Draytek Vigor 2960High-Performance Router/FirewallLoad Balancing & WAN FailoverNative IPv4 & IPv6 dual-stackTwo Gigabit WAN portsFour Gigabit LAN PortsTwin Independent USB PortsIPSec VPN – LAN-to-LAN or Teleworker (200 tunnels)SSL VPN Tunnel or Web-Proxy (50 tunnels)802.1q Tagged and port-based VLANsQoS Assurance on different traffic typesVPN Trunking (Backup/aggregation)Mobile One-Time Passwords for Teleworker VPNsMultiple LAN-side private IP subnetsInternet Content FilteringCentral Management of up to 30 DrayTek VigorAPs – New!Central Switch Management – New!Optional VigorCare AvailableTechnical Specification (UK Hardware Spec.)Physical InterfacesLAN: 4-port Gigabit (10/100/1000 Base-T)WAN: 2-port Gigabit (10/100/1000 Base-T) EthernetUSB: 2 USB 2.0 Ports (for flash storage and 3G)WAN Protocols: PPPoE, PPTP, DHCP Client, Static IPLoad Balancing: Policy based or automaticWAN Failover: Switch to other connection when primary WAN lostVPN ServicesRemote Dial In Teleworker Protocols:PPTPIPSecL2TPL2TP over IPSecSSL VPNLAN to LAN VPN Tunnel Protocols:PPTPIPSecSSL VPNGRE (LAN to LAN Tunnel) – New!Up to 200 simultaneous tunnels (LAN-to-LAN or Teleworker-to-LAN)PPTP Acceleration (up to 90Mbps with encryption)Dial-in and Dial-out supportedVPN Trunking: allows alternative failover route or multiple tunnels to the same destination to increase capacity/throughputMultiple SA (Security Association) IPsec VPN support: send multiple Local and Remote subnets through one VPN tunnel – New!Teleworker – Remote Dial-In VPN Features:LDAP/Active Directory: Teleworker VPNs can be authenticated by a LDAP/AD serverXAuth authentication support for IPsec Remote Dial-In Teleworker VPN tunnels – New!Radius Client: Authentication for Remote Dial-In TeleworkersScheduled Remote Dial-In VPN – configure times that specified Teleworkers are allowed to Dial In – New!DrayTek Smart-VPN Software utilityIPsec IKE Protocols:IKEv1IKEv2 – New!IPsec IKE Authentication:Pre-shared key (PSK)PKI Certificate (RSA): Use X.509 Digital SignaturesPhase 1 Main Mode or Aggressive ModePhase 2 selectable lifetimesEncryption:Hardware-based AES (128, 192, 256 bits)Hardware-based DES/3DES (56 & 168 bits)Hardware-based MD5, SHA-1 & SHA-256MPPE (40 or 128 bits)IKE Phase 1 DiffieHelman Groups 1,2,5 & 14IKE Phase 2 DiffieHelman Groups 1,2,5 & 14 (will match phase 1 selection)DHCP over IPSecGRE over IPSecDead-Peer-Detection (DPD)NAT-Traversal (NAT-T): VPN over routes without VPN PassthroughNo extra licencing or additional VPN client costs.Interoperability : Compatible with other 3rd party VPN devicesFirewallStateful Packet Inspection (SPI)Content Security Management (CSM)Multi-NAT: Set one-to-one mappings between your private and public IP addressesNAT Port Forward Features:Port Redirection – 256 entries with 16 port ranges per entryDMZ HostServer Load Balance & Inbound Load BalanceSIP Application Layer Gateway (ALG)H.323 Application Layer Gateway (ALG)Policy-based IP Packet Filter. Fully configurable policies based on IP address, MAC address (source or destination), DiffServ attribute, direction, bandwidth, remote siteDoS/DDoS ProtectionIP Address Anti-spoofingObject-Based FirewallNotification: Email alerts and logs to syslogBind IP to MAC addressUser-Controlled Rules: Interrogates LDAP server to permit access or enforce policiesDNSSEC support – New!LAN DNS Features:Control DNS resolution for A and