Vigor 3912S VPN Enterprise Router with 256GB SSD for hosting docker Linux applications
Multi-WAN Router with over 12Gbps NAT Throughput
Suricata-based Intrusion Detection System – New!
8x WAN/LAN Switchable Ports & 4x fixed Ethernet LAN Ports
256GB SSD and 8GB DDR4 for hosting Docker Linux applications – New!
2x 10GbE SFP+ and 2x 2.5GbE for WAN/LAN
Additional SSD Storage for Docker Linux Applications
Make use of the additional disk space available on Vigor 3912S routers, where some applications such as Ubuntu, Suricata, and VigorConnect are pre-installed.
The Docker container system is also present, coupled with Portainer graphic interface that makes installation of additional Docker applications quick and easy. Additional functionality such as a web server and many other containers can be run simultaneously on this quad-core router.
Suricata Intrusion Detection System
The well-known open-source IDS system by Suricata can help with network safety. With over 60k rules, including 6k+ CVE definitions, this platform can alert the network administrator about threats, including malware, network intrusions, DoS attacks, and data breaches.
Simply, activate the Suricata protection application from the WUI of the router with the matter of a few clicks to enable advanced security options.
Powerful 12Gb Capable Internet Gateway
The Vigor 3912S is specially designed to cope with the throughput demands of large networks and as a VPN concentrator, has suitable processing power to meet the demands of hundreds of active VPN tunnels.
Firewall and NAT throughput of the router can reach over 12 Gigabits per second when connected via multiple interfaces including the 10 Gigabit SFP+ ports which help to spread over multiple Internet connections with Load Balancing.
The Vigor 3912S accelerates LAN-to-LAN IPsec VPN throughput up to 5 Gigabits per second, with up to 500 active VPN tunnels it can provide enough throughput to each tunnel, without becoming a bottleneck to the user experience.
The SSL VPN capabilities of the Vigor 3912 series are also increased, with over 3 Gigabit per second of total SSL VPN throughput, suitable to cater to the bandwidth requirements of up to 200 active SSL VPN users.
High-Performance VPN Concentrator
A feature central to DrayTek routers is its VPN (Virtual Private Networking) capabilities. A VPN enables you to link remote offices and branch offices back to HQ, or home-based/mobile teleworkers back to your office.
Once connected, they have access to your office/remote resources through a secure encrypted tunnel allowing remote desktop, file sharing and seamless access to other resources and devices.
The Vigor 3912S allows you to have up to 500 simultaneous VPN tunnels to remote offices or teleworkers, with up to 5Gbps of VPN throughput.
It supports all common industry standard protocols, encryption types and authentication methods (see specification tab for full support list). Teleworkers can authenticate directly with your LDAP server if preferred.
The Vigor 3912S supports VPN trunking; this allows you to create tunnels down multiple WAN connections to a remote site in order to increase bandwidth. VPN trunking also provides failover (backup) of your VPN route down a secondary WAN connection.
You can learn more about DrayTek VPN here. Teleworkers can also use 2FA (Two factor authentication) such as Mobile One-Time Passwords (MOTP) or Time-based One-time Password (TOTP).
Load Balancing - Ultimate Resiliency & Reliability
The Vigor 3912S features Multi-WAN connectivity with up to 8 WAN interfaces:
4 RJ-45 1GbE ports
2 RJ-45 2.5GBase-T (backwards compatible with 1GbE) ports
2 SFP+ module slots
The Ethernet and 2.5GBase-T ports can be connected to:
Leased Lines
DSL modems (e.g. Vigor 166) for ADSL 2+, VDSL and G.Fast connectivity
4G and LTE through the Vigor 2620Ln in LTE bridge mode
Cable modems
Any other Ethernet-based Internet feed
The SFP+ ports, when fitted with an optional SFP+ or SFP module, can be linked to 1GbE or 10GbE uplinks, through Fibre or any other link type with a suitable transceiver.
Fibre is of particular use for longer distance deliveries, beyond the range of standard Ethernet, or where copper connections cannot be used.
These multiple WAN interfaces can be used either for WAN-Backup or Load Balancing with Policy-based Routing giving you full control of where and how traffic is routed. Load-balancing or failover supports IPv4 only currently (not IPv6).
