and is an ideal solution for simple network deployments.

Hotspot Web Portal

Market your business while offering free Wi-Fi

Wi-Fi Marketing

Redirect hotspot guests to the company homepage, online surveys, or display a promotion message.

Grow Customer Mailing List

Require guests to leave contact info or social media accounts before they can use the Internet services.

Various Authentication Types

A variety of login methods are supported to meet your business needs, including Facebook Login, Google Login, SMS PIN, Voucher PIN, and RADIUS.

3rd-Party Service Compliant

Supports external captive portal authentication so you can keep using the Wi-Fi marketing solution you prefer.

Data Quota Management

Bandwidth management is integrated into the Hotspot features to control the bandwidth and session usage of the Hotspot guests.

Management Solution

All-in-One Management
Mesh (ac model)Central Switch ManagementCentral AP Management
  • Discovery
  • Provisioning
  • Monitoring
  • Centralised Hierarchy View
  • Auto-Discovery
  • Provisioning
  • Monitoring
  • Centralised Hierarchy View
  • Reboot PoE Devices Remotely
  • Quick VLAN Configuration
  • Auto-Discovery
  • Auto-Provisioning
  • Monitoring
  • Centralised View
  • Alarm
  • Reboot VigorAP Remotely
  • Wi-Fi Client Load Balancing
Software Management
VigorACS 2VigorACS 3
  • Provisioning
  • Monitoring
  • Centralised Hierarchy View
  • Alarm
  • Reboot Vigor Devices Remotely
  • Scheduled Maintenance
  • Report
  • Zero Touch Deployment & Provisioning
  • Auto VPN
  • Interface Quality & SLA
  • VoIP Optimization & Monitoring
  • Application Visibility
  • Application Based SD-WAN Policy
  • Customized Hotspot Page with Multilingual
  • Hotspot Clients Analytics
  • ACS Server Load Balancing / Failover

In-the-Box

Vigor2927/ax/ac/Vac

Antenna x 2
(ax/ac/Vac model)

RJ-45 Cable
(Ethernet)

Power Adaptor

Quick Start Guide

Note :

The throughput figures are maximum, based on DrayTek internal testing with optimal conditions. The actual performance may vary depending on the different network conditions and applications activated.

Models

ModelVigor2927Vigor2927axVigor2927ac
Product
Gigabit WAN111
Configurable GbE WAN/LAN port111
4G LTE/3G2 x USB 2.02 x USB 2.02 x USB 2.0
Wireless WAN
2
Gigabit LAN555
VPN Tunnels505050
Wireless LAN
WiFi 6, AX3000WiFi 5, AC1300
Wi-Fi Antenna
3dBi for 5GHz
2.5dBi for 2.4GHz
3dBi for 5GHz
2.5dBi for 2.4GHz
VoIP (2xFXS)

Specifications

Interface (DISABLE)

Interface
Fixed WAN Port1 x Gigabit Ethernet
LAN/WAN Switchable Port1 x Gigabit Ethernet
Fixed LAN Port5 x Gigabit Ethernet
USB Port2 x USB 2.0 for 3G/4G/LTE USB modem, storage, printer or thermometer
RJ-11 Port for Voice2 x FXS (V model)
Wi-Fi Antenna2 x External Dipole
Gain: 3 dBi for 5GHz, 2.5 dBi for 2.4GHz (ax/ac/Vac models)
2.4G WLAN802.11n 2×2 MIMO 400Mbps (ac/Vac models)
802.11ax 2×2 MIMO 574Mbps (ax model)
5G WLAN802.11ac Wave 2 2×2 MU-MIMO 867Mbps (ac/Vac models)
802.11ax Wave 2 2×2 MU-MIMO 2402Mbps (ax model)

Performance (DISABLE)

Performance
NAT Throughput800 Mbps
NAT Throughput
with Hardware Acceleration
940 Mbps (Ethernet WAN)
1.8 Gbps (Dual WAN)
IPsec VPN Performance290 Mbps (AES 256 bits)
SSL VPN Performance120 Mbps
Max. Number of NAT Sessions60,000
Max. Concurrent VPN Tunnels50
Max. Concurrent OpenVPN/ SSL-VPN25

Internet Connection (DISABLE)

Internet Connection
IPv4PPPoE, DHCP, Static IP, PPTP/L2TP
IPv6PPP, DHCPv6, Static IP, TSPC, AICCU, 6rd, 6in4 Static Tunnel
802.1p/q Multi-VLAN Tagging
Multi-VLAN/PVC
Wireless WAN2 (ac/Vac models)
3G/4G/LTE WAN with USB modem
Load BalancingIP-based, Session-based
WAN Active on DemandLink Failure, Traffic Threshold
Connection DetectionARP, Ping
WAN Data Budget
Dynamic DNS
DrayDDNS

LAN Management (DISABLE)

