Product and Solutions

Vigor 3900

  • 4 Gigabit Ethernet WANs + 1 Active Fiber (SFP) for a total of 5 WAN ports.
  • 2 Gigabit LAN ports + 1 Active Fiber (SFP).
  • 1 Console port.
  • Up to 500 simultaneous VPN tunnels.
  • SPI firewall, Multi-NAT, DoS/DDoS prevention, content filters for complete protection and policy enforcement.
  • Bandwidth management, traffic shaping and QoS to control allocation of resources.
  • Comprehensive certificate management.
  • 2 USB ports.
WAN Protocol
EthernetPPPoE, PPTP, DHCP client, static IP, L2TP*, Ipv6
Multi WAN
Outbound policy based load balance
  • Allow your local network to access Internet using multiple Internet connections with high-level of Internet connectivity availability.
  • 4 dedicated Ethernet WAN ports (10/100/1000Mbps) and 1 active fiber (SFP) slot.
  • WAN fail-over or load-balanced connectivity.
  • Redundancy.
  • By WAN interfaces traffic volume.
  • By destination IP address range.
  • By fixed VPN connection.
  • Flexible pooling rule setting.
  • Auto-detect line status.
  • Service/IP based preference rules or auto-weight.
Bandwidth on demandService/IP based preference rules or auto-weight
VPN
Prevent Replay Attack
ProtocolsPPTP, IPSec, L2TP, L2TP over IPSec.
Up to 500 connections simultaneouslyLAN to LAN, remote access (teleworker-to-LAN), dial-in or dial-out.
VPN trunkingVPN load-balancing and VPN backup.
VPN throughput760Mbps.
NAT-traversal (NAT-T)VPN over routes without VPN pass-through.
PKI certificateDigital signature (X.509).
IKE authenticationPre-shared key; IKE.
AuthenticationHardware-based MD5, SHA-1.
EncryptionMPPE and hardware-based AES/DES/3DES.
RADIUS clientAuthentication for PPTP remote dial-in.
DHCP over IPSec*Because DrayTek add a virtual NIC on the PC, thus, while connecting to the server via IPSec tunnel, PC will obtain an IP address from the remote side through DHCP protocol, which is quite similar with PPTP.
GRE over IPSecCreating a virtual point-to-point link to various brands of routers at remote sites over an IP internetwork.
Dead Peer Detection (DPD)When there is traffic between the peers, it is not necessary for one peer to send a keep-alive to check for liveness of the peer because the IPSec traffic serves as implicit proof of the availability of the peer.
Smart VPN software utilityProvided free of charge for teleworker convenience (Windows environment).
Easy of adoptionNo additional client or remote site licensing required.
Industrial-standard interoperabilityCompatible with other leading 3rd party vendor VPN devices.
SSL VPN
  • Allow users to use a web browser for secure remote user login tunnel mode, application mode, proxy mode
  • Support 200 SSL tunnels*
Content filter
IM/P2P blockingJava applet, cookies, active X, compressed, executable, multimedia file blocking.
Web content filterDynamic URL filtering database.
Time schedule control*Set rule according to your specific office hours.
Firewall
Stateful Packet Inspection (SPI)Outgoing/Incoming traffic inspection based on connection information.
Multi-NATYou have been allocated multiple public IP address by your ISP. You hence can have a one-to-one relationship between a public IP address and an internal/private IP address. This means that you have the protection of NAT (see earlier) but the PC can be addressed directly from the outside world by its aliased public IP address, but still by only opening specific ports to it (for example TCP port 80 for an http/web server).
Port redirectionThe packet is forwarded to a specific local PC if the port number matches with the defined port number. You can also translate the external port to another port locally.
DMZ hostThis opens up a single PC completely. All incoming packets will be forwarded onto the PC with the local IP address you set. The only exceptions are packets received in response to outgoing requests from other local PCs or incoming packets which match rules in the other two methods.
Policy-based IP packet filterThe header information of an IP packet (IP or Mac source/destination addresses; source /destination ports; DiffServ attribute; direction dependent, bandwidth dependent, remote-site dependent.
DoS/DDoS preventionAct of preventing customers, users, clients or other computers from accessing data on a computer.
IP address anti-spoofingSource IP address check on all interfaces only IP addresses classified within the defined IP networks are allowed.
NotificationE-mail alert* and logging via syslog.
Bind IP to MAC addressFlexible DHCP with 'IP-MAC binding'.
