Descrição
Quad-Core Powerful Enterprise Gateway
Vigor3912 Series is designed for bandwidth-demanding networks, featuring a 2GHz Quad-Core CPU for fast connection speed, even with multiple connected devices. The router has 8 WAN interface, including 2x 10G SFP+ for fiber connectivity, 2x 2.5G Ethernet, and 4x 1G Ethernet, providing ultra-fast NAT throughput. Port1 to port8 are configurable independently for WAN or LAN to offer flexibility and optimize the router performance.
Vigor3912 Series can serve as a VPN server to establish LAN-to-LAN or remote dial-in VPN connections. It includes SMB-friendly features like VPN 2FA authentication and VPN from LAN, ensuring a more secure and efficient VPN network.
Vigor3912S comes equipped with 256GB SSD storage inside, supporting Linux applications with Docker. Suricata and VigorConnect are supported. This feature allows users to effortlessly install and run powerful softwares directly on the Vigor3912S, eliminating the need for additional computer to installing servers.
Up to 8 WANs
including 10G SFP+ and 2.5G Ethernet
Quad-Core CPU
provides 15.6 Gbps NAT throughput*
500 VPN
provides 5.7 Gbps IPsec throughput*
500 Hosts
Reserve 2048 entries for Bind-IP-to-MAC
*bi-directional(TX+RX) performance

12x USB 3.0
2Reset Button
3RJ-45 Console Port
42x 10G/2.5G/1G SFP+ Port*
52x 2.5G/1G/100M/10M Base-T, RJ-45*
64x 1G/100M/10M Base-T, RJ-45*
74x 1G/100M/10M Base-T, RJ-45
*WAN/LAN Switchable
High Performance 10G Router*
Quad-Core CPU
Provides 15.6 Gbps NAT throughput (bi-directional)

*bi-directional(TX+RX) performance

Key Features
Quad-Core Processor
Offer excellent performance for bandwidth-demanding enterprise networks.
10G SFP+
Provides 2x 10G-capable fiber SFP ports for WAN or LAN connection.
Load Balancing
Maximize throughput and reliability by using multiple Internet connections. Learn more
VPN (Virtual Private Network)
Build a secure and private tunnel from the LAN of Vigor3912 Series to the remote offices and teleworkers over the Internet. Learn more
SSL VPN
The VPN works through firewalls providing secure remote access to any network environment. Learn more

VPN 2FA Auth for AD/LDAP
Enhance the security for remote VPN connections and eliminate the cost for an official authentication system. Learn more
VPN Matcher
Helps routers behind NAT to find each other and establish a LAN-to-LAN VPN. Learn more
PPPoE Server
Use Point-to-Point connection on LAN to keep track of individual user's traffic. Setup Guide
Hotspot Web Portal
Market your business and communicate with the guests while offering hospitality WLAN. Learn more
Bandwidth Management
Prevent one device using all the bandwidth by bandwidth limit policy, session limit policy, and QoS settings.
Firewall & Content Filter
Filter web pages by URL keyword or web category to block access to insecure or inappropriate contents.
DrayDDNS
The free DDNS service for you to access the router by a fixed hostname of your choice. Learn more
Central AP Management
Use the Vigor3912 Series router as a wireless controller to maintain and monitor the VigorAPs. Learn more
Central Switch Management
Set up VLAN easily from the router and get a centralized hierarchy view of the switches. Learn more
Flexible WAN & LAN Port
12 Ports in total
8 Ports can be switched to LAN or WAN. So it can have up to:
- 8 WAN interfaces with 4 LAN Ports or
- 1 WAN interface with 11 LAN Ports