WAN-Backup provides contingency (redundancy) in case of your primary Internet connection or ISP suffering temporary outage. Internet Traffic will be temporarily routed via the secondary Internet access. When normal services are restored to your primary Internet line, all traffic is switched back to that.
Flexible WAN & LAN Ports
The Vigor 3912S features 12 physical ports in total, with 8 ports that can be switched between LAN and WAN usage to fit your network requirements, with many combinations being possible, including:
8 WAN interfaces with 4 LAN ports
1 WAN interface with 11 LAN ports
High Availability
For even greater resilience, the Vigor 3912S provides High Availability (HA), with both a primary and secondary router able to provide connectivity to your network and subnets.
In the event of the primary unit failing, the secondary unit will take its place on the network, automatically switching over to resume Internet, routing and VPN connectivity with no intervention required. This can remove the possibility of a single point of failure within your routers.
CERTIFICATION
|
PSTI certified |
Yes |
DESIGN
|
Rack mounting |
Yes |
LED indicators |
Power, Status, USB |
Product colour |
Black |
Rack capacity |
1U |
Housing material |
Metal |
On/off switch |
Yes |
ENERGY MANAGEMENT
|
Power consumption (typical) |
35 W |
Power source type |
DC |
Power consumption (max) |
35 W |
FEATURES
|
Internal storage capacity |
256 GB |
Storage media |
SSD |
MANAGEMENT FEATURES
|
Wake-on-LAN ready |
Yes |
Quality of Service (QoS) support |
Yes |
Web-based management |
Yes |
Reset button |
Yes |
Firmware upgradeable |
Yes |
Universal Plug and Play (UPnP) |
Yes |
Traffic shaping |
Yes |
Interface-based traffic policing |
Yes |
Priority mapping |
Yes |
NETWORKING
|
Full duplex |
Yes |
Cabling technology |
10/100/1000Base-T(X) |
VLAN support |
Yes |
Ethernet interface type |
2.5 Gigabit Ethernet, Gigabit Ethernet |
Static route |
Yes |
Throughput |
12.5 Gbit/s |
Policy-based routing |
Yes |
Differentiated services (DiffServ) supported |
Yes |
OPERATIONAL CONDITIONS
|
Storage temperature (T-T) |
-10 - 55 °C |
Operating temperature (T-T) |
0 - 45 °C |
Operating temperature range (T-T) |
Yes |
PACKAGING CONTENT
|
Cables included |
AC, LAN (RJ-45) |
Quick start guide |
Yes |
PACKAGING DATA
|
Cables included |
AC, LAN (RJ-45) |
Quick start guide |
Yes |
Package type |
Box |
PORTS & INTERFACES
|
Ethernet LAN (RJ-45) ports |
10 |
Gigabit Ethernet (copper) ports quantity |
8 |
USB version |
3.0 |
USB ports quantity |
2 |
SFP+ module slots quantity |
2 |
Number of console ports |
1 |
WAN/Ethernet LAN ports quantity |
6 |
PROTOCOLS
|
Management protocols |
http, https, ssh, telnet, tr-069 |
Routing protocols |
BGP, OSPF |
DHCP client |
Yes |
DHCP server |
Yes |
IPv4 & IPv6 features |
Dual stack IPv4/IPv6 |
SECURITY
|
Security algorithms |
3DES, DES, EAP, HTTPS, MD5, SHA-1, SHA-256 |
VPN support |
IPsec
IKEv1
IKEv2
IKEv2 EAP
IPsec-XAuth
DrayTek SSL VPN
OpenVPN
WireGuard
GRE over IPsec
PPTP
L2TP
L2TP over IPsec |
VPN tunnels quantity |
500 |
MAC address filtering |
Yes |
Access Control List (ACL) |
Yes |
System event log |
Yes |
IP address filtering |
Yes |
DoS attack prevention |
Yes |
Network address translation (NAT) |
Yes |
Firewall |
Yes |
URL filtering |
Yes |
Guest access |
Yes |
ARP attack prevention |
Yes |
ICMP attack prevention |
Yes |
WAN CONNECTION
|
Ethernet WAN |
Yes |
SFP WAN |
Yes |
WEIGHT & DIMENSIONS
|
Weight |
3.82 kg |
Height |
45 mm |
Width |
443 mm |
Depth |
285 mm |