DrayTek DV3912S Firewall VPN Router, 8x WAN Ports, 2 x 10GbE SFP+, 2x 2.5GbE, 4x GbE, Suricata IDS, 256GB SSD

  • Up to 8 WANs - including 10G SFP+ and 2.5G Ethernet
  • Quad-Core CPU - provides 15.6 Gbps NAT throughput
  • 500 x VPN tunnels - provides 5.7 Gbps IPsec throughput
  • 500 Hosts - Reserve 2048 entries for Bind-IP-to-MAC
  • 1 million NAT sessions - Recommended for a network of up to 500+ devices

Please feel free to contact us about this item, and we will recommend an IT Sales and Service Provider in your area.


Resellers: for pricing and to place orders.

This item is not normally held in stock. We’ll order it in on request. Please contact us for estimated delivery time
In stock email will be sent.
Instock notification already exists.
Order SKU: Supplier Code:

DrayTek Vigor3912S 10G multi-WAN VPN security router

The DrayTek Vigor3912S is a high-performance enterprise VPN router combining flexible multi-WAN connectivity, 10Gb SFP+ interfaces, advanced traffic management and integrated threat detection. With a 2GHz quad-core processor, 8GB DDR4 memory and a 256GB SSD for Linux applications, it is designed for larger organisations, multi-site networks, service providers and other demanding deployments.

Flexible 10G, 2.5G and Gigabit WAN connectivity

Eight of the Vigor3912S’s twelve network interfaces can be configured for either WAN or LAN operation. This allows the router to support anything from a single high-speed internet connection with extensive LAN connectivity through to an eight-WAN deployment with four dedicated LAN ports.

Configurable interfaces include:

  • Two 10G/2.5G/1G SFP+ slots
  • Two 2.5G/1G/100M/10M RJ-45 ports
  • Four Gigabit Ethernet RJ-45 ports

Four additional Gigabit Ethernet ports are dedicated to LAN connectivity.

Multiple internet services can be combined using session-based load balancing, while WAN failover helps maintain connectivity if a primary service becomes unavailable. This flexibility makes the Vigor3912S suitable for organisations using a combination of fibre, Ethernet, fixed wireless and other externally terminated broadband services.

High-performance routing for bandwidth-intensive networks

A 2GHz quad-core processor and hardware acceleration provide up to 15.6Gbps of aggregate bidirectional NAT throughput under DrayTek test conditions. The router supports up to one million concurrent NAT sessions, providing the capacity required for larger user populations and networks with substantial numbers of connected devices.

Two 10Gb SFP+ slots enable high-speed WAN or LAN connections, while the 2.5GbE interfaces provide practical multi-gigabit connectivity for internet services, servers, core switches and other network infrastructure.

Actual throughput will depend on network conditions, traffic patterns, configuration and the security or management services in use.

Integrated Suricata threat detection

Unlike the standard Vigor3912, the Vigor3912S includes a 256GB SSD with Ubuntu and Docker support. Suricata is pre-installed to provide network-based intrusion detection using an extensive library of threat-detection rules.

Suricata analyses traffic passing through the router and records suspicious activity such as malware communication, intrusion attempts, denial-of-service activity and other potentially malicious behaviour. Administrators can review threat details and use Smart Action rules to trigger notifications or automatically block associated IP addresses.

This provides an additional security layer at the network edge without requiring a separate server to host the threat-detection application.

Automated responses with Smart Action

Smart Action allows network events to trigger predefined responses automatically. Up to 64 event-to-action profiles can be configured, helping administrators react to security events, system conditions and scheduled requirements without continuous manual intervention.

Depending on the event, actions can include:

  • Blocking an IP address
  • Sending email, web or Telegram notifications
  • Calling a webhook
  • Running a command-line instruction
  • Disabling or removing a VPN profile
  • Applying scheduled access restrictions
  • Waking a networked computer

On the Vigor3912S, Smart Action can also respond to keywords recorded in Suricata, syslog and console logs.

Host VigorConnect directly on the router

The integrated Linux environment can run VigorConnect as a Docker application. This allows the Vigor3912S to host DrayTek’s network management software without requiring a separate computer or server.

VigorConnect provides centralised discovery, monitoring and management of supported DrayTek network devices. This capability is particularly useful for organisations wanting local network management while reducing the number of dedicated appliances and servers required onsite.

Enterprise VPN capacity for branches and remote users

The Vigor3912S supports up to 500 concurrent VPN tunnels, including up to 200 concurrent SSL VPN or OpenVPN connections. Supported technologies include IPsec, IKEv2, SSL VPN, OpenVPN, WireGuard, L2TP over IPsec and GRE.

Maximum published VPN performance includes:

  • 5.7Gbps bidirectional IPsec throughput using AES-256
  • 4.3Gbps bidirectional SSL VPN throughput
  • 1.08Gbps bidirectional WireGuard throughput

VPN load balancing, failover and backup options can improve resilience for site-to-site deployments. The router also supports VPN user isolation, VPN packet capture, VPN Matcher and two-factor authentication integrated with AD or LDAP services.

These figures are maximum results from DrayTek testing under optimal conditions; real-world VPN performance varies with configuration, protocol, encryption, packet size and traffic conditions.

Network segmentation, routing and traffic control

Support for up to 100 VLANs allows administrators to separate staff, servers, guests, voice systems, IoT equipment and other network resources. VLAN tagging, multiple IP subnets, inter-LAN routing and policy-based firewall rules provide detailed control over how each segment communicates.

BGP and OSPF dynamic routing support make the Vigor3912S suitable for more advanced enterprise and service-provider environments. An integrated PPPoE server supports up to 200 accounts, while inbound server load balancing can distribute connections across multiple internal servers.

Bandwidth limits, session limits and Quality of Service policies help protect important applications from congestion and ensure that voice, video and other business-critical traffic receive appropriate priority.

Business firewall and content security controls

The object-based stateful packet inspection firewall enables administrators to create detailed security policies using reusable network, service and application objects.

Security capabilities include:

  • IP-based firewall policies
  • Application and URL keyword filtering
  • DNS keyword filtering
  • Denial-of-service defence
  • Spoofing defence
  • Port knocking
  • IP and URL reputation services
  • Brute-force protection
  • IPv4 and IPv6 support

Web-category filtering and cloud-based reputation services may require an additional subscription.

High availability for critical network environments

The Vigor3912S supports router high availability, allowing a secondary compatible router to take over if the primary unit fails. Combined with multi-WAN load balancing, internet failover and VPN redundancy, this helps reduce downtime for organisations that depend on continuous connectivity.

The rack-mountable 1U design is suited to installation in a communications cabinet, server room or data centre.

Central management of DrayTek networks

The router can centrally manage up to 50 compatible DrayTek Vigor access points and 30 VigorSwitches. Administrators can discover devices, provision common settings, monitor operational status and perform selected maintenance tasks from the router interface.

For larger or distributed networks, the Vigor3912S also supports VigorACS 3 for remote provisioning, monitoring and SD-WAN management. VigorACS 3 is a separate management platform and may require additional licensing or hosting.

Vigor3912S compared with the Vigor3912

Both models offer the same configurable 10G, 2.5G and Gigabit interfaces, routing performance, VPN capacity and enterprise networking features.

The Vigor3912S adds:

  • 8GB DDR4 memory
  • Integrated 256GB SSD
  • Ubuntu-based Linux application environment
  • Docker application support
  • Pre-installed Suricata threat detection
  • Ability to host VigorConnect locally

The standard Vigor3912 is appropriate where high-performance routing and VPN functionality are required without the integrated Linux applications. The Vigor3912S is the stronger choice when local threat detection, automated security responses or onboard VigorConnect hosting are important.

Technical specifications

Specification

Details

Product model

DrayTek Vigor3912S

Product type

Enterprise multi-WAN VPN security router

Processor

2GHz quad-core processor

Memory

8GB DDR4

Internal storage

256GB SSD

Application environment

Ubuntu with Docker application support

Included applications

Suricata and VigorConnect support

Configurable SFP+ interfaces

2 × 10G/2.5G/1G SFP+ WAN/LAN slots

Configurable multi-gigabit interfaces

2 × 2.5G/1G/100M/10M RJ-45 WAN/LAN ports

Configurable Gigabit interfaces

4 × 1G/100M/10M RJ-45 WAN/LAN ports

Fixed LAN interfaces

4 × 1G/100M/10M RJ-45 ports

Maximum WAN interfaces

Up to 8

Console interface

1 × RJ-45 console port

USB interfaces

2 × USB 3.0

Maximum NAT throughput

15.6Gbps aggregate bidirectional throughput

Maximum NAT sessions

1,000,000

Maximum concurrent VPN tunnels

500

Maximum SSL VPN/OpenVPN tunnels

200

IPsec VPN throughput

Up to 3.3Gbps single-directional or 5.7Gbps bidirectional with AES-256

SSL VPN throughput

Up to 3.3Gbps single-directional or 4.3Gbps bidirectional

WireGuard throughput

Up to 900Mbps single-directional or 1.08Gbps bidirectional

VPN protocols

IPsec, IKEv2, SSL VPN, OpenVPN, WireGuard, PPTP, L2TP, L2TP over IPsec, GRE and IPsec-XAuth

VPN authentication

Local, RADIUS, LDAP, TACACS+, mOTP and TOTP

WAN resilience

Load balancing, failover and backup

High availability

Supported

VLAN capacity

Up to 100 VLANs

PPPoE server

Up to 200 user accounts

Dynamic routing

BGP and OSPF

Firewall

Object-based stateful packet inspection firewall

Threat detection

Suricata IDS with Smart Action integration

Smart Action capacity

Up to 64 event-to-action profiles

Content filtering

Application, URL keyword, DNS keyword, web-feature and web-category filtering; some services require a subscription

Central AP management

Up to 50 compatible DrayTek Vigor access points

Central switch management

Up to 30 compatible DrayTek VigorSwitches

Remote management

VigorACS 3 support

Management protocols

HTTP, HTTPS, Telnet, SSH v2, FTP, TR-069, SNMP v1/v2c/v3 and syslog

Power input

100–240V AC, 0.6A

Maximum power consumption

35W

Dimensions

443 × 285 × 45mm

Weight

3.35kg

Operating temperature

0°C to 45°C

Operating humidity

10% to 90%, non-condensing

Installation

1U rack-mountable