DrayTek DV3912 Firewall VPN Router, 8x WAN Ports, 2 x 10GbE SFP+, 2x 2.5GbE, 4x GbE

- 2 x 10G/2.5G/1G SFP+ configurable WAN/LAN ports
- Perfect for Hyperfibre
8x WAN broadband router with Quad-Core CPU and 8G DDR4 memory, 2 x 10Gb SFP+ Fibre WAN/LAN slots, 2 x 2.5GbE WAN/LAN ports, and 4 x fixed GbE LAN ports; support SPI Firewall, 500 x VPN tunnels including 200 x SSL-VPN tunnels.
- Memory: 8GB DDR4 (Vigor3912)
- 2 x 10G/2.5G/1G SFP+ Fibre configurable WAN/LAN Slots
- 2 x 2.5G/1G/100M/10M Ethernet configurable WAN/LAN ports
- 4 x 1G/100M/10M Ethernet Configurable WAN/LAN ports
- 4 x 1G/100M/10M Ethernet LAN ports with 1 million NAT sessions
- Multi-WAN Load Balancing & Failover
- Quad-Core CPU with 15.6 Gbps NAT throughput (bi-directional(TX+RX) performance)
- 500 x VPN tunnels (including 200 x OpenVPN/ SSL-VPN tunnels) with most security protocols
- Fast VPN throughput, VPN Load Balancing, Failover, and backup for site-to-site applications
- 100 x VLANs for secure and efficient workgroup management
- 1 x RJ-45 console port
- 2 x USB 3.0 ports for external storage (one USB flash drive is supported at any one time)
- High-Availability (with CARP) ensuring 24/7 system uptime
- Object-oriented SPI Firewall
- Multi-subnet WAN/LAN through 802.1Q
- IPv6 & IPv4
- Bandwidth management
- Supports VigorACS 3 Central Management Software for remote management
- SD WAN capability when used with VigorACS 3
- Supports Central AP Management (up to 50 Vigor Access Points) Learn more
- Supports Central Switch Management (up to 30 Vigor Switches) Learn more
- Rack-mountable
The DrayTek Vigor3912 series routers are built for high performance, featuring powerful Quad-Core CPUs and 8GB of DDR4 memory. This robust hardware configuration results in excellent processing capabilities, with NAT throughput reaching 15.6 Gbps. Such speed allows the router to manage multiple applications and user demands effortlessly. This ensures smooth data transfers and minimal latency, which are vital for businesses that depend on real-time communication and cloud services.
Flexible WAN Connectivity
In an era where redundancy is crucial, the Vigor3912 series routers excel with their Octuple-WAN capability. Businesses can utilise up to eight different WAN connections, optimising bandwidth usage and ensuring continuous uptime. The multi-WAN load balancing feature enhances reliability. If one connection experiences downtime, traffic is automatically rerouted, thereby preventing disruptions in business operations.
Configurable WAN/LAN Ports
12 Ports in total
8 ports from a total of 12 ports, can be configured as either a LAN port or a WAN interface. For example, the following port options are achievable:
• 8 x WAN interfaces and 4 x LAN Ports or
• 1 x WAN interface and 11 LAN Ports
Robust Security Features
Security is a major concern for businesses of all sizes, and the Vigor3912 series addresses this with a range of advanced security features. That includes an object-oriented SPI firewall, which offers deep packet inspection and sophisticated filtering options. Additionally, the Vigor3912 series routers support up to 500 VPN tunnels, enabling secure remote access for employees while ensuring data integrity. The various security protocols available with these VPN tunnels further reinforce the Vigor3912 series as strong protectors of sensitive information. The built-in EasyVPN features simplify VPN setup, ensuring effortless and reliable connectivity
Stealth Security Protection with Port Knocking
DrayTek’s Port Knocking technology offers an advanced stealth security layer by keeping critical network services hidden from unauthorised users. Instead of exposing management ports or VPN services to the public internet, Port Knocking requires a predefined “knock” sequence before granting access, ensuring that only trusted users can locate and utilise these services.
By combining three essential functions, Port Knocking delivers exceptional protection against port scanning, brute-force attacks, and unauthorised access.
a) Port Redirection
• Hide service ports from the public internet.
• Redirect unauthorised requests to non-existent services, preventing detection.
b) Router Management Access
• Allow router management only through a secure internal server or after successful knocking.
• Eliminate exposure of the management interface to the open internet.
c) VPN Service Control (WAN Binding)
• Keep VPN services invisible and inaccessible until the correct knock sequence is received.
• Bind VPN availability to specific WAN interfaces and authorised IP addresses.
With Port Knocking enabled, the network operates in stealth mode, hidden from attackers, yet immediately accessible to authorised administrators and remote users. All targeted ports remain closed and undetectable. However, after the correct knock sequence, selected ports are temporarily opened for authorised access.
This makes it an ideal solution for organisations demanding high security without compromising accessibility.
Enhanced Scalability and Support for VLANs
Scalability is essential as businesses expand and develop. The Vigor3912 series supports up to 100 VLANs, allowing organisations to efficiently segment their network, preserve security, and easily manage workgroups. This feature is especially beneficial for businesses that require secure and effective collaboration across various departments or teams.
High Availability and Reliability
Uptime is vital for any business, and the Vigor3912 series is built with this in mind. With features like high availability through CARP (Common Address Redundancy Protocol), the router guarantees continuous operation, enabling businesses to stay productive without interruptions. This dependability is crucial for maintaining customer trust and productivity.
Future-Proofing with IPv6 Support
As the internet continues to evolve, adopting IPv6 is becoming increasingly important. The Vigor3912 series fully supports both IPv4 and IPv6, ensuring businesses are prepared for future technological developments. This feature offers peace of mind for companies aiming to future-proof their networks as more devices come online.
Smart Action
Smart Action allows predefined events to trigger predefined actions. Vigor users can pre-configure up to 64 event-to-action profiles. Actions, such as sending alerts, emails, removing a VPN profile, etc., can be programmed for events such as network conditions, occurrence counts, etc., associated with specified time and date.
Smart Action will act on these events:
• Send an alert email when CPU usage reaches 90%
• Disable VPN profile at a specified time
• Limit the access of a LAN server by Schedule
• Remove VPN User profile on a specified date
• Wake up the PC when the office hours start
• Log Keyword Match (syslog log, console log, Suricata log) for Vigor3912S only
Effortless and Secure VPN Access with EasyVPN
Setting up a VPN can often be complex, involving protocol selection, manual configurations, and troubleshooting, especially for non-technical users. While Vigor routers support advanced VPN protocols such as IPsec, WireGuard, and OpenVPN, traditional setup methods can be time-consuming and daunting.
EasyVPN simplifies this process by offering a streamlined, hassle-free solution for secure remote connectivity. With EasyVPN, users can quickly establish encrypted connections without the need to:
• Manually generate WireGuard keys
• Import OpenVPN configuration files
• Upload certificates
By automating these steps, EasyVPN delivers a fast, secure, and intuitive VPN experience—perfect for businesses and users who want robust protection without the technical complexity.