System management
Web-based user interface (HTTP)Integrated web server for the configuration of routers via Internet browsers with HTTP.
Quick start wizardLet administrator adjust time zone and promptly set up the Internet (PPPoE, PPTP, Static IP, DHCP).
User managementDial-in access management (PPTP/L2TP and mOTP).
CLI(Command Line Interface, Telnet/SSH)Remotely administer computers via the telnet.
DHCP client/relay/serverProvides an easy-to configure function for your local IP network.
Dynamic DNSWhen you connect to your ISP, by broadband or ISDN you are normally allocated an dynamic IP address. i.e. the public IP address your router is allocated changes each time you connect to the ISP. If you want to run a local server, remote users cannot predict your current IP address to find you.
Administration access controlThe password can be applied to authentication of administrators.
Configuration backup/restoreIf the hardware breaks down, you can recover the failed system within an acceptable time. Through TFTP, the effective way is to backup and restore configuration between remote hosts.
Built-in diagnostic functionDial-out trigger, routing table, ARP cache table, DHCP table, NAT sessions table, data flow monitor, traffic graph, ping diagnosis, trace route.
NTP client/call schedulingThe Vigor has a real time clock which can update itself from your browser manually or more conveniently automatically from an Internet time server (NTP). This enables you to schedule the router to dial-out to the Internet at a preset time, or restrict Internet access to certain hours. A schedule can also be applied to LAN-to-LAN profiles (VPN or direct dial) or some of the content filtering options.
Tag-based VLAN (802.1Q)By means of using a VLAN ID, a tag-based VLAN can identify VLAN group membership. The VLAN ID provides the information required to process the traffic across a network.Furthermore, the VLAN ID associates traffic with a specific VLAN group.
Firmware upgrade via TFTP/HTTPUsing the TFTP server and the firmware upgrade utility software, you may easily upgrade to the latest firmware whenever enhanced features are added.
Remote maintenanceWith Telnet/SSL, SSH (with password or public key), browser (HTTP/HTTPS), TFTP or SNMP, firmware upgrade via HTTP or TFTP.
Logging via syslogSyslog is a method of logging router activity.
SNMP managementSNMP management via SNMP v1/v2, MIB II.
VigorACS SI Centralized ManagementTR-069 based
Certificate management
Advance encrypted methodA pair of public/priviate key for encryption/decryption.
Comprehensive Certificate AuthenticationTrusted CA / Local Certificate / CA server.
Bandwidth management
Bandwidth managementDynamic bandwidth management with IP traffic shaping.
Bandwidth reservationReserve minimum and maximum bandwidths by connection based or total data through send/receive directions.
DiffServ codepoint classifyingPriority queuing of packets based on DiffServ.
Individual IP bandwidth/session limitationDefine session/bandwidth limitation based on IP address.
User-defined class-based rulesMore flexibility.
QoSIngress/Egress Filter Rules monitor both LAN/WAN packets/8 priority level setting.
Routing functions
RouterIP and NetBIOS/IP-multi-protocol router.
Advanced routing and forwardingComplete independent management and configuration of IP networks in the device, i.e. individual settings for DHCP, DNS, firewall, VLAN, routing, QoS etc.
DNSDNS cache/proxy.
DHCPDHCP client/relay/server.
NTPNTP client, automatic adjustment for daylight-saving time.
Dynamic routingIt is with routing protocol of RIP v2. Learning and propagating routes.
Static routingAn instruction to re-route particular traffic through to another local gateway, instead of sending it onto the Internet with the rest of the traffic. A static route is just like a 'diversion sign' on a road.
High availability
CARP
  • Common address redundancy protocol.
  • Enhanced security with encrypted packet.
Hardware
LAN
  • 2 x 10/100/1000M Base-TX LAN switch, RJ-45
  • 1 x active fiber (SFP) slot
WAN
  • 4 x 10/100/1000M Base-TX WAN switch, RJ-45
  • 1 x active fiber (SFP) slot
Console1 x console, RJ-45
Reset1 x factory reset button
USB2 x USB host 2.0
Support
Warranty2-year limited warranty, technical support through e-mail and Internet FAQ/application notes.
Firmware upgradeFree firmware upgrade from Internet.
ModelPortsWireless
Vigor 39004 Gigabit WAN & 1 SFP
2 Gigabit LAN & 1 SFP
2 USB + 1 Console for Admin.
None

Click link to download PDF file

  1. Vigor 3900 Datasheet