Vigor2927 Series is a dual-Ethernet WAN firewall router, providing load-balancing and failover for your business continuity. Featuring VPN, QoS, route policy, firewall, content filtering, bandwidth management, captive hotspot portal, and a lot more, this is the ultimate router that does it all for SMB. The Series includes built-in 802.11ac Wave 2 WiFi, 802.11ax WiFi, and VoIP gateway models.
IPsec VPN throughput up to 290 Mbps
Throughput up to 120 Mbps
Recommended for a network of 50 hosts
Delivers link rate up to 3 Gbps
1Wireless Antenna (ac/ax model)
2Reset Button
3WLAN/WPS Button (ac/ax model)
4LED Indicator
52x USB 2.0
6Fixed WAN Port: 1x GbE RJ-45
7WAN/LAN Switchable Port: 1x GbE RJ-45
8Fixed LAN Port: 5x GbE RJ-45
92x FXS for VoIP (V model)
10Power On/Off Switch
11Power Input
Maximize throughput and reliability by using multiple Internet connections. Learn more
Build a secure and private tunnel from the LAN of 2927F to the remote offices and teleworkers over the Internet. Learn more
The VPN works through firewalls providing secure remote access to any network environment. Learn more
Helps routers behind NAT to find each other and establish a LAN-to-LAN VPN. Learn more
Filter web pages by URL keyword or web category to block access to insecure or inappropriate contents.
2927F can do port forwarding and reserve bandwidth for VoIP traffic automatically, making VoIP setup effortless. Setup Guide
Prevent one device using all the bandwidth by bandwidth limit policy, session limit policy, and QoS settings.
Market your business and communicate with the guests while offering hospitality WLAN. Learn more
Get Internet access wirelessly from a wireless network, a mobile hotspot, or a personal hotspot set up on smartphones. Learn more
The free DDNS service for you to access the router by a fixed hostname of your choice. Learn more
Use the 2927F router as a wireless controller to maintain and monitor the VigorAPs. Learn more
Easily link to other VigorAP to expand the wireless network. Learn more
Set up VLAN easily from the router and get a centralized hierarchy view of the switches. Learn more
Without sacrificing traffic control features, such as QoS, Bandwidth Limit, WAN Budget, Traffic Graph, Data Flow Monitor, the accelerator brings great performance.
With Hardware accelerator, Vigor2927 is fully capable of providing connections via 2 high speed WANs simultaneously. The accelerator supports up to 8k NAT and routing connections, providing firewall performance up to 940Mbps on single WAN and 1.8Gbps combine d performance across both WAN, while still meeting high expectation of QoS quality.
The accelerator includes Hardware QoS to meet high expectation of QoS quality while enjoying high firewall performance. You may easily prioritized business critical apps, and always keep VoIP in 1 st priority.
Although Vigor2927 already has improved IPSec performance from the previous Vigor2926 series, with Hardware IPSec enabled, IPSec performance is further improved to 800 Mbps. The acceleration capacity is 16 IPSec tunnels max. First 16 tunnels are accelerated automatically on a first come first serve basis. If any of the accelerating 16 tunnels disconnected, new tunnel will be put into the accelerator automatically to top off 16 accelerated tunnels.
*Since firmware v4.2.2
VoIP is always with top priority! With default UDP 5060 port (configurable), VoIP QoS is out-of-box ready.
Select your business critical apps, and easily put them into QoS classes.
Bandwidth will be reserved for high-priority classes, and can be used by low-priority classes when available.
OFDMA has been used in LTE for many years, and is now available in 802.11ax for multi-user mode.
Traditionally with OFDM, each frame is transmitted across the entire channel width. With low-rate transmission still using the whole channel, it brings latency and jitter to others and lower the overall efficiency.
OFDMA splits a single transmission into groups of subcarriers, and each subcarrier can be used by different client. With multiple clients transmitting simultaneously in the same channel, it improves efficiency of every single transmission opportunity and thus increases the wireless experiences in high density environment.
