DrayTek DV3912S Firewall VPN Router, 8x WAN Ports, 2 x 10GbE SFP+, 2x 2.5GbE, 4x GbE,

  • Up to 8 WANs - including 10G SFP+ and 2.5G Ethernet
  • Quad-Core CPU - provides 15.6 Gbps NAT throughput
  • 500 x VPN tunnels - provides 5.7 Gbps IPsec throughput
  • 500 Hosts - Reserve 2048 entries for Bind-IP-to-MAC
  • 1 million NAT sessions - Recommended for a network of up to 500+ devices

Please feel free to contact us about this item, and we will recommend an IT Sales and Service Provider in your area.


Resellers: for pricing and to place orders.

This item is not normally held in stock. We’ll order it in on request. Please contact us for estimated delivery time
In stock email will be sent.
Instock notification already exists.
Order SKU: Supplier Code:

The DrayTek Vigor3912S router is a cutting-edge solution designed to meet the demands of modern enterprise networks. Its excellent performance and security features, including the Suricata Intrusion Detection System and Smart Action, make it a standout choice for businesses seeking to safeguard their networks from potential security breaches.

The Vigor3912S model comes equipped with a 256GB SSD Memory which has pre-installed Ubuntu OS and Docker applications such as Suricata IDS (Intrusion Detection System)/IPS (Intrusion Prevention System), VigorConnect, etc. to enhance network security.

  • 2 x 10G/2.5G/1G SFP+ Fibre configurable WAN/LAN Slots
  • 2 x 2.5G/1G/100M/10M Ethernet configurable WAN/LAN ports
  • 4 x 1G/100M/10M Ethernet Configurable WAN/LAN ports
  • 4 x 1G/100M/10M Ethernet LAN ports with 1 million NAT sessions
  • Multi-WAN Load Balancing & Failover
  • Quad-Core CPU with 15.6 Gbps NAT throughput**
  • 500 x VPN tunnels (including 200 x OpenVPN/ SSL-VPN tunnels) with most security protocols
  • Fast VPN throughput, VPN Load Balancing, Failover, and backup for site-to-site applications
  • 100 x VLANs for secure and efficient workgroup management
  • 1 x RJ-45 console port
  • 2 x USB 3.0 ports for external storage (one USB flash drive is supported at any one time)
  • High-Availability (with CARP) ensuring 24/7 system uptime
  • Object-oriented SPI Firewall
  • Multi-subnet WAN/LAN through 802.1Q
  • IPv6 & IPv4
  • Bandwidth management
  • Supports VigorACS 3 Central Management Software for remote management
  • SD WAN capability when used with VigorACS 3
  • Supports Central AP Management (up to 50 Vigor Access Points) Learn more
  • Supports Central Switch Management (up to 30 Vigor Switches) Learn more
  • Rack-mountable
  • 2 year warranty
  • ** bi-directional(TX+RX) performance

The Vigor3912S is powered by a 2GHz Quad-Core CPU, ensuring fast and reliable connection speeds even with multiple devices connected. It supports eight configurable WAN/LAN interfaces, including two 10G SFP+ ports for fibre connectivity, two 2.5G Ethernet ports, and four 1G Ethernet ports. This flexibility allows network administrators to optimise performance based on specific networking needs and circumstances.

In addition to the comprehensive hardware specifications, the Vigor3912S is equipped with a 256GB solid-state drive (SSD) pre-installed with Ubuntu OS and Docker applications such as Suricata and VigorConnect. Running VigorConnect from the Vigor3912S simplifies network management by allowing it to monitor DrayTek devices without requiring an additional server.

Here are some of the key security benefits of the Vigor3912S router:
Suricata Intrusion Detection and Prevention System:

The Vigor3912S integrates with Suricata, an open-source intrusion detection system that monitors network traffic for suspicious activity and potential security threats. Suricata provides real-time protection against malicious activities and unauthorised access attempts so businesses can stay one step ahead of cyber threats. When the system detects unplanned threats, they are recorded by the log feature, blocked by the router’s “Smart Action” feature, and network administrators can be notified of the incidents.

The Suricata Statistical Graph summarises the frequency of threats. When the mouse hovers over the icon representing the most frequent threat, a small pop-up note will display the number of occurrences of that threat. Moreover, clicking on any point in the graph will bring up more details.