Fiber to the Building/Home
An ideal choice to work with tier 2/3 ISPs and co-working spaces
High Performance with 10G SFP+
For both NAT and routing network, and for both 10G-WAN and 10G-LAN, Vigor3912 Series is ready to deliver high throughput to your business.
Layer 3 Routing with BGP and OSPF
With the most popular Exterior and Interior Gateway Protocols, Vigor3912 Series is ideal for ISP deployment.
Layer 2 Security with PPPoE Server and VLAN
With 200 PPPoE user accounts and 100 VLAN/LAN subnets, Vigor3912 Series provides up to 15.6 Gbps throughput(bi-directional), and makes subletting network infrastructure secure and easy.
Advanced VPN Features
VPN 2FA on AD/LDAP Server
With new Two-Factor authentication, you can strength the security of VPN connections and eliminates the expense of SMS messages or license fees in a cost-effective way.

Packet Capture Tool for VPN tunnel
By either mirroring all packets to designated LAN port and now to VPN connection no matter LAN to LAN profile or remote Dial-in users, and even downloading .pcap file via WUI remotely, spotting an issue is easier than ever.

VPN from LAN (Zero Trust)
Never trust, always verify. VPN from LAN works Zero Trust out. It provides a better security level to your network, which protects vital servers from potential threats caused by other LAN devices. The servers can only be accessed by VPN, even if the devices are on the LAN network.

VPN User Isolation
Isolating remote dial-in accounts to protect VPN users from each others. They can only access company’s servers but not allowed to enter each other’s devices. This helps prevent unauthorized access to sensitive data and protect network from malware or other intrusions.

VPN 2FA on AD/LDAP Server
With new Two-Factor authentication, you can strength the security of VPN connections and eliminates the expense of SMS messages or license fees in a cost-effective way.

Packet Capture Tool for VPN tunnel
By either mirroring all packets to designated LAN port and now to VPN connection no matter LAN to LAN profile or remote Dial-in users, and even downloading .pcap file via WUI remotely, spotting an issue is easier than ever.

VPN from LAN (Zero Trust)
Never trust, always verify. VPN from LAN works Zero Trust out. It provides a better security level to your network, which protects vital servers from potential threats caused by other LAN devices. The servers can only be accessed by VPN, even if the devices are on the LAN network.

VPN User Isolation
Isolating remote dial-in accounts to protect VPN users from each others. They can only access company’s servers but not allowed to enter each other’s devices. This helps prevent unauthorized access to sensitive data and protect network from malware or other intrusions.

Server Load Balancing
Hosting multiple servers to share the traffic load for the same service is common. It can avoid excessive load on a single server by distributing the load, optimizing resource usage, and preventing a single server failure.
With Server Load Balance, when massive connections enter the router, the router will distribute the inbound NAT sessions among the servers with the configured load balance weight.

Port Knocking
Configuring NAT Port Redirection rules is the typical way to allow the internal servers to be accessible from the Internet. However, once the port opens, it is exposed to the Internet and can be scanned by the malware.
Port knocking is a technology that can add an extra layer of protection to the internal servers. Its basic idea is that only open ports are at risk of being attacked, so it allows all ports to be closed at the beginning. Do not open them, and then set a password based on the port combination. Only those who know the password can open the ports and connect.

Linux Applications 3912S Only
- VigorConnect
- Suricata
- Applications on Ubuntu

Linux Application VigorConnect
*S Model Only
The Vigor3912S router supports Docker, enabling the installation and operation of the VigorConnect server directly on the device. This capability simplifies network management by allowing the VigorConnect server to monitor DrayTek devices without requiring an additional computer. The installation process is straightforward and can be completed through the router's web user interface (WUI) with just a few clicks. This integration provides a convenient and efficient solution for network administrators to oversee and manage their network infrastructure.

Linux Application Suricata
*S Model Only
A famous open-source threat detection software, empowering it to detect and prevent a wide range of network threats effectively.
Suricata is an open-source threat detection system. It supports more than 60,000 rules, including 6,000+ CVE rules, and can detect and prevent a wide range of network threats, such as malware, network intrusions, denial-of-service attacks, and data breaches.
Vigor3912S supports Linux Applications Suricata, allowing this powerful software to be installed and used to protect the network.

image source : https://suricata.io/
Suricata Features
*S Model Only
Notifications by Smart Action
When Suricata detects threats, the Vigor3912S supports notifying the admin by Smart Action using the following methods:
- Web Notification: Notifications are displayed directly on the router's web user interface , allowing admins to see alerts when they log in.
- Telegram by Smart Action: Notifications can be sent to a designated Telegram account, ensuring that admins receive alerts in real-time on their mobile devices.
These methods ensure that admins are promptly informed about potential threats, enabling quicker responses to network security issues.


Auto Blocking by Smart Action
Suricata detects network threats, and Smart Action can perform advanced filtering and blocking actions. Admins define specific keywords related to network threats in the Smart Action Profile. When Suricata detects a threat that matches one of the predefined keywords, the Vigor3912S will automatically block the associated IP address.
This feature allows for proactive and automated threat mitigation, enhancing the security of the network without requiring constant manual intervention.

Statistical Graph
Suricata Statistical Graph allow users to clearly see which threat occurs the most frequently. When the mouse hovers over the point representing the most frequent threat, a small menu pops up, displaying the number of occurrences of that threat. Additionally, these points are clickable. After clicking, the user is taken to another detailed view (illustrated in the second image) that provides more comprehensive information.

Notifications by Smart Action
When Suricata detects threats, the Vigor3912S supports notifying the admin by Smart Action using the following methods:
- Web Notification: Notifications are displayed directly on the router's web user interface , allowing admins to see alerts when they log in.
- Telegram by Smart Action: Notifications can be sent to a designated Telegram account, ensuring that admins receive alerts in real-time on their mobile devices.
These methods ensure that admins are promptly informed about potential threats, enabling quicker responses to network security issues.


Auto Blocking by Smart Action
Suricata detects network threats, and Smart Action can perform advanced filtering and blocking actions. Admins define specific keywords related to network threats in the Smart Action Profile. When Suricata detects a threat that matches one of the predefined keywords, the Vigor3912S will automatically block the associated IP address.
This feature allows for proactive and automated threat mitigation, enhancing the security of the network without requiring constant manual intervention.

Statistical Graph
Suricata Statistical Graph allow users to clearly see which threat occurs the most frequently. When the mouse hovers over the point representing the most frequent threat, a small menu pops up, displaying the number of occurrences of that threat. Additionally, these points are clickable. After clicking, the user is taken to another detailed view (illustrated in the second image) that provides more comprehensive information.

Notifications by Smart Action
When Suricata detects threats, the Vigor3912S supports notifying the admin by Smart Action using the following methods:
- Web Notification: Notifications are displayed directly on the router's web user interface , allowing admins to see alerts when they log in.
- Telegram by Smart Action: Notifications can be sent to a designated Telegram account, ensuring that admins receive alerts in real-time on their mobile devices.
These methods ensure that admins are promptly informed about potential threats, enabling quicker responses to network security issues.


All-in-One Management
Vigor Router provides a management platform for your Vigor Devices on the LAN

Auto-Discovery
Automatically discover LAN subnets and add detected VigorSwitch/AP into managed list.
Provisioning
Most-frequent used settings can be pre-defined on the Vigor Router, and provision to the managed VigorSwitch/AP.
Monitoring
Vigor Router provides a centralized view of managing devices, you may always check if the managed Vigor Switch/AP is online.
System Maintenance
Support basic maintenance remotely via Vigor Router. Such as remote reboot, factory reset, configuration backup/restore, etc.
Management Solution
All-in-One Management

Vigor Router SWM
Auto-Discovery, Provisioning, Monitoring, Centralized Hierarchy View, Reboot PoE Devices Remotely, Quick VLAN Configuration
Vigor Router APM
Auto-Discovery, Provisioning, Monitoring, Centralized View, Alarm, Reboot VigorAP Remotely, Wi-Fi Client Load Balancing