LAN Management
VLAN802.1q Tag-based, Port-based
Max. Number of VLAN16
Number of LAN Subnet8
DHCP ServerMultiple IP Subnet, Custom DHCP Options, Bind-IP-to-MAC
LAN IP Alias
Wired 802.1x Authentication
Port Mirroring
Local DNS Server
Conditional DNS Forwarding
Hotspot Web Portal
Hotspot AuthenticationClick-Through, Social Login, SMS PIN, Voucher PIN, RADIUS, External Portal Server

Networking (DISABLE)

Networking
RoutingIPv4 Static Routing, IPv6 Static Routing, Inter-VLAN Routing, RIP, BGP (IPv4)
Policy-based RoutingProtocol, IP Address, Port, Domain, Country
High Availability
DNS Security (DNSSEC)
IGMPIGMP v2/v3, IGMP Proxy, IGMP Snooping & Fast Leave
Local RADIUS server
SMB File Sharing (Requires external storage)

VPN (DISABLE)

VPN
LAN-to-LAN
Teleworker-to-LAN
ProtocolsPPTP, L2TP, IPsec, L2TP over IPsec, SSL, GRE, IKEv2, IKEv2-EAP, IPsec-XAuth, OpenVPN (Host to LAN)
User AuthenticationLocal, RADIUS, LDAP, TACACS+, mOTP
IKE AuthenticationPre-Shared Key, X.509
IPsec AuthenticationSHA-1, SHA-256
EncryptionMPPE, DES, 3DES, AES
VPN Trunk (Redundancy)Load Balancing, Failover
Single-Armed VPN
NAT-Traversal (NAT-T)
DrayTek VPN Matcher

Firewall & Content Filtering (DISABLE)

Firewall & Content Filtering
NATPort Redirection, Open Ports, Port Triggering, DMZ Host, UPnP
ALG (Application Layer Gateway)SIP, RTSP, FTP, H.323
VPN Pass-ThroughPPTP, L2TP, IPsec
IP-based Firewall Policy
Content FilteringApplication, URL, DNS Keyword, Web Features, Web Category (subscription required)
DoS Attack Defense
Spoofing Defense

Bandwidth Management (DISABLE)

Bandwidth Management
IP-based Bandwidth Limit
IP-based Session Limit
QoS (Quality of Service)TOS, DSCP, 802.1p, IP Address, Port, Application
VoIP Prioritisation

Wireless LAN (wireless model) (DISABLE)

Wireless LAN (ax/ac/Vac models)
Number of SSID4 per radio band
SecurityWEP, WPA, WPA2, Mixed (WPA+WPA2), WPA3
AuthenticationPre-Shared Key, 802.1x
WPSPIN, PBC
WDSRepeater (5GHz only)
Access ControlAccess List, Client Isolation, Hide SSID, Wi-Fi Scheduling
AirTime Fairness
Band Steering
MU-MIMO (5GHz only)
WMM

VoIP Gateway (Vac model) (DISABLE)

VoIP Gateway (Vac model)
ProtocolSIP, RTP/RTCP, ZRTP
SIP Registrars12
Dial PlanPhone Book, Digit Map, Call Barring, Regional
Call FeaturesCall Waiting, Call Transfer, Scheduled DND, Hotline
Voice CodecG.711 A/u law, G.723.1, G.726, G.729 A/B
Caller IDFSK_ETSI, FSK_BELLCORE, DTMF

Management (DISABLE)

Management
Local ServiceHTTP, HTTPS, Telnet, SSH, TR-069
Config File Export & Import
Config File CompatibilityVigor2926 Series
Firmware UpgradeTFTP, HTTP, TR-069
2-Level Administration Privilege
Access ControlAccess List, Brute Force Protection
Syslog
Notification AlertSMS, E-mail
SNMPv2, v2c, v3
Managed by VigorACS
Central VPN Management8 remote Vigor routers
Central AP Management20 VigorAPs
Mesh Network7 VigorAPs (ac/Vac models only)
Central Switch Management10 VigorSwitches

Physical (DISABLE)

Physical
Rack Mountable Mouting Kit Excluded (DR101)
Power SupplyDC 12V @ 2A
Max. Power Consumption24 watts (ac model)
Dimension241mm x 165mm x 44mm
Weight630g (ac model)
Operating Temperature0 to 45°C
Storage Temperature-25 to 70°C
Operating Humidity (non-condensing)10 to 90%
Certificate

Note :

  • All specifications are subject to change without notice.
  • The throughput figures are maximum, based on DrayTek internal testing with optimal conditions. The actual performance may vary depending on the different network conditions and applications activated.

DrayTek Vigor2927ax Review Published in APC Magazine – Xmas 2022

DrayTek Vigor2927ac Review Published in APC Magazine – Jun 2021

Multi-subnets

The Vigor2926 supports up to 8 LAN IP subnets, an IP Routed subnet and a DMZ port.