CNAME records for configured hostnamesWildcard supportConditional Forwarding to specified DNS Server(s)Web Content Filtering & CSMURL Keyword Blocking: Blacklist or WhitelistContent Type Blocking: Java applet, cookies, Active-XApplication Enforcement (APPE): IM, P2P, Protocol, Tunnelling, Streaming, Remote Cotnrol, Wed HDAuto APPE Signature UpgradeBlock P2P Applications (inc. Kazza, WinMX, Bittorrent)Block Instant messagingBlock access of web sites by direct IP address (thus URLs only)Block HTTP download of compressed, executable or multimedia filesWeb Content Filter: GlobalView filtering of 64 web site categories (e.g. adult, gambling sites etc.). subscription required (free trial included)Time Scheduling: Blocking rules can be activated based on time schedulesUser ManagementManage account features through User Profiles – VPN, PPPoE, Web Portal, FTP, SambaInternal RADIUS ServerExternal LDAP / Active Directory server authentication with SSL supportExternal RADIUS server authenticationPPPoE ServerGuest Profiles with Guest Account GeneratorWeb Portal Features:User Authentication for Internet access with Time QuotasSMS Authentication (requires SMS provider)Web Portal Login Page CustomisationLogin HistorySystem ManagementWeb-Based User Interface: Integrated server for router management (via HTTP or HTTPS)Telnet/SSH : Command line control and configurationConfiguration Backup/RestoreBuilt-in diagnostics, dial-out triger, routing table, ARP table, DHCP Table, NAT Sessions Table, data flow monitor, traffic graph, ping diagnostics, tracerouteFirmware Upgrade by HTTP, TFTP & FTPSyslog LoggingSNMP Management: v1/v2/v3, MIB IIMail Alert & Mail Notifications with SSL & StartTLS encryption supportVigor ACS-SI Centralised Management: TR-069 compatible for ACS platformCompatible with Smart Monitor Traffic Analyser : Windows software for up to 100 usersCentral ManagementAP Management – Manage up to 30 compatible VigorAP access points – New!Switch Management – Manage up to 10 compatible VigorSwitch switches – New!VPN Management – Manage up to 12 DrayTek Vigor routersCertificate ManagementLocal Certificates for HTTPS, SSL & VPNRemote Certificates; Sign and manage certificates from other devices – New!Bandwidth ManagementTraffic Shaping: Dynamic bandwidth management with IP traffic shapingBandwidth Reservation: Connection or client basedPacket Size ControlDiffServ Codepoint Classifying4 Priority Levels (Inbound/Outbound)Individual IP Bandwidth Session Limits per user/groupBandwidth BorrowingUser-defined class-based rulesRouting FunctionsIPv4 & IPv6 Dual-StackUp to 20 LAN Subnets / VLANsDNS Cache/ProxyDHCP Client, Server & RelayDHCP Options: 1,3,6,51,53,54,58,59,60,61,66,125IGMP v1/v2 & Proxy/SnoopinguPnP: 500 SessionsNAT: 80,000 SessionsNTP Client with DST AdjustmentsStatic routingPolicy-based routing with scheduling – New!BGP Routing protocolDynamic DNS : Updates DDNS servers with public IP addressPort-Based VLANTag-Based VLAN: 802.1qClient/Call Scheduling : Real-time clock, with NTP updating schedules access or connectivityWake-on-LAN : Passed from WAN to preset LAN deviceOperating RequirementsRack Mountable (Mount brackets included)Temperature Operating : 0 °C ~ 45 ° ° CStorage : -10 °C ~ 70 °CHumidity 10% ~ 90% (non-condensing)Power Consumption: 19W MaxDimensions: L273 * W166 * H44 (mm) (1U Height)Operating Power: 220-240VAC (internal PSU)
Box 4