Discovery, Provisioning, Monitoring, Centralized Hierarchy View
Auto-Discovery, Provisioning, Monitoring, Centralized Hierarchy View, Reboot PoE Devices Remotely, Quick VLAN Configuration
Auto-Discovery, Provisioning, Monitoring, Centralized View, Alarm, Reboot VigorAP Remotely, Wi-Fi Client Load Balancing
Note :The stated throughput performance figures are the maximum derived from DrayTek internal testing, conducted under optimal conditions, with Hardware Acceleration enabled where available. The actual performance may vary based on network conditions and activated applications.
Model | WAN Port | 2.4GHz WLAN | 5GHz WLAN | Wireless Antenna | Wireless Mode | Max. Link Rate | Max. Bandwidth | Wireless WAN | WDS | Mesh | VoIP Gateway | FXS RJ-11 |
Vigor2927 | GbE, RJ-45 | - | - | - | - | - | - | - | - | - | - | - |
Vigor2927ax | GbE, RJ-45 | 2x Dual-Band (3dBi for 5GHz, 2.5dBi for 2.4GHz) |
2.4 GHz: 802.11b/g/n/ax 5 GHz: 802.11 a/n/ac/ax |
2.4 GHz: 574 Mbps 5 GHz: 2.4 Gbps |
160 MHz | - | 5GHz Only |
5GHz Only |
- | - | ||
Vigor2927ac | GbE, RJ-45 | 2x Dual-Band (3dBi for 5GHz, 2.5dBi for 2.4GHz) |
2.4 GHz: 802.11b/g/n 5 GHz: 802.11 a/n/ac |
2.4 GHz: 400 Mbps 5 GHz: 867 Mbps |
80 MHz | 5GHz Only |
5GHz Only |
- | - | |||
Vigor2927Vac | GbE, RJ-45 | 2x Dual-Band (3dBi for 5GHz, 2.5dBi for 2.4GHz) |
2.4 GHz: 802.11b/g/n 5 GHz: 802.11 a/n/ac |
2.4 GHz: 400 Mbps 5 GHz: 867 Mbps |
80 MHz | 5GHz Only |
5GHz Only |
2 | ||||
Vigor2927F | 100/1000M Fiber SFP | - | - | - | - | - | - | - | - | - |
Model |
Performance |
NAT Session | Max. NAT (Mbps) | Max. NAT with Hardware Acceleration (Mbps) | Max. NAT with Hardware Acceleration : Single WAN (Mbps) | Max. NAT with Hardware Acceleration : Dual WAN (Mbps) | Max. NAT with Software Acceleration (single-directional) (Mbps) | Max. NAT with Software Acceleration (bi-directional) (Mbps) | Max. VDSL Link Rate (Mbps) | Max. ADSL Link Rate (Mbps) | WAN |
Ethernet (GbE) | Ethernet (2.5 GbE) | Switchable WAN/LAN (GbE) | xDSL | VDSL Standards | VDSL2 Profile | G.fast Profile | ADSL Standards | Other Standards | Band Plan | SFP | SFP (WAN/LAN Switchable) | SFP/Ethernet Combo (WAN/LAN Switchable) | Cellular (via USB) | Cellular (Built-in) | Wireless WAN (2.4GHz or 5GHz) | Wireless WAN (2.4GHz + 5GHz) | 4G LTE |
LTE Category | LTE Antenna (External Dipole) | LTE Antenna Peak Gain (dBi) | SIM Slot | Max. Rx Link Rate (Mbps) | Max. Tx Link Rate (Mbps) | FDD Band | TDD Band | WCDMA (3G) Band | SMS Gateway | 5G |
5G Band | 5G Antenna Peak Gain (dBi) | 5G NSA Max. Rx Link Rate (Mbps) | 5G NSA Max. Tx Link Rate (Mbps) | 5G SA Max. Rx Link Rate (Mbps) | 5G SA Max. Tx Link Rate (Mbps) | Note | Internet Connection |
IPv4 | IPv6 | LTE WAN Bridge | 802.1p/q Multi-VLAN Tagging | Multi-VLAN/PVC | Virtual WAN | PPPoE Pass-Through | MPoA Bridge | Failover | Load Balancing | WAN Active on Demand | Connection Detection | WAN Data Budget | Dynamic DNS | DrayDDNS | LAN |
Fixed LAN (RJ-45, GbE) | LAN Subnet | DMZ Port | VLAN | Max. Number of VLAN | DHCP Server | IPv6 Address Assignment | LAN IP Alias | IP Pool Count | PPPoE Server | Wired 802.1x Authentication | Port Mirroring | Local DNS Server | Conditional DNS Forwarding | Hotspot Web Portal (Profile No.) | Hotspot Authentication | Other Ports |