The 8 LAN IP subnets can be assigned to 16 VLANS allowing the creation of logical workgroups to provide additional security and traffic management within an organisation.

For example, within a building each tenant or workgroup can be assigned their own IP network. In addition, workgroups can also be located in different physical locations or floors within a building. For example, a Sales Department may be located on the 1st floor of a building, but some of the sales people are located on the second floor and still be part of the sales VLAN.

The IEEE 802.1q VLAN trunk feature means that only a single LAN cable connection is required between the router and the VigorSwitch, create a number of VLANs for different departments.

The VLAN Tag Priority setting can be used to prioritise traffic for certain VLANS or workgroups.

Multi-site business deployment

Increase remote access security to your office by combining both VPN and Firewall features in the Vigor2926.

The Vigor2926 supports up to 50 simultaneous VPN tunnels (such as IPSec/PPTP/L2TP/SSL protocols) for secure data exchange and communication. In addition, 25 SSL VPN tunnels are available for teleworkers to access the office LAN. Teleworkers can be authenticated directly with your LDAP server if preferred. The SSL technology is same as the encryption used for secure web sites such as online banking.

Security is enhanced by utilising firewall features such as web content and URL filtering in addition to restricting access to P2P traffic and Instant Messaging applications.

The Vigor2926 series is equipped with two Gigabit Ethernet ports and two USB WAN ports for WAN load-balancing and backup. This allows backup VPN tunnels to be created to branch office networks to ensure maximum VPN connectivity uptime. In addition, the VPN Trunking feature can be used to set up dual VPN tunnel links to branch office networks to increase bandwidth and provide redundancy and backup to prevent downtime due to one of the WAN connections failing.

Comprehensive Firewall

The comprehensive firewall in the Vigor2926 router protects your network by using Stateful Packet Inspection (SPI) and extensive firewall filtering rules. Stateful Packet Inspection monitors incoming and outgoing data packets at layer 3. It maintains a table of open connections and inspects the payload to determine its data will be passed or blocked by matching known active legitimate connections.

The DoS (Denial of Service) Defense also protects your network against a number of attacks from the Internet.

The URL and Web content filters are also available to restrict access to certain websites (such as Social Networking, Gambling, etc.) for some users and it can be enforced according to a time schedule.

The DMZ Host feature allows you to place a server in the DMZ so it can be access from the Internet but not exposing your main network to the Internet.

USB Thermometer

The optional USB thermometer can be attached to the Vigor2926 to provide logging of the ambient temperature in the server room. Upper and lower temperature thresholds can be set and when the temperature exceeds these thresholds and alarm is generated. This alarm can be sent to the network administrator via email or SMS to alert them of the environmental issue.

802.11ac Wave 2 (for ac/Vac model)

802.11ac Wave 2 can simultaneously stream to multiple users to maximise bandwidth utilisation.

Vigor2926ac routers now operate 802.11ac Wave 2 Wi-Fi with support for MU-MIMO, TX Beam Forming, 1733Mb/s Link Rate and up to 4 spatial streams. This allows up to 4 wireless clients such as laptops or smartphones to have simultaneous access to a Wi-Fi channel. The result is an increased performance of the Wi-Fi network.

Central Management – AP / Switch / VPN Management

The central management features allow the network administrator to monitor and configure Vigor devices including VigorAPs, Vigor Switches, and even Vigor Routers from a central management console built into the Vigor2926 series router. Maintenance tasks such as firmware upgrades, configuration backup and restoration as well as and monitoring be done from a single portal.

Three options are available in Central Management. These are:

  • VPN Management
  • AP Management
  • Switch Management

VPN management supports 8 external CPE devices and allows the creation and management of IPSec, PPTP or SSL VPN tunnels from the central Vigor2926 router to the remote routers.

The AP Management feature allows the monitoring and auto-configuration of up to 20 DrayTek Access Points connected to the Vigor2926 LAN. Automatic Provisioning can be triggered when a new Access point is connected to the LAN. Other features include client or traffic history of the AP and configuration of load balancing rules for the Access Points.

Switch Management allows you to manage up to 10 VigorSwitches. It simplifies the task of configuring VLANS in attached VigorSwitches matching the router’s VLAN settings. It also displays the switch status as well as the network topology through the switch hierarchy feature.

Flexible Installation with Rackmount

The Vigor2926 series router can be rack mounted into a standard 19’ rack or cabinet. The 1RU rack mounting kit allows the front panel of the router to be easily accessible as well as keeping it secure in the communications rack.

  • 1 x Gigabit Ethernet WAN port and 1 x configurable GbE WAN/LAN port for Failover, Load-Balancing and High Availability mode

  • Two USB 2.0 ports for connection to two 3G/4G LTE USB modems, FTP server and network printer
  • 4 x Gigabit LAN ports with multiple subnets and 50,000 NAT sessions
  • 50 x VPN tunnels (including 25 SSL-VPN tunnels) with comprehensive secure protocols
  • Fast VPN throughput, VPN load-balancing and backup for site-to-site applications
  • 16 x VLANs for secure and efficient workgroup management
  • IPv6 & IPv4
  • Up to 1022 IP addresses and 8 IP subnets

  • Integrated IEEE 802.11n wireless Access Point (n model)

  • Integrated IEEE 802.11ac (AC2000) wireless Access Point; dual band; up to 1.7Gbps throughput (ac/Vac model)

  • 2 x FXS and 1 x FXO Line VoIP Port (Vac model)

  • High Availability mode

  • Object-based SPI Firewall and CSM (Content Security Management) for network security
  • Supports VigorACS 2 Central Management System for remote management

  • Central VPN Management for 8 remote Vigor routers
  • Central AP Management for deployment of multiple wireless VigorAPs
  • 2 years back to base warranty

Overview

The Vigor2926 Series provides multi-WAN broadband connectivity to ensure a reliable Internet connection for businesses. Two Gigabit Ethernet WAN ports are featured, which can be configured in either Failover or Load Balancing mode, or alternatively WAN 2 can be configured as an additional LAN port if a second Ethernet WAN connection is not required. Two USB ports are also featured which can work with 3G/4G/LTE USB modems to add wireless Internet access for additional load balancing or failover.

The Vigor2926 Series also have comprehensive security and management features including VLAN, Bandwidth Management, Quality of Service, DNS Control, SPI Firewall, Web Content Filtering and Central Management solutions to provide a reliable and secure business network.

  • 1 x fixed GbE WAN port and 1 x configurable GbE WAN/LAN port for Failover, Load Balancing and High Availability mode

  • Two USB 2.0 ports for connection to two 3G/4G LTE USB modems, FTP server, network printer and thermometer
  • 5 x Gigabit LAN ports with multiple subnets and 60,000 NAT sessions
  • 50 x VPN tunnels (including 25 x OpenVPN/ SSL-VPN tunnels) with comprehensive secure protocols

  • Fast VPN throughput, VPN Load Balancing and backup for site-to-site VPN applications

  • Hardware Acceleration and Hardware QoS for up to 8k NAT and routing connections, and 940Mbps (Single WAN) or 1.8Gbps (Multi-WAN) Firewall speed

  • 16 x VLANs for secure and efficient workgroup management

  • IPv6 & IPv4
  • Up to 1022 IP addresses and 8 IP subnets

  • Integrated IEEE 802.11ax (WiFi 6, AX3000) wireless Access Point; dual band; up to 2402 Mbps throughput (ax model)

  • Integrated IEEE 802.11ac (AC1300) wireless Access Point; dual band; up to 867 Mbps throughput (ac/Vac models)

  • 2 x FXS VoIP ports (Vac model)
  • High Availability mode
  • Object-based SPI Firewall and CSM (Content Security Management) for network security
  • Supports VigorACS 2 and VigorACS 3 Central Management Software for remote management

  • SD WAN capability when used with VigorACS 3
  • Central VPN Management for up to 8 remote Vigor routers Learn More
  • Central AP Management for up to 20 Vigor Access Points Learn more
  • Central Switch Management for up to 10 VigorSwitches Learn More
  • Supports Web Content Filter (content security management software)
  • 2 years back to base warranty

Dual Ethernet WAN Broadband Security Routers for SMBs

The Vigor2927 Series are dual-Ethernet WAN Firewall routers providing Load Balancing and Failover for reliable Internet accesses. Featuring VPN, QoS, Route Policy, Firewall, Content Filtering, Bandwidth Management, Captive Hotspot Portal and a lot more, these are the ultimate routers for SMBs. The series include models with built-in 802.11ax (WiFi 6, AX3000)/ 802.11ac Wi-Fi and a VoIP gateway (Vac model).

Vigor2927ax

802.11ax (WiFi 6, AX3000)

Performance Comparison: Vigor2927 vs. Vigor2926

NAT throughput (1.6 times faster)

800 Mbps

Vigor2927 Series

500 Mbps

Vigor2926 Series

IPSec throughput (3.6 times faster)

290 Mbps

Vigor2927 Series

80 Mbps

Vigor2926 Series

SSL-VPN throughput (2.7 times faster)

120 Mbps

Vigor2927 Series

45 Mbps

Vigor2926 Series

Key Features

Hardware Acceleration

Without sacrificing traffic control features such as QoS, Bandwidth Limit, WAN Budget, Traffic Graph and Data Flow Monitor, Hardware Acceleration enhances performance for:

  • NAT & routing connections
  • QoS
  • IPsec VPN

Hardware NAT & Routing

With Hardware Acceleration and Hardware QoS enabled, the router supports up to 8k NAT and routing connections, and firewall performance reaching 940Mbps on single WAN and 1.8Gbps combined performance on multi-WANs.

Dual WAN (Ethernet + DSL)

2.3x Faster NAT Performance

1.8 Gbps

with Hardware NAT & Routing

800 Mbps

without Hardware NAT & Routing

Single Ethernet WAN

1.2x Faster NAT Performance

940 Mbps

with Hardware NAT & Routing

800 Mbps

without Hardware NAT & Routing

Hardware QoS

Hardware QoS allows prioritization of applications and services on DrayTek routers, to improve performance of critical applications such as VoIP, conferencing and video streaming, etc. Furthermore, it allows flexible bandwidth allocation to suit business requirements.

Dual WAN (Ethernet + DSL)

2.6x Faster QoS Performance

1.8 Gbps

with Hardware QoS

700 Mbps

with Software QoS

Single Ethernet WAN

1.3x Faster QoS Performance

940 Mbps

with Hardware QoS

700 Mbps

with Software QoS

Hardware IPsec

While the Vigor2927 series already has improved IPsec performance over the previous Vigor2862 series, with Hardware Acceleration enabled, IPsec performance can now reach 800 Mbps. The first 16 tunnels are automatically accelerated on a first come first serve basis. If any drops out, a new tunnel will be put into the accelerator automatically to top off 16 accelerated tunnels.

2.7x Faster IPsec Performance

800 Mbps

with Hardware IPsec

300 Mbps

with Software IPsec

App QoS

Application QoS allows prioritisation of applications and services on DrayTek routers to improve and enhance critical applications such as VoIP, conferencing and video streaming, etc. It also allow flexible bandwidth allocation to suit business requirements.

VoIP First

VoIP is always a top priority! The default VoIP port, UDP 5060 (configurable) has priority out-of-box with QoS.

Improve Experience for Business-Critical Apps

Select your business critical apps, and easily put them into QoS classes.

Flexible Bandwidth Allocation

Bandwidth will be reserved for high-priority classes, and can be used by low-priority classes when available.

New OFDMA Feature for 802.11ax (WiFi 6) – Vigor2927ax only

Higher Transmission Efficiency with OFDMA

OFDMA has been used in LTE for many years, and is now available in 802.11ax for multi-user mode.

With legacy OFDM, each frame is transmitted across the entire channel width. When the transmission rate is low, this causes more latency and jitters and lower the overall efficiency.

OFDMA splits a single frame into groups of subcarriers, and each subcarrier can be sent simultaneously. With multiple access mode, it allows multiple users to transmit at the same time thus improving efficiency and enhancing user experiences in high density environments.

OFDM

OFDMA

802.11ax (WiFi 6) Downlink & Uplink MU-MIMO (Vigor2927ax only)

802.11ax (WiFi 6) BSS Colouring (Vigor2927ax only)

In traditional 802.11 Wi-Fi networks, access points are designed to wait and take turns if other signals of the same frequency are detected from adjacent access points. This sharing of a resource, in this case radio frequencies, is called a basic service set (BSS). 802.11ax adds Colouring to the BSS information being broadcast so that APs can use the same channel at the same time without having to take turns. This increases Wi-Fi efficiency, particularly in high density environments.

In the diagram here, AP1 and AP4 are using Channel 1 simultaneously, which normally means they would have to take turns if transmitting information at the same time. However, using BSS Colouring, the 2 APs can now transmit simultaneously without waiting.

An 802.11ax AP using BSS Colouring has the ability to change its BSS Colour if it detects another AP using the same BSS Colour on the same frequency.

AP-Assisted Roaming – built-in in selected Wi-Fi Vigor Routers and all Vigor Access Points

Extend Transmission Range

When a Wi-Fi client moves out of its effective transmission range which is defined by the Basic Rate and/or Received Signal Strength threshold, the AP forces the Wi-Fi client to pick up a nearby access point with stronger signals thereby extending the range.

Improve Data Rates

When the “Minimum RSSI with Adjacent AP” option is set, APs or routers on the same local subnet will exchange client information with each other and switch to the AP or router that has the strongest signal, ensuring that data rates can be as good as possible.

Better User Experience

Instead of ineffective transmission with low basic rates or RSSI, the better links provide better user experience while saving the airtime.

No Controller Required

Assisted Roaming is a built-in feature in all Vigor Access Points and a number of Wi-Fi routers; it saves the need for an ad-hoc wireless controller and is an ideal solution for simple network deployments.

Hotspot Web Portal

Market your business while offering free Wi-Fi

Wi-Fi Marketing

Redirect hotspot guests to the company homepage, online surveys, or display a promotion message.

Grow Customer Mailing List

Require guests to leave contact info or social media accounts before they can use the Internet services.

Various Authentication Types

A variety of login methods are supported to meet your business needs, including Facebook Login, Google Login, SMS PIN, Voucher PIN, and RADIUS.

3rd-Party Service Compliant

Supports external captive portal authentication so you can keep using the Wi-Fi marketing solution you prefer.

Data Quota Management

Bandwidth management is integrated into the Hotspot features to control the bandwidth and session usage of the Hotspot guests.

Management Solution

All-in-One Management
Mesh (ac/Vac models)
Up to 7 APs
  • Discovery
  • Provisioning
  • Monitoring
  • Centralised Hierarchy
    View
Central AP Management
Up to 2 APs
  • Auto-Discovery
  • Auto-Provisioning
  • Monitoring
  • Centralised View
  • Alarm
  • Reboot VigorAP
    Remotely
  • Wi-Fi Client Load
    Balancing
Software Management
VigorACS 2
  • Provisioning
  • Monitoring
  • Centralised Hierarchy
    View
  • Alarm
  • Reboot Vigor Devices
    Remotely
  • Scheduled Maintenance
  • Report
VigorACS 3
  • Zero Touch Deployment
    & Provisioning
  • Auto VPN
  • Interface Quality & SLA
  • VoIP Optimization
    & Monitoring
  • Application Visibility
  • Customized Hotspot
    Page with Multilingual
  • Hotspot Clients
    Analytics
  • ACS Server Load
    Balancing / Failover

In-the-Box

Vigor2927/ax/ac/Vac

Antenna x 2
(ax/ac/Vac model)

RJ-45 Cable
(Ethernet)

Power Adaptor

Quick Start Guide

Note :

The throughput figures are maximum, based on DrayTek internal testing with optimal conditions. The actual performance may vary depending on the different network conditions and applications activated.

Models

Vigor2927

Vigor2927
  • Gigabit WAN: 1
  • Selectable Gigabit WAN/LAN: 1
  • 4G LTE/3G: 2 x USB 2.0
  • Wireless WAN: n/a
  • Gigabit LAN: 5
  • VPN Tunnels: 50
  • Wireless LAN: n/a
  • Wi-Fi Antenna: n/a
  • VoIP (2xFXS): n/a

Vigor2927ax

Vigor2927ax
  • Gigabit WAN: 1
  • Selectable Gigabit WAN/LAN: 1
  • 4G LTE/3G: 2 x USB 2.0
  • Wireless WAN: n/a
  • Gigabit LAN: 5
  • VPN Tunnels: 50
  • Wireless LAN: WiFi 6, AX3000
  • Wi-Fi Antenna:
    3dBi for 5GHz
    2.5dBi for 2.4GHz
  • VoIP (2xFXS): n/a

Vigor2927ac

Vigor2927ac
  • Gigabit WAN: 1
  • Selectable Gigabit WAN/LAN: 1
  • 4G LTE/3G: 2 x USB 2.0
  • Wireless WAN: 2
  • Gigabit LAN: 5
  • VPN Tunnels: 50
  • Wireless LAN: WiFi 5, AC1300
  • Wi-Fi Antenna:
    3dBi for 5GHz
    2.5dBi for 2.4GHz
  • VoIP (2xFXS): n/a

Specifications

Interface (DISABLE)

Interface
Fixed WAN Port:
1 x Gigabit Ethernet
LAN/WAN Switchable Port:
1 x Gigabit Ethernet
Fixed LAN Port:
5 x Gigabit Ethernet
USB Port:
2 x USB 2.0 for
3G/4G LTE USB modem, storage,
printer or thermometer
RJ-11 Port for Voice:
2x FXS (V model)
Wi-Fi Antenna:
2 x External Dipole
Gain: 3 dBi for 5GHz, 2.5 dBi for
2.4GHz (ax/ac/Vac models)
2.4G WLAN:
802.11n 2×2 MIMO
400Mbps (ac/Vac models)

802.11ax 2×2 MIMO
574Mbps (ax model)
5G WLAN:
802.11ac Wave 2 2×2 MU-MIMO
867Mbps (ac/Vac models)

802.11ax Wave 2 2×2 MU-MIMO
2402Mbps (ax model)

Performance (DISABLE)

Performance
NAT Throughput:
800 Mbps
NAT Throughput
with Hardware Acceleration:
940 Mbps (Single WAN)
1.8 Gbps (Dual WAN)
IPsec VPN Performance:
290 Mbps (AES 256 bits)
SSL VPN Performance:
120 Mbps
Max. Number of
NAT Sessions:
60,000
Max. Concurrent
VPN Tunnels:
50
Max. Concurrent
OpenVPN / SSL-VPN:
25

Internet Connection (DISABLE)

Internet Connection
IPv4:
PPPoE, DHCP, Static IP, PPTP/L2TP
IPv6:
PPP, DHCPv6, Static IP, TSPC, AICCU,
6rd, 6in4 Static Tunnel
802.1p/q Multi-VLAN
Tagging
Multi-VLAN/PVC
Wireless WAN:
2 (ac/Vac models)
3G/4G/LTE WAN with
USB modem
Load Balancing:
IP-based, Session-based
WAN Active on Demand:
Link Failure, Traffic Threshold
Connection Detection:
ARP, Ping
WAN Data Budget
Dynamic DNS
DrayDDNS

LAN Management (DISABLE)

LAN Management
VLAN:
802.1q Tag-based, Port-based
Max. Number of VLAN:
16
Number of LAN Subnet:
8
DHCP Server:
Multiple IP Subnet,
Custom DHCP Options,
Bind-IP-to-MAC
LAN IP Alias
Wired 802.1x
Authentication
Port Mirroring
Local DNS Server
Conditional DNS
Forwarding
Hotspot Web Portal
Hotspot Authentication:
Click-Through, Social Login, SMS PIN,
Voucher PIN, RADIUS,
External Portal Server

Networking (DISABLE)

Networking
Routing:
IPv4 Static Routing,
IPv6 Static Routing,
Inter-VLAN Routing, RIP, BGP (IPv4)
Policy-based Routing:
Protocol, IP Address, Port, Domain,
Country
High Availability
DNS Security (DNSSEC)
Multicast:
IGMP Proxy, IGMP Snooping &
Fast Leave, Bonjour
Local RADIUS server
SMB File Sharing
(Requires external storage)

VPN (DISABLE)

VPN
LAN-to-LAN
Teleworker-to-LAN
Protocols:
PPTP, L2TP, IPsec, L2TP over IPsec,
SSL, GRE, IKEv2, IKEv2-EAP,
IPsec-XAuth, OpenVPN (Host to LAN)
User Authentication:
Local, RADIUS, LDAP, TACACS+,
mOTP
IKE Authentication:
Pre-Shared Key, X.509
IPsec Authentication:
SHA-1, SHA-256
Encryption:
MPPE, DES, 3DES, AES
VPN Trunk (Redundancy):
Load Balancing, Failover
Single-Armed VPN
NAT-Traversal (NAT-T)
DrayTek VPN
Matcher

Firewall & Content Filtering (DISABLE)

Firewall & Content Filtering
NAT:
Port Redirection, Open Ports,
Port Triggering, DMZ Host, UPnP
ALG (Application Layer Gateway):
SIP, RTSP, FTP, H.323
VPN Pass-Through:
PPTP, L2TP, IPsec
IP-based Firewall Policy
Content Filtering:
Application, URL, DNS Keyword,
Web Features, Web Category
(subscription required)
DoS Attack Defense
Spoofing Defense

Bandwidth Management (DISABLE)

Bandwidth Management
IP-based Bandwidth
Limit
IP-based Session
Limit
QoS (Quality of Service):
TOS, DSCP, 802.1p, IP Address,
Port, Application
VoIP Prioritisation

Wireless LAN (wireless model) (DISABLE)

Wireless LAN (ax/ac/Vac models)
Number of SSID:
4 per radio band
Security:
WEP, WPA, WPA2,
Mixed (WPA+WPA2), WPA3
Authentication:
Pre-Shared Key, 802.1x
WPS:
PIN, PBC
WDS:
Repeater (5GHz only)
Access Control:
Access List, Client Isolation,
Hide SSID, Wi-Fi Scheduling
AirTime Fairness
Band Steering
MU-MIMO
(5GHz only)
WMM

VoIP Gateway (Vac model) (DISABLE)

VoIP Gateway (Vac model)
Protocol:
SIP, RTP/RTCP, ZRTP
SIP Registrars:
12
Dial Plan:
Phone Book, Digit Map,
Call Barring, Regional
Call Features:
Call Waiting, Call Transfer,
Scheduled DND, Hotline
Voice Codec:
G.711 A/u law, G.723.1, G.726, G.729 A/B
Caller ID:
FSK_ETSI, FSK_BELLCORE, DTMF

Management (DISABLE)

Management
Local Service:
HTTP, HTTPS, Telnet, SSH, TR-069
Config File Export &
Import
Config File Compatibility:
Vigor2926 Series
Firmware Upgrade:
TFTP, HTTP, TR-069
2-Level
Administration
Privilege
Access Control:
Access List, Brute Force Protection
Syslog
Notification Alert:
SMS, E-mail
SNMP:
v2, v2c, v3
Managed by
VigorACS
Central VPN Management:
8 remote Vigor routers
Central AP Management:
20 VigorAPs
Mesh Network:
7 VigorAPs (ac/Vac models only)
Central Switch
Management:
10 VigorSwitches

Physical (DISABLE)

Physical
Rack Mountable
Mouting Kit Excluded
(DR101)
Power Supply:
DC 12V @ 2A
Max. Power Consumption:
24 watts (ac model)
Dimension:
241mm x 165mm x 44mm
Weight:
630g (ac model)
Operating Temperature:
0 to 45°C
Storage Temperature:
-25 to 70°C
Operating Humidity
(non-condensing):
10 to 90%
Certificate:

Note :

  • All specifications are subject to change without notice.
  • The throughput figures are maximum, based on DrayTek internal testing with optimal conditions. The actual performance may vary depending on the different network conditions and applications activated.

DrayTek Vigor2927ax Review Published in APC Magazine – Xmas 2022

DrayTek Vigor2927ac Review Published in APC Magazine – Jun 2021

Multi-subnets

The Vigor2926 supports up to 8 LAN IP subnets, an IP Routed subnet and a DMZ port.

The 8 LAN IP subnets can be assigned to 16 VLANS allowing the creation of logical workgroups to provide additional security and traffic management within an organisation.

For example, within a building each tenant or workgroup can be assigned their own IP network. In addition, workgroups can also be located in different physical locations or floors within a building. For example, a Sales Department may be located on the 1st floor of a building, but some of the sales people are located on the second floor and still be part of the sales VLAN.

The IEEE 802.1q VLAN trunk feature means that only a single LAN cable connection is required between the router and the VigorSwitch, create a number of VLANs for different departments.

The VLAN Tag Priority setting can be used to prioritise traffic for certain VLANS or workgroups.

Multi-site business deployment

Increase remote access security to your office by combining both VPN and Firewall features in the Vigor2926.

The Vigor2926 supports up to 50 simultaneous VPN tunnels (such as IPSec/PPTP/L2TP/SSL protocols) for secure data exchange and communication. In addition, 25 SSL VPN tunnels are available for teleworkers to access the office LAN. Teleworkers can be authenticated directly with your LDAP server if preferred. The SSL technology is same as the encryption used for secure web sites such as online banking.

Security is enhanced by utilising firewall features such as web content and URL filtering in addition to restricting access to P2P traffic and Instant Messaging applications.

The Vigor2926 series is equipped with two Gigabit Ethernet ports and two USB WAN ports for WAN load-balancing and backup. This allows backup VPN tunnels to be created to branch office networks to ensure maximum VPN connectivity uptime. In addition, the VPN Trunking feature can be used to set up dual VPN tunnel links to branch office networks to increase bandwidth and provide redundancy and backup to prevent downtime due to one of the WAN connections failing.

Comprehensive Firewall

The comprehensive firewall in the Vigor2926 router protects your network by using Stateful Packet Inspection (SPI) and extensive firewall filtering rules. Stateful Packet Inspection monitors incoming and outgoing data packets at layer 3. It maintains a table of open connections and inspects the payload to determine its data will be passed or blocked by matching known active legitimate connections.

The DoS (Denial of Service) Defense also protects your network against a number of attacks from the Internet.

The URL and Web content filters are also available to restrict access to certain websites (such as Social Networking, Gambling, etc.) for some users and it can be enforced according to a time schedule.

The DMZ Host feature allows you to place a server in the DMZ so it can be access from the Internet but not exposing your main network to the Internet.

USB Thermometer

The optional USB thermometer can be attached to the Vigor2926 to provide logging of the ambient temperature in the server room. Upper and lower temperature thresholds can be set and when the temperature exceeds these thresholds and alarm is generated. This alarm can be sent to the network administrator via email or SMS to alert them of the environmental issue.

802.11ac Wave 2 (for ac/Vac model)

802.11ac Wave 2 can simultaneously stream to multiple users to maximise bandwidth utilisation.

Vigor2926ac routers now operate 802.11ac Wave 2 Wi-Fi with support for MU-MIMO, TX Beam Forming, 1733Mb/s Link Rate and up to 4 spatial streams. This allows up to 4 wireless clients such as laptops or smartphones to have simultaneous access to a Wi-Fi channel. The result is an increased performance of the Wi-Fi network.

Central Management – AP / Switch / VPN Management

The central management features allow the network administrator to monitor and configure Vigor devices including VigorAPs, Vigor Switches, and even Vigor Routers from a central management console built into the Vigor2926 series router. Maintenance tasks such as firmware upgrades, configuration backup and restoration as well as and monitoring be done from a single portal.

Three options are available in Central Management. These are:

  • VPN Management
  • AP Management
  • Switch Management

VPN management supports 8 external CPE devices and allows the creation and management of IPSec, PPTP or SSL VPN tunnels from the central Vigor2926 router to the remote routers.

The AP Management feature allows the monitoring and auto-configuration of up to 20 DrayTek Access Points connected to the Vigor2926 LAN. Automatic Provisioning can be triggered when a new Access point is connected to the LAN. Other features include client or traffic history of the AP and configuration of load balancing rules for the Access Points.

Switch Management allows you to manage up to 10 VigorSwitches. It simplifies the task of configuring VLANS in attached VigorSwitches matching the router’s VLAN settings. It also displays the switch status as well as the network topology through the switch hierarchy feature.

Flexible Installation with Rackmount

The Vigor2926 series router can be rack mounted into a standard 19’ rack or cabinet. The 1RU rack mounting kit allows the front panel of the router to be easily accessible as well as keeping it secure in the communications rack.