Linux Application – VigorConnect
The Vigor3912S router supports Docker applications such as VigorConnect directly on the device. This capability simplifies network management by allowing VigorConnect to monitor DrayTek devices without requiring an additional computer. The installation process is straightforward and can be completed through the router’s web user interface (WUI) with just a few clicks. This feature provides a convenient and efficient solution for network administrators to oversee and manage their network infrastructure.

Smart Action Feature
The Vigor3912S router’s Smart Action feature allows automatic actions based on predefined security events. Whether blocking specific IP addresses, triggering alerts or enforcing access control policies, Smart Action empowers administrators to preplan responses to security incidents without manual intervention, enhancing the network’s overall security.

Action types available in Smart Action include:

  • Command-line Interface
  • Mail Alert
  • Webhook
  • Web Notification
  • Telegram
  • Block IP

Firewall and Content Filtering Feature
The Vigor3912S’s built-in firewall and advanced security protocols protect the network against cyber threats to keep sensitive data and network infrastructure secure.
The Vigor3912S features an object-based firewall that allows administrators to set up detailed security policies. Its web content filter blocks access to pre-designated insecure or inappropriate websites, ensuring a safe browsing environment for all users.
Additionally, the IP Reputation feature analyses the reputation of IP addresses attempting to connect to the router. It then blocks any IP identified as associated with known malicious activity. This helps prevent attacks from known malicious IP addresses and reduces the risk of security breaches.

Other key benefits of using the Vigor3912S router for a business are:
Quality of Service (QoS) Feature
With the Vigor3912S’s QoS support, you can effectively prioritise and manage network traffic so critical applications and services always receive the necessary bandwidth and resources.

Advanced VPN Feature
The Vigor3912S supports up to 500 concurrent VPN tunnels, making it ideal for businesses with many remote workers or multiple branch offices. It offers several VPN protocols and connection types, including LAN-to-LAN and remote dial-in VPNs, to ensure secure and efficient communication across various networking environments.

Two-factor authentication (2FA) adds an extra layer of security by requiring users to provide two forms of identification before gaining access to the network. It ensures that legitimate remote dial-in users can be authenticated and provided with secure VPN connections while illegitimate connection requests will fail.

Intuitive Management Interface
The Vigor3912S offers a user-friendly management interface, making configuration and monitoring of the networks easy and intuitive to minimise technical errors.

Scalability and Reliability
Built for scalability, the Vigor3912S has plenty of flexible features and growth options for network expansion when the business grows and network traffic increases without compromising performance and reliability.

Cost-Effective Solution
The Vigor3912S offers a cost-effective networking solution and delivers superb performance, security, and reliability by streamlining its network infrastructure and optimising resource utilisation.

Maximise Performance with Fast NAT and Fast Routing
Enhance overall network performance with optimised data packet processing and forwarding. This feature improves network efficiency by improving transmission speed, and enhances user experience by minimising network latency, making it ideal for real-time applications such as large file transfers and voice calls.

High Performance with 10Gb SFP+
For both NAT and routing network, and for both 10Gb-WAN and 10Gb-LAN, Vigor3912 is ready to deliver high throughput to your business.

Layer 3 Routing with BGP and OSPF
With the most popular Exterior and Interior Gateway Protocols, Vigor3912 is ideal for ISP deployment.

Layer 2 Security with PPPoE Server and VLAN
With 200 PPPoE user accounts and 100 VLAN/LAN subnets, the Vigor3912 provides 15.6 Gbps (bi-directional; TX+RX) NAT throughput, making network infrastructure segmentation secure and easy.

Configurable WAN/LAN Ports
12 Ports in total

8 ports from a total of 12 ports, can be configured as either a LAN port or a WAN interface. For example, the following port options are achievable:

8 x WAN interfaces and 4 x LAN Ports or
1 x WAN interface and 11 LAN Ports

Advanced VPN Features
 
VPN from LAN
This feature offers a more secure method for connecting to servers by restricting LAN clients’ access to LAN servers through a VPN only. This ensures that data transmission between LAN clients and servers is encrypted, protecting critical data and enhancing overall security.

VPN User Isolation
Activating a VPN connection to access a company’s internet for work has become a common routine for many employees.

Teleworkers need to connect to the company’s servers through VPN connections. However, it is often unnecessary for VPN users to access each other, which may pose security risks. By enabling the “Isolate VPN Users from each other” option, you can ensure that each VPN user is isolated and the VPN network is more secure.