Console (RJ-45) | USB | USB Type | FXS (RJ-11) | Networking |
Routing | Policy-based Routing | Smart Action | High Availability | DNS Security (DNSSEC) | IGMP | Local RADIUS server | SMB File Sharing (Requires external storage) | IAM |
Users & Groups | Access Policies | Group Policies | Conditional Access Policy | Resources | Backup and Restore | VPN |
LAN-to-LAN | Teleworker-to-LAN | Protocols | Max. VPN Tunnels | Max. OpenVPN + SSL VPN Tunnels | IPsec VPN Throughput (AES 256 bits) (single-directional) (Mbps) | IPsec VPN Throughput (Hardware NAT Enabled) | IPsec VPN Throughput (AES 256 bits) (bi-directional) (Mbps) | SSL VPN Throughput (single-directional) (Mbps) | SSL VPN Throughput (bi-directional) (Mbps) | WireGuard VPN Throughput (single-directional) (Mbps) | WireGuard VPN Throughput (bi-directional) (Mbps) | User Authentication | IKE Authentication | IPsec Authentication | Encryption | VPN Trunk (Redundancy) | Single-Armed VPN | NAT-Traversal (NAT-T) | VPN from LAN (Mainline fw only) | VPN Isolation (Mainline fw only) | VPN Packet Capture (Mainline fw only) | VPN 2FA Authentication for AD/LDAP (Mainline fw only) | VPN Matcher | Firewall & Content Filtering |
NAT | ALG (Application Layer Gateway) | VPN Pass-Through | IP-based Firewall Policy | Content Filtering | IP Reputation | DoS Attack Defense | Spoofing Defense | Linux Applications |
Suricata | VigorConnect | Bandwidth Management |
IP-based Bandwidth Limit | IP-based Session Limit | QoS (Quality of Service) | VoIP Prioritization | APP QoS | WLAN |
2.4GHz WLAN | 5GHz WLAN | Antennas | Antenna Type | Antenna Spec | 2.4GHz Antenna Gain (dBi) | 5GHz Antenna Gain (dBi) | 2.4GHz Max. Link Rate (Mbps) | 5GHz Max. Link Rate (Mbps) | Max. Number of SSIDs per band | Security Mode | Authentication | WiFi 6 | OFDMA | Roaming | WPS | WDS | Access Control | AirTime Fairness | Band Steering | WMM | Mesh (5GHz Only) | VoIP |
Protocols | SIP Registrars | Dial Plan | Call Features | Voice Codec | Caller ID | Management |
Local Service | Config Backup/Restore | Config File Compatibility | Firmware Upgrade | 2-Level Administration Privilege | Role-based Privilege | Access Control | Notification Alert | Netflow | SNMP | Syslog | Broadcast DSL Info to LAN | VPN Managment | AP Managment (APM) | Virtual AP Controller | Mesh (Number of manageable APs) | Switch Management (SWM) | Virtual Switch Controller | VigorACS Management (Since f/w) | Physical |
Power Input | Max. Power Consumption (watts) | Memory | Dimension (mm) | Operating Temperature | Storage Temperature | Operating Humidity (non-condensing) |
2927F |
K | 700 | 0 | 940 | 1800 | - | - | - | - | 0 | 1 | 0 | 1 | 0 | 0 | 2 | - | F | F | - | - | - | - | - | - | F Learn More | - | - | - | - | - | PPPoE DHCP Static IP PPTP/L2TP |
PPP DHCPv6 Static IPv6 TSPC AICCU 6rd 6in4 Static Tunnel |
F | T | T | F | F | F | T | IP-based, Session-based | Link Failure, Traffic Threshold | ARP, Strict ARP, Ping | T | T | T | 5 | 8 | 1 | 802.1q Tag-based VLAN Port-based VLAN |
16 | Multiple IP Subnet Custom DHCP Options Bind-IP-to-MAC |
T | - | F | T | T | T | T | 4 | Click-Through Social Login SMS PIN Voucher PIN RADