- Dual Gigabit Ethernet WAN ports for failover and load-balancing
- Two USB 2.0 ports for connection to two 3G/4G LTE USB modems, FTP server and network printer
- 4 x Gigabit LAN ports with multiple subnets and 50,000 NAT sessions
- 50 x VPN tunnels (including 25 SSL-VPN tunnels) with comprehensive secure protocols
- Fast VPN throughput, VPN load-balancing and backup for site-to-site applications
- 16 x VLANs for secure and efficient workgroup management
- IPv6 & IPv4
- Increased IP addresses (1022) and IP subnets (8)
- Integrated IEEE 802.11ac (AC2000) wireless Access Point; dual band; up to 1.7Gbps throughput
- High Availability mode
- Object-based SPI Firewall and CSM (Content Security Management) for network security
Supports VigorACS 2 Central Management System for remote management
- Central VPN Management for 8 remote Vigor routers
- Central AP Management for deployment of multiple wireless VigorAPs
- Free Smart Monitor Network Traffic Analyzer for 30-nodes
- 2 years back to base warranty
Vigor2926 Series is a Dual WANs broadband security firewall router.
Vigor2926 Series provides reliable broadband connectivity with the multi-WAN accesses. The two Gigabit Ethernet WAN ports can be operated in failover or load balancing mode to ensure a steady Internet connection. The two USB ports can work with 3G/4G/LTE USB modem to add additional wireless Internet access.
Vigor2926 Series also covers comprehensive functions, including VLAN, Bandwidth Management, Quality of Service, DNS Control, SPI Firewall, Web Content Filtering, and Central Management solutions to provide a reliable and secure business network.
- Faster Wi-Fi speed 802.11ac Wave 2 dual-band wireless for speed up to 1.7Gbps (ac/Vac model) compared to 1300 Mbps for the Vigor2925.
- Increased number of IP addresses supported IP Pool Count (up to 1022) for LAN1~3 subnet, compared to 253 for Vigor2925.
- Increased number of IP subnets (8 in Vigor2926 compared to 5 in Vigor2925)
- Increased number of VLANs (16 in Vigor2926 compared to 8 in Vigor2925)
- Faster processor in Vigor2926
- Faster NAT/Firewall throughput in Vigor2926 series compared to Vigor2925 series (400Mbps for Vigor2926 vs 300Mbps for Vigor2925 series)
- Faster VPN throughput in Vigor2926
|Wireless LAN||11n||11ac (AC2000)||11ac (AC2000)|
|Concurrent Dual Band|
|VoIP (2xFXS, 1xPSTN)|
Vigor2926 Series VS Vigor2925 Series
|2.4GHz: 11b/g/n||2.4GHz: 11b/g/n|
|Wi-Fi Link Rate||2.4GHz: 300Mbps|
|2.4GHz: 300Mbps||2.4GHz: 300Mbps|
|MIMO||2.4GHz: 2×2 SU-MIMO|
5GHz: 4×4 SU-/MU-MIMO
|2.4GHz: 2×2 SU-MIMO|
5GHz: 3×3 SU-MIMO
|2.4GHz: 2×2 SU-MIMO||2.4GHz: 2×2 SU-MIMO|
|Spatial Stream||2.4GHz: 2|
5GHz: 4 (SU-MIMO)/3 (MU-MIMO)
|2.4GHz: 2||2.4GHz: 2|
|Wi-Fi Channel||2.4GHz: 40MHz|
|2.4GHz: 40MHz||2.4GHz: 40MHz|
|TX Beam Forming|
|QAM||2.4GHz: 64 QAM|
5GHz: 256 QAM
|2.4GHz: 64 QAM|
5GHz: 256 QAM
|2.4GHz: 64 QAM||2.4GHz: 64 QAM|
|IP Pool Count||Up to 1022 for Subnet 1-3||253 per Subnet||Up to 1022 for Subnet 1-3||253 per Subnet|
WAN Load Balancing & Failover
Vigor2926 Series has two Gigabit Ethernet WAN ports that can be used for any type of connection, 3G/4G/LTE USB modem can also be attached to the USB ports of the router, and offer wireless Internet connectivity in case the fixed lines are not available. All of the WAN interfaces can be configured to be operated in either Load Balancing mode, which will be active all the time, or in Failover mode, which will be active only when detecting connection loss or heavy load on the primary connection.
On Vigor2926 Series, Load Balancing can be either IP-based mode, which will distribute the packets destined to different IP address across different WANs, or Session-based mode, which allows the packets of different sessions to take different paths, which means a multiple-session connection can be established across multiple WANs, and use multiple WAN’s bandwidth at the same time. Policy-based Load Balancing is also supported so that you may specify the path for some certain packets.
To increase network accessibility, Vigor2926 Series also supports High Availability feature and allows one or more redundant Vigor2926 Series to be added to the network and operated in standby mode.
Flexible LAN Management
The 4-port Gigabit Ethernet switch on the LAN side provides high-speed connectivity for the servers and PCs on the local network, and the Virtual LAN (VLAN) feature allows you to separate the LAN clients into different logical domains thus to increase the security and network efficiency. Vigor2926 Series support 802.1Q standard and can build a Tag-based VLAN system with an 802.1Q support switch, Port-based VLAN is also supported that each LAN port can be configured as a member of different VLAN and be isolated from each other without the use of VLAN tag.
Firewall & Security
Vigor2926 Series supports Stateful Packet Inspection (SPI) Firewall and flexible filtering rules, it can accept or deny packets based on the information in the packet header (such as source IP, destination IP, protocol, and port number) or the packet’s application. IP-based restrictions can be set to filter certain HTTP traffic as well as various application software and help you to prevent time and network resource wasting on inappropriate network activities.
With an annual subscription to Cyren Web Content Filtering service, you may also filter the websites by their categories, and set up restrictions to block the whole categories of websites (such as Social Networking, Gambling.. etc.) without the need to specify every site you would like to block. The Cyren service is constantly updating the categorization, and a free 30-day trial is included in each new router.
The Vigor2926 Series firewall also includes DoS (Denial of Service) Defense to protect the network against variants of attacks.
Vigor2926 Series supports both LAN-to-LAN VPN and Remote Dial-in VPN, up to 50 VPN tunnels (Including 25 SSL VPN tunnels) can be set up simultaneously. All the industry standard tunneling protocols are supported, including PPTP, L2TP, IPsec, and GRE, and it’s compatible with 3rd party VPN devices.
Vigor2926 Series also support SSL VPN – a type of VPN based on the very common encryption method which is used by all the HTTPS websites. While the traditional VPN protocols might be filtered by the firewall and NAT of public networks, SSL VPN will be passed as long as the HTTPS is allowed. DrayTek also offers free official client App for Windows, iOS, and Android.
VPN Trunking is also supported by Vigor2926 Series, this allows you to establish two VPN tunnels to the same remote site but through different WAN interfaces. The two trunking tunnels can be set up in load balancing or failover mode.
Vigor2926 Series can be the central management portal for all the Vigor devices on the same network, including VigorAPs and VigorSwitches, which allows the administrator to manage all the devices through a single portal. Vigor2926 Series also embeds CVM (Central VPN Management), an easier way for Network administrator to establish and manage VPN connections between several CPEs (VPN Client). The router itself supports TR-069 protocol and can be remotely managed and monitored through the TR-069-based VigorACS system, thus to reduce the need for on-site technicians.
DrayTek Vigor2926 Series –
Dual WAN Gigabit broadband firewall router review published on techradar.com
- Hardware Interface
- 2 x 10/100/1000Base-TX, RJ-45 (WAN1/WAN2)
- 4 x 10/100/1000Base-TX LAN, RJ-45 (Configurable Physical DMZ on Port4)
- 2 x Detachable Antennas (n model)
- 4 x Detachable Antennas (ac,Vac Model)
- 2 x USB Host 2.0
- 1 x Factory Reset Button
- 1 x Wireless On/Off/ WPS Button (n/ac/Vac model)
- 2 x FXS and 1 x Life Line Port, RJ11 (Vac Model)
- Operating: 0°C~45°C
- Storage: -25°C~70°C
- Humidity: 10%~90% (non-condensing)
- Power Adapter: DC 12V @ 1.5A~2A
- Power Consumption: 19~24 Watt
- Dimension: L241*W165*H44 (mm)
- WAN Protocol
- Ethernet WAN:
- DHCP Client
- Static IP
- PPTP / L2TP (WAN-2 only)
- 802.1q Multi-VLAN Tagging
- IPv6 Connection Type:
- Dual Stack: PPP, DHCPv6 Client, Static IPv6
- Tunnel Mode: TSPC, AICCU, 6rd, 6in4 Static Tunnel
- USB WAN:
- PPP (3G) / CDC driver (3G)
- Support IPv6 protocol: TSPC/AICCU
- Ethernet WAN:
- Dual WAN
- Load-Balance / Route Policy
- Outbound policy-based load-balance
- WAN Connection Failover
- Support IPv6 LAN
- Port-based / Tag-based VLAN
- Bind IP to MAC Address:
- Disable / Enable / Strict Bind
- IP Bind list: 1024 entries
- LAN Port Mirror
- Wired 802.1x
- Web Portal
- Support IP Pool Count more than 253 (up to 1022) for LAN1~3 subnet
- 8 x Multiple Subnet LAN
- DMZ Host: Port-redirection, Open Port, Port Triggering
- User-based / Rule-based Firewall
- Object-based Firewall：SPI (Stateful Packet Inspection) (Flow Track)
- DoS Prevention
- Time Schedule Control
- DNS Filter Enhancement
- User Management
- Firewall Wizard Mode and Advanced Mode
- Up to 50 VPN Tunnels (including 25 SSL VPN tunnels)
- VPN Wizard
- VPN Trunk with Backup / Load Balance
- Protocol: PPTP, IPsec, L2TP, L2TP over IPsec, GRE over IPSec
- Encryption: MPPE and hardware-based AES/DES/3DES
- Authentication: MD5, SHA-1
- IKE Authentication: Pre-shared Key and Digital Signature (X.509)
- LAN-to-LAN, Teleworker-to-LAN (remote user dial-in)
- DHCP over IPsec
- IPsec NAT-traversal (NAT-T)
- Dead Peer Detection (DPD)
- VPN Pass-through
- Bandwidth Management
- Guarantee bandwidth for VoIP
- Class-based bandwidth guarantee by user-defined traffic categories
- DiffServ Code Point classifying
- 4-level priority for each direction (Inbound/Outbound)
- Bandwidth borrowed
- Bndwidth/Session limitation
- Smart Bandwidth Limit
- config by ip range
- Layer-3 (TOS/DSCP) QoS
- Layer-2 (802.1p) QoS
- WAN budget
- Network Feature
- Hotspot Web Portal
- Packet Forwarding Acceleration
- DHCP client/relay/server
- DHCP Option: 1,3,6,51,53,54,58,59,60,61,66,125
- IGMP v2/v3
- LAN DNS/DNS Forwarding
- Dynamic DNS
- NTP Client
- Call Scheduling
- RADIUS/TACACS+ Client
- Internal RADIUS Server
- Active Directory/LDAP compatible (client)
- DNS Cache/Proxy and LAN DNS
- UPnP 50 sessions
- Wake on LAN
- Bonjour service
- Routing Protocol:
- Static Routing
- RIP v1/v2
- Triple-Play Application
- IGMP snooping/proxy
- 6 x Multiple Subnet LAN
- Support Smart Monitor (Up to 30 PCs)
- Central Device Management
- AP Management
- VPN Management
- Switch Management
- External Devices
- CSM (Content Security Management)
- APP Enforcement
- Support APPE Signature Upgrade by license
- URL Content Filter
- Access Control : URL Keyword Blocking (White/Black List)
- Web Feature : Java Applet, Cookies, Active X, Compressed, Executable, Multimedia File Blocking
- Web Content Filter (support Cyren and BPjM)
- DNS Filter
- APP Enforcement
- Printer Sharing
- File System
- Support FAT32 File System
- Support FTP Function for File Sharing
- 3.5G (HSDPA) and 4G (LTE) as WAN3/WAN4 by using USB dongle (can support Dual USB WAN)
- USB Device Status (disk/modem/printer/sensor)
- Support USB Temperature Sensor
- Support file sharing (DrayTek’s own SMB protocol stack)
- Network Management
- Web-based User Interface (HTTP/HTTPS)
- CLI (Command Line Interface, Telnet/SSH)
- Administration Access Control
- Configuration Backup/Restore
- Built-in Diagnostic Function
- Firmware Upgrade via TFTP/HTTP/TR-069
- Logging via Syslog
- SNMP v2/v3
- Support SMS/E-mail Alert
- Management Session Time Out
- Two-level Management (Admin/User Mode)
- External device detection (master mode)
- Support Multiple-Firmware Upgrade Utility (MFUU)
- Wireless AP (for n/ac/Vac model)
- 2.4 GHz (for n model)
- 2.4 + 5 GHz (for ac/Vac model)
- Wireless Client List
- Wireless LAN Isolation
- 64/128-bit WEP
- Hidden SSID
- MAC Address Access Control
- Access Point Discovery
- WDS (Wireless Distribution System)
- 802.1x Authentication
- Multiple SSID
- Wireless Rate-control
- SSID VLAN Grouping with LAN Port (Port-based VLAN)
The Vigor2926 supports up to 8 LAN IP subnets, an IP Routed subnet and a DMZ port.
The 8 LAN IP subnets can be assigned to 16 VLANS allowing the creation of logical workgroups to provide additional security and traffic management within an organisation.
For example, within a building each tenant or workgroup can be assigned their own IP network. In addition, workgroups can also be located in different physical locations or floors within a building. For example, a Sales Department may be located on the 1st floor of a building, but some of the sales people are located on the second floor and still be part of the sales VLAN.
The IEEE 802.1q VLAN trunk feature means that only a single LAN cable connection is required between the router and the VigorSwitch, create a number of VLANs for different departments.
The VLAN Tag Priority setting can be used to prioritise traffic for certain VLANS or workgroups.
Multi-site business deployment
Increase remote access security to your office by combining both VPN and Firewall features in the Vigor2926.
The Vigor2926 supports up to 50 simultaneous VPN tunnels (such as IPSec/PPTP/L2TP/SSL protocols) for secure data exchange and communication. In addition, 25 SSL VPN tunnels are available for teleworkers to access the office LAN. Teleworkers can be authenticated directly with your LDAP server if preferred. The SSL technology is same as the encryption used for secure web sites such as online banking.
Security is enhanced by utilising firewall features such as web content and URL filtering in addition to restricting access to P2P traffic and Instant Messaging applications.
The Vigor2926 series is equipped with two Gigabit Ethernet ports and two USB WAN ports for WAN load-balancing and backup. This allows backup VPN tunnels to be created to branch office networks to ensure maximum VPN connectivity uptime. In addition, the VPN Trunking feature can be used to set up dual VPN tunnel links to branch office networks to increase bandwidth and provide redundancy and backup to prevent downtime due to one of the WAN connections failing.
The comprehensive firewall in the Vigor2926 router protects your network by using Stateful Packet Inspection (SPI) and extensive firewall filtering rules. Stateful Packet Inspection monitors incoming and outgoing data packets at layer 3. It maintains a table of open connections and inspects the payload to determine its data will be passed or blocked by matching known active legitimate connections.
The DoS (Denial of Service) Defense also protects your network against a number of attacks from the Internet.
The URL and Web content filters are also available to restrict access to certain websites (such as Social Networking, Gambling, etc.) for some users and it can be enforced according to a time schedule.
The DMZ Host feature allows you to place a server in the DMZ so it can be access from the Internet but not exposing your main network to the Internet.
The optional USB thermometer can be attached to the Vigor2926 to provide logging of the ambient temperature in the server room. Upper and lower temperature thresholds can be set and when the temperature exceeds these thresholds and alarm is generated. This alarm can be sent to the network administrator via email or SMS to alert them of the environmental issue.
802.11ac Wave 2 (for ac/Vac model)
802.11ac Wave 2 can simultaneously stream to multiple users to maximize bandwidth utilization.
Vigor2926ac routers now operate 802.11ac Wave 2 Wi-Fi with support for MU-MIMO, TX Beam Forming, 1733Mb/s Link Rate and up to 4 spatial streams. This allows up to 4 wireless clients such as laptops or smartphones to have simultaneous access to a Wi-Fi channel. The result is an increased performance of the Wi-Fi network.
Central Management – AP / Switch / VPN Management
The central management features allow the network administrator to monitor and configure Vigor devices including VigorAPs, Vigor Switches, and even Vigor Routers from a central management console built into the Vigor2926 series router. Maintenance tasks such as firmware upgrades, configuration backup and restoration as well as and monitoring be done from a single portal.
Three options are available in Central Management. These are:
- VPN Management
- AP Management
- Switch Management
VPN management supports 8 external CPE devices and allows the creation and management of IPSec, PPTP or SSL VPN tunnels from the central Vigor2926 router to the remote routers.
The AP Management feature allows the monitoring and auto-configuration of up to 20 DrayTek Access Points connected to the Vigor2926 LAN. Automatic Provisioning can be triggered when a new Access point is connected to the LAN. Other features include client or traffic history of the AP and configuration of load balancing rules for the Access Points.
Switch Management allows you to manage up to 10 VigorSwitches. It simplifies the task of configuring VLANS in attached VigorSwitches matching the router’s VLAN settings. It also displays the switch status as well as the network topology through the switch hierarchy feature.
Support Smart Monitor up to 30 PC Users
Smart Monitor is a free network traffic analyser available from DrayTek. It can be used with the Vigor2926 router to monitor traffic from 30 PCs on your network and produce reports to assist trouble shooting or network usage. Reports range from listing the top 10 users and classifying network traffic into 15 categories such as IM monitor, HTTP traffic, P2P traffic etc.
Flexible Installation with Rackmount
The Vigor2926 series router can be rack mounted into a standard 19’ rack or cabinet. The 1RU rack mounting kit allows the front panel of the router to be easily accessible as well as keeping it secure in the communications rack.
Please click the link. http://eu.draytek.com:12926/