2FA with AD/LDAP Server
Enhance the security of remote dial-in VPN connections with two-factor authentication integrated with AD/LDAP servers. DrayTek offers various authentication methods, including TOTP, email, SMS, and URL links. This approach not only adds an extra layer of security but also helps reduce costs associated with SMS messages and official authentication system license fees.

Packet Capture Tool for VPN Tunnel
By either mirroring all packets to the designated LAN port or VPN connection, whether LAN to LAN profile or remote Dial-in users and even downloading PCAP files via WUI remotely and spotting an issue is easier than ever.

Server Load Balancing
For organizations that host multiple servers in their network, a policy of server load balance can be configured, such that the router can distribute the inbound NAT sessions evenly for the servers based on the configured load balance weight. This will avoid excessive load on a single server, prevent server failure due to overloading, and optimise resource usage .

Port Knocking
The Port Redirection function is often used to allow the internal servers to be accessible from the Internet. However, the opened ports present security threats as these can be scanned by hackers and malware. Vigor3912 series employ Port Knocking, a technology that adds an extra layer of protection to the internal servers, by allowing only users with a matching password to open the port and be connected to the server, effectively closing the door for unauthorized accesses.

All-in-One Management

This Vigor router provides a management platform for your Vigor devices on the LAN

Auto-Discovery

Automatically discover LAN subnets and add detected VigorSwitch/AP into managed list.

Provisioning

Most-frequent used settings can be pre-defined on the Vigor Router, and provision to the managed VigorSwitch/AP.

Monitoring

Vigor Router provides a centralized view of managing devices, you may always check if the managed Vigor Switch/AP is online.

System Maintenance

Support basic maintenance remotely via Vigor Router. Such as remote reboot, factory reset, configuration backup/restore, etc.

Key Features

Quad-Core Processor
Offers excellent performance for bandwidth-demanding enterprise networks

Hotspot Web Portal
Market your business and communicate with the guests while offering hospitality Wi-Fi. Learn more

10G SFP+
Provides 2 x 10G-capable fibre SFP ports for WAN or LAN connection.

 

Bandwidth Management

Control Internet bandwidth usage by users by using the bandwidth limit and session limit policy settings, and prioritise traffic by using the QoS feature.


Load Balancing
Maximize throughput and reliability by using multiple Internet connections. Learn more


Firewall & Content Filter

Use URL keywords or web categories to filter web pages and block access to insecure or inappropriate content.


VPN (Virtual Private Network)
Build a secure and private tunnel from the LAN of Vigor3912 to the remote offices and teleworkers over the Internet. Learn more


DrayDDNS

The free DDNS service for you to access the router by a fixed hostname of your choice. Learn more.


SSL VPN

SSL VPN works through firewalls providing secure remote access to any network environment. Learn more


Central AP Management

Use the Vigor3912 router as a wireless controller to maintain and monitor the VigorAPs. Learn more


DrayDDNS
The free DDNS service for you to access the router by a fixed hostname of your choice. Learn more


PPPoE Server
Use Point-to-Point connection on LAN to keep track of individual user’s traffic. Setup Guide


Central Switch Management

Set up VLAN easily from the router and get a centralized hierarchy view of the switches. Learn more


VPN 2FA Auth for AD/LDAP
Enhance the security for remote VPN connections and eliminate the cost for an official authentication system. Learn more


VPN Matcher
Helps routers behind NAT to find each other and establish a LAN-to-LAN VPN. Learn more

All-in-One Management
Vigor Router SWM
DrayTek

Central Switch Management
Auto-Discovery
Auto-Provisioning
Monitoring
Centralized Hierarchy View
Reboot PoE Devices Remotely
Quick VLAN Configuration
VigorAP-based APM
DrayTekCentral AP Management
Auto-Discovery
Auto-Provisioning
Monitoring
Centralized View
Alarm
Reboot VigorAP Remotely
Wi-Fi Client Load Balancing
Software Management
VigorACS 3
DrayTekVigorACS 3
Zero Touch Deployment & Provisioning
Auto VPN
Interface Quality & SLA
VoIP Optimization & Monitoring
Application Visibility
Application Based SD-WAN Policy
Customized Hotspot Page with Multilingual
Hotspot Clients Analytics
ACS Server Load Balancing / Failover