DrayTek Vigor3912 Series Broadband Router
Quad-Core CPU, 2 x 10Gb SFP+ Fibre WAN/LAN slots, 2 x 2.5GbE WAN/LAN Ports, and 4 x fixed GbE LAN ports, SPI Firewall, 500 x VPN tunnels inc. 200 x SSL-VPN tunnels. The Vigor3912S model also has 256GB SSD for Suricata IDS and other security apps.
- Estimated Delivery : Up to 4 business days
- Free Shipping & Returns : On all orders over $200
The Vigor3912S model comes equipped with a 256GB SSD pre-installed with Ubuntu OS and Docker applications such as Suricata IDS (Intrusion Detection System) and VigorConnect to enhance network security.
**bi-directional(TX+RX) performance
Quad-Core Powerful Enterprise Gateway
The Vigor3912 series Multi-WAN routers are high-performance enterprise-level broadband routers with 2 x 10Gb SFP+ Fibre configurable WAN/LAN slots, 2 x 2.5GbE configurable WAN/LAN ports, 4 x 1GbE configurable WAN/LAN ports, and 4 x 1GbE fixed LAN ports with 15.6 Gbps max. NAT throughput and Software Acceleration (bi-directional), 1,000k NAT sessions and other enterprise-level features. With the capacity to handle up to 500 VPN tunnels including 200 OpenVPN /SSL-VPN tunnels, and 100 IP subnets simultaneously, Vigor3912 routers are an excellent solution for network applications in corporations, organisations and governments.
The session-based Load Balance feature allows the aggregation of multiple WAN connections to provide a higher speed internet connection. In addition to the Load Balance and Failover multi-WAN functions, the Vigor3912 supports High Availability (Common Address Redundancy Protocol) with hardware redundancy to ensure 24/7 system uptime for all WAN interfaces.
The Central Management feature provides a centralised console to manage your network. It includes AP Management to configure and manage up to 50 DrayTek Access Points, and Switch Management to configure and manage up to 30 DrayTek VigorSwitches.
The Vigor3912S model comes equipped with a 256GB SSD which supports Linux with Docker applications such as Suricata IDS and VigorConnect. Together with this router’s capacity, these powerful applications eliminate the need for additional servers, enforcing security options at the door.
Linux Applications (Vigor3912S Only)
The Vigor3912S model comes equipped with a 256GB SSD pre-installed with Ubuntu OS and Docker applications such as Suricata IDS and VigorConnect to enhance network security:
- VigorConnect
- Suricata
- Applications on Ubuntu


Linux Application – VigorConnect (Vigor3912S Only)
The Vigor3912S router supports Docker applications such as VigorConnect directly on the device. This capability simplifies network management by allowing VigorConnect to monitor DrayTek devices without requiring an additional computer. The installation process is straightforward and can be completed through the router’s web user interface (WUI) with just a few clicks. This feature provides a convenient and efficient solution for network administrators to oversee and manage their network infrastructure.

Linux Application – Suricata (Vigor3912S Only)
A popular open-source threat detection application for detecting and preventing a wide range of network threats.
The Vigor3912S is pre-installed with the Linux-based application Suricata, an open-source threat detection system that supports more than 60,000 rules, including 6,000+ CVE (Common Vulnerabilities and Exposures) rules, and it can detect and prevent a wide range of network threats, such as malware, network intrusions, denial-of-service attacks and data breaches.
Suricata, an intrusion detection system (IDS), monitors LAN and WAN traffic through the router. A log is generated if any unusual activity is detected, which can be sent to the network administrator via the router’s Web Notification function.

Blocking can be achieved with the “Smart Action” feature in the router.
This feature monitors network traffic and detect malicious activity in real time. Suricata works by analysing packets and comparing them to a set of rules to determine whether the traffic is legitimate. If it detects suspicious activity, it can raise an alarm. Suricata is highly customisable and can monitor many network environments, from small homes to large enterprise networks.
Suricata – The Threat Log Generator

Suricata Features (Vigor3912S Only)
Statistical Graph
Suricata Statistical Graph presents the timing and frequency of threats. When the mouse hovers over the point representing the most frequent threat, a small menu will pop up to display the number of occurrences of that threat. Additionally, a click on the item will display more details that are crucial for security enhancement.

Smart Action (Vigor3912 feature)

Smart Action allows predefined events to trigger predefined actions. Vigor users can pre-configure up to 64 event-to-action profiles. Actions, such as sending alerts, emails, removing a VPN profile, etc., can be programmed for events such as network conditions, occurrence counts, etc., associated with specified time and date.
– Event → Action: A predefined event triggers the predefined action.
– Web Notification.
– Log Keyword Match (syslog log, console log, Suricata log).
** bi-directional(TX+RX) performance
Interface

*WAN/LAN Switchable
Performance Comparison: Vigor3912 vs. Vigor3910
NAT throughput (1.9x times faster)
IPSec throughput
(2.1 times faster)
SSL-VPN throughput
(2.9 times faster)
Wireguard throughput
(3.2 times faster)
**bi-directional(TX+RX) performance
Maximise Performance with Fast NAT and Fast Routing
Enhance overall network performance with optimised data packet processing and forwarding. This feature improves network efficiency by improving transmission speed, and enhances user experience by minimising network latency, making it ideal for real-time applications such as large file transfers and voice calls.

Key Features
Fibre to the Building/Home
The Vigor3912 is an ideal choice for tier 2/3 ISPs and co-working spaces
High Performance with 10Gb SFP+
For both NAT and routing network, and for both 10Gb-WAN and 10Gb-LAN, Vigor3912 is ready to deliver high throughput to your business.
Layer 3 Routing with BGP and OSPF
With the most popular Exterior and Interior Gateway Protocols, Vigor3912 is ideal for ISP deployment.
Layer 2 Security with PPPoE Server and VLAN
With 200 PPPoE user accounts and 100 VLAN/LAN subnets, the Vigor3912 provides 15.6 Gbps (bi-directional; TX+RX) NAT throughput, making network infrastructure segmentation secure and easy.

Configurable WAN/LAN Ports
12 Ports in total
8 ports from a total of 12 ports, can be configured as either a LAN port or a WAN interface. For example, the following port options are achievable:
- 8 x WAN interfaces and 4 x LAN Ports or
- 1 x WAN interface and 11 LAN Ports

Advanced VPN Features

VPN from LAN
This feature offers a more secure method for connecting to servers by restricting LAN clients’ access to LAN servers through a VPN only. This ensures that data transmission between LAN clients and servers is encrypted, protecting critical data and enhancing overall security.
VPN User Isolation
Activating a VPN connection to access a company’s internet for work has become a common routine for many employees.
Teleworkers need to connect to the company’s servers through VPN connections. However, it is often unnecessary for VPN users to access each other, which may pose security risks. By enabling the “Isolate VPN Users from each other” option, you can ensure that each VPN user is isolated and the VPN network is more secure.


2FA with AD/LDAP Server
Enhance the security of remote dial-in VPN connections with two-factor authentication integrated with AD/LDAP servers. DrayTek offers various authentication methods, including TOTP, email, SMS, and URL links. This approach not only adds an extra layer of security but also helps reduce costs associated with SMS messages and official authentication system license fees.
Packet Capture Tool for VPN Tunnel
By either mirroring all packets to a designated LAN port or VPN connection, whether LAN to LAN profiles or remote Dial-in users, or even downloading PCAP files via WUI remotely, spotting an issue is easier than ever.

Server Load Balancing
For organisations that host multiple servers in their network, a policy of server load balance can be configured, such that the router can distribute the inbound NAT sessions evenly for the servers based on the configured load balance weight. This will avoid excessive load on a single server, prevent server failure due to overloading, and optimise resource usage.

Port Knocking
The Port Redirection function is often used to allow internal servers to be accessible from the Internet. However, the opened ports present security threats as these can be scanned by hackers and malware. Vigor3912 series employs Port Knocking, a technology that adds an extra layer of protection to internal servers by allowing only users with a matching password to open the port and be connected to the server, effectively closing the door for unauthorised accesses.

All-in-One Management
Vigor routers provide a management platform for Vigor devices on the LAN
Auto-Discovery
Automatically discover LAN subnets and add detected VigorSwitches/APs into the managed list.
Provisioning
Most-frequently used settings can be pre-defined on the Vigor Router, which can then be provisioned to the managed VigorSwitch/AP.
Monitoring
Vigor Routers provide a centralised view of managed devices so you can always check if the managed Vigor Switch/AP is online.
System Maintenance
Support basic maintenance remotely via Vigor Router, such as remote reboot, factory reset, configuration backup/restore.

Management Solution
Software Management |
---|
All-in-One Management |
---|
In-the-Box

Vigor3912

Rack Mount Kit
(brackets)

Console Connector +
Console Flat Cable

RJ-45 Cable
(Ethernet)

Power Cord

Quick Start Guide
Vigor391x Series Models Comparison
Model | Vigor3912S | Vigor3912 | Vigor3910 |
---|---|---|---|
Product | ![]() |
![]() |
![]() |
Multi Gigabit WAN | 2 x 10Gb SFP+ WAN/LAN slots 2 x 2.5GbE WAN/LAN ports 4 x 1GbE WAN/LAN ports |
2 x 10Gb SFP+ WAN/LAN slots 2 x 2.5GbE WAN/LAN ports 4 x 1GbE WAN/LAN ports |
2 x 10Gb SFP+ WAN/LAN slots 2 x 2.5GbE WAN/LAN ports 4 x 1GbE WAN/LAN ports |
Gigabit LAN | 4 | 4 | 4 |
Quad-Core Processor | 2GHz | 2GHz | 1.2GHz |
Max. Number of VLAN | 100 | 100 | 100 |
VPN Tunnels | 500 | 500 | 500 |
Memory | 8GB DDR4 + 256GB SSD | 4GB DDR4 | |
Wireless LAN |
Specifications
Interface | |
---|---|
WAN/LAN Port | 2 x 10G/2.5G/1G SFP+ Fibre configurable WAN/LAN Slots 2 x 2.5G/1G/100M/10M Ethernet configurable WAN/LAN, RJ-45 4 x 1G/100M/10M Ethernet Configurable WAN/LAN ports, RJ-45 4 x 1G/100M/10M Ethernet LAN ports with 1 million NAT sessions |
USB Port | 2 x USB 3.0 ports for external storage (one USB flash drive is supported at any one time) |
Console Port | 1 x RJ-45 |
Reset Button | 1 x Factory Reset |
Performance | |
---|---|
NAT Throughput | 15.6 Gbps ( bi-directional(TX+RX) performance) |
IPsec VPN Performance | 5.7 Gbps |
SSL VPN Performance | 4.3 Gbps |
NAT Sessions | 1,000,000 |
Max. Concurrent VPN Tunnels | 500 |
Max. Concurrent OpenVPN + SSL VPN | 200 |
Internet Connection | |
---|---|
IPv4 | PPPoE, DHCP, Static IP |
IPv6 | PPP, DHCPv6, Static IPv6, TSPC, AICCU, 6rd, 6in4 Static Tunnel |
802.1p/q Multi-LAN Tagging | |
Multi-VLAN/PVC | |
Load Balancing | IP-based, Session-based |
WAN Active on Demand | Link Failure, Traffic Threshold |
Connection Detection | ARP, Ping, Strict ARP |
WAN Data Budget | |
Dynamic DNS | |
DrayDDNS |
LAN Management | |
---|---|
VLAN | 802.1q Tag-based, Port-based |
Max. Number of VLAN | 100 |
Number of LAN Subnet | 100 |
DHCP Server | Multiple IP Subnet, Custom DHCP Options, Bind-IP-to-MAC |
LAN IP Alias | |
IP Pool Count | Up to 4K per LAN Subnet |
PPPoE Server | |
Port Mirroring | |
Local DNS Server | |
Conditional DNS Forwarding | |
Hotspot Web Portal (Profile No.) | 4 |
Hotspot Authentication | Click-Through, Social Login, SMS PIN, RADIUS, External Portal Server |
Networking | |
---|---|
Routing | IPv4 Static Routing, IPv6 Static Routing, Policy Route, Inter-VLAN Routing, Fast Routing, RIP v1/v2, OSPFv2, BGP |
Policy-based Routing | Protocol, IP Address, Port, Domain, Country |
Smart Action | |
High Availability | |
DNS Security (DNSSEC) | IGMP v2/v3, IGMP Proxy, IGMP Snooping & Fast Leave |
Local RADIUS server |
VPN | |
---|---|
LAN-to-LAN | |
Teleworker-to-LAN | |
Protocols | PPTP, L2TP, IPsec, L2TP over IPsec, SSL, GRE, IKEv2, IPsec-XAuth, OpenVPN, Wireguard |
IPsec VPN Throughput (AES 256 bits) (single-directional) |
3300 Mbps |
IPsec VPN Throughput (AES 256 bits) (bi-directional) |
5700 Mbps |
SSL VPN Throughput (single-directional) |
3300 Mbps |
SSL VPN Throughput (bi-directional) |
4300 Mbps |
Wireguard VPN Throughput (single-directional) |
900 Mbps |
Wireguard VPN Throughput (bi-directional) |
1080 Mbps |
User Authentication | Local, RADIUS, LDAP, TACACS+, mOTP, TOTP |
IKE Authentication | EAP, Pre-Shared Key, X.509, XAuth |
IPsec Authentication | MD5, SHA-1, SHA-256, SHA-512 |
Encryption | MPPE, DES, 3DES, AES |
VPN Trunk (Redundancy) | Load Balancing, Failover |
Single-Armed VPN | |
NAT-Traversal (NAT-T) | |
VPN from LAN | |
VPN Isolation | |
VPN Packet Capture | |
VPN 2FA Authentication for AD/LDAP | |
DrayTek VPN Matcher |
Firewall & Content Filtering | |
---|---|
IP-based Firewall Policy | |
Content Filtering | Application, URL Keyword, DNS Keyword, Web Features, Web Category (subscription required) |
DoS Attack Defense | |
Spoofing Defense |
Linux Applications (Vigor3912S only) | |
---|---|
Suricata | |
VigorConnect |
NAT | |
---|---|
NAT | Port Redirection, Open Ports, Port Triggering, Port Knocking, Fast NAT, DMZ Host, UPnP, Server Load Balance |
ALG (Application Layer Gateway) | SIP, RTSP, FTP, H.323 |
VPN Pass-Through | PPTP, L2TP, IPsec |
Bandwidth Management | |
---|---|
IP-based Bandwidth Limit | |
IP-based Session Limit | |
QoS (Quality of Service) | TOS, DSCP, 802.1p, IP Address, Service Type |
VoIP Prioritization | |
APP QoS |
Management | |
---|---|
Local Service | HTTP, HTTPS, Telnet, SSH v2, FTP, TR-069 |
Config Backup/Restore | |
Firmware Upgrade | TFTP, HTTP, TR-069 |
2-Level Administration Privilege | |
Access Control | Access List, Brute Force Protection |
Notification Alert | SMS, E-mail |
SNMP | v1, v2c, v3 |
Syslog | |
Central AP Management | 50 Vigor Access Points |
Central Switch Management | 30 Vigor Switches |
VigorACS Management (Since f/w) | V4.3.5.1 |
Physical | |
---|---|
Power Input | AC 100~240V @ 0.6A |
Max. Power Consumption | 35 watts |
Memory | 8GB DDR4 (Vigor3912) 8GB DDR4 + 256GB SSD (Vigor3912S) |
Dimension | 443 mm x 285 mm x 45 mm |
Weight | 3.35 kg |
Operating Temperature | 0 to 45°C |
Storage Temperature | -10 to 55°C |
Operating Humidity (non-condensing) | 10 to 90% |
Note :
- All specifications are subject to change without notice.
- The throughput figures are maximum, based on DrayTek internal testing with optimal conditions. The actual performance may vary depending on the different network conditions and applications activated.
Resources
Dimensions | N/A |
---|---|
Model | Vigor3910, Vigor3912, Vigor3912S |