DrayTek DV3912S Firewall VPN Router, 8x WAN Ports, 2 x 10GbE SFP+, 2x 2.5GbE, 4x GbE, Suricata IDS, 256GB SSD
- Up to 8 WANs - including 10G SFP+ and 2.5G Ethernet
- Quad-Core CPU - provides 15.6 Gbps NAT throughput
- 500 x VPN tunnels - provides 5.7 Gbps IPsec throughput
- 500 Hosts - Reserve 2048 entries for Bind-IP-to-MAC
- 1 million NAT sessions - Recommended for a network of up to 500+ devices
DrayTek Vigor3912S 10G multi-WAN VPN security router
The DrayTek Vigor3912S is a high-performance enterprise VPN router combining flexible multi-WAN connectivity, 10Gb SFP+ interfaces, advanced traffic management and integrated threat detection. With a 2GHz quad-core processor, 8GB DDR4 memory and a 256GB SSD for Linux applications, it is designed for larger organisations, multi-site networks, service providers and other demanding deployments.
Flexible 10G, 2.5G and Gigabit WAN connectivity
Eight of the Vigor3912S’s twelve network interfaces can be configured for either WAN or LAN operation. This allows the router to support anything from a single high-speed internet connection with extensive LAN connectivity through to an eight-WAN deployment with four dedicated LAN ports.
Configurable interfaces include:
- Two 10G/2.5G/1G SFP+ slots
- Two 2.5G/1G/100M/10M RJ-45 ports
- Four Gigabit Ethernet RJ-45 ports
Four additional Gigabit Ethernet ports are dedicated to LAN connectivity.
Multiple internet services can be combined using session-based load balancing, while WAN failover helps maintain connectivity if a primary service becomes unavailable. This flexibility makes the Vigor3912S suitable for organisations using a combination of fibre, Ethernet, fixed wireless and other externally terminated broadband services.
High-performance routing for bandwidth-intensive networks
A 2GHz quad-core processor and hardware acceleration provide up to 15.6Gbps of aggregate bidirectional NAT throughput under DrayTek test conditions. The router supports up to one million concurrent NAT sessions, providing the capacity required for larger user populations and networks with substantial numbers of connected devices.
Two 10Gb SFP+ slots enable high-speed WAN or LAN connections, while the 2.5GbE interfaces provide practical multi-gigabit connectivity for internet services, servers, core switches and other network infrastructure.
Actual throughput will depend on network conditions, traffic patterns, configuration and the security or management services in use.
Integrated Suricata threat detection
Unlike the standard Vigor3912, the Vigor3912S includes a 256GB SSD with Ubuntu and Docker support. Suricata is pre-installed to provide network-based intrusion detection using an extensive library of threat-detection rules.
Suricata analyses traffic passing through the router and records suspicious activity such as malware communication, intrusion attempts, denial-of-service activity and other potentially malicious behaviour. Administrators can review threat details and use Smart Action rules to trigger notifications or automatically block associated IP addresses.
This provides an additional security layer at the network edge without requiring a separate server to host the threat-detection application.
Automated responses with Smart Action
Smart Action allows network events to trigger predefined responses automatically. Up to 64 event-to-action profiles can be configured, helping administrators react to security events, system conditions and scheduled requirements without continuous manual intervention.
Depending on the event, actions can include:
- Blocking an IP address
- Sending email, web or Telegram notifications
- Calling a webhook
- Running a command-line instruction
- Disabling or removing a VPN profile
- Applying scheduled access restrictions
- Waking a networked computer
On the Vigor3912S, Smart Action can also respond to keywords recorded in Suricata, syslog and console logs.
Host VigorConnect directly on the router
The integrated Linux environment can run VigorConnect as a Docker application. This allows the Vigor3912S to host DrayTek’s network management software without requiring a separate computer or server.
VigorConnect provides centralised discovery, monitoring and management of supported DrayTek network devices. This capability is particularly useful for organisations wanting local network management while reducing the number of dedicated appliances and servers required onsite.
Enterprise VPN capacity for branches and remote users
The Vigor3912S supports up to 500 concurrent VPN tunnels, including up to 200 concurrent SSL VPN or OpenVPN connections. Supported technologies include IPsec, IKEv2, SSL VPN, OpenVPN, WireGuard, L2TP over IPsec and GRE.
Maximum published VPN performance includes:
- 5.7Gbps bidirectional IPsec throughput using AES-256
- 4.3Gbps bidirectional SSL VPN throughput
- 1.08Gbps bidirectional WireGuard throughput
VPN load balancing, failover and backup options can improve resilience for site-to-site deployments. The router also supports VPN user isolation, VPN packet capture, VPN Matcher and two-factor authentication integrated with AD or LDAP services.
These figures are maximum results from DrayTek testing under optimal conditions; real-world VPN performance varies with configuration, protocol, encryption, packet size and traffic conditions.
Network segmentation, routing and traffic control
Support for up to 100 VLANs allows administrators to separate staff, servers, guests, voice systems, IoT equipment and other network resources. VLAN tagging, multiple IP subnets, inter-LAN routing and policy-based firewall rules provide detailed control over how each segment communicates.
BGP and OSPF dynamic routing support make the Vigor3912S suitable for more advanced enterprise and service-provider environments. An integrated PPPoE server supports up to 200 accounts, while inbound server load balancing can distribute connections across multiple internal servers.
Bandwidth limits, session limits and Quality of Service policies help protect important applications from congestion and ensure that voice, video and other business-critical traffic receive appropriate priority.
Business firewall and content security controls
The object-based stateful packet inspection firewall enables administrators to create detailed security policies using reusable network, service and application objects.
Security capabilities include:
- IP-based firewall policies
- Application and URL keyword filtering
- DNS keyword filtering
- Denial-of-service defence
- Spoofing defence
- Port knocking
- IP and URL reputation services
- Brute-force protection
- IPv4 and IPv6 support
Web-category filtering and cloud-based reputation services may require an additional subscription.
High availability for critical network environments
The Vigor3912S supports router high availability, allowing a secondary compatible router to take over if the primary unit fails. Combined with multi-WAN load balancing, internet failover and VPN redundancy, this helps reduce downtime for organisations that depend on continuous connectivity.
The rack-mountable 1U design is suited to installation in a communications cabinet, server room or data centre.
Central management of DrayTek networks
The router can centrally manage up to 50 compatible DrayTek Vigor access points and 30 VigorSwitches. Administrators can discover devices, provision common settings, monitor operational status and perform selected maintenance tasks from the router interface.
For larger or distributed networks, the Vigor3912S also supports VigorACS 3 for remote provisioning, monitoring and SD-WAN management. VigorACS 3 is a separate management platform and may require additional licensing or hosting.
Vigor3912S compared with the Vigor3912
Both models offer the same configurable 10G, 2.5G and Gigabit interfaces, routing performance, VPN capacity and enterprise networking features.
The Vigor3912S adds:
- 8GB DDR4 memory
- Integrated 256GB SSD
- Ubuntu-based Linux application environment
- Docker application support
- Pre-installed Suricata threat detection
- Ability to host VigorConnect locally
The standard Vigor3912 is appropriate where high-performance routing and VPN functionality are required without the integrated Linux applications. The Vigor3912S is the stronger choice when local threat detection, automated security responses or onboard VigorConnect hosting are important.
Technical specifications
|
Specification |
Details |
|---|---|
|
Product model |
DrayTek Vigor3912S |
|
Product type |
Enterprise multi-WAN VPN security router |
|
Processor |
2GHz quad-core processor |
|
Memory |
8GB DDR4 |
|
Internal storage |
256GB SSD |
|
Application environment |
Ubuntu with Docker application support |
|
Included applications |
Suricata and VigorConnect support |
|
Configurable SFP+ interfaces |
2 × 10G/2.5G/1G SFP+ WAN/LAN slots |
|
Configurable multi-gigabit interfaces |
2 × 2.5G/1G/100M/10M RJ-45 WAN/LAN ports |
|
Configurable Gigabit interfaces |
4 × 1G/100M/10M RJ-45 WAN/LAN ports |
|
Fixed LAN interfaces |
4 × 1G/100M/10M RJ-45 ports |
|
Maximum WAN interfaces |
Up to 8 |
|
Console interface |
1 × RJ-45 console port |
|
USB interfaces |
2 × USB 3.0 |
|
Maximum NAT throughput |
15.6Gbps aggregate bidirectional throughput |
|
Maximum NAT sessions |
1,000,000 |
|
Maximum concurrent VPN tunnels |
500 |
|
Maximum SSL VPN/OpenVPN tunnels |
200 |
|
IPsec VPN throughput |
Up to 3.3Gbps single-directional or 5.7Gbps bidirectional with AES-256 |
|
SSL VPN throughput |
Up to 3.3Gbps single-directional or 4.3Gbps bidirectional |
|
WireGuard throughput |
Up to 900Mbps single-directional or 1.08Gbps bidirectional |
|
VPN protocols |
IPsec, IKEv2, SSL VPN, OpenVPN, WireGuard, PPTP, L2TP, L2TP over IPsec, GRE and IPsec-XAuth |
|
VPN authentication |
Local, RADIUS, LDAP, TACACS+, mOTP and TOTP |
|
WAN resilience |
Load balancing, failover and backup |
|
High availability |
Supported |
|
VLAN capacity |
Up to 100 VLANs |
|
PPPoE server |
Up to 200 user accounts |
|
Dynamic routing |
BGP and OSPF |
|
Firewall |
Object-based stateful packet inspection firewall |
|
Threat detection |
Suricata IDS with Smart Action integration |
|
Smart Action capacity |
Up to 64 event-to-action profiles |
|
Content filtering |
Application, URL keyword, DNS keyword, web-feature and web-category filtering; some services require a subscription |
|
Central AP management |
Up to 50 compatible DrayTek Vigor access points |
|
Central switch management |
Up to 30 compatible DrayTek VigorSwitches |
|
Remote management |
VigorACS 3 support |
|
Management protocols |
HTTP, HTTPS, Telnet, SSH v2, FTP, TR-069, SNMP v1/v2c/v3 and syslog |
|
Power input |
100–240V AC, 0.6A |
|
Maximum power consumption |
35W |
|
Dimensions |
443 × 285 × 45mm |
|
Weight |
3.35kg |
|
Operating temperature |
0°C to 45°C |
|
Operating humidity |
10% to 90%, non-condensing |
|
Installation |
1U rack-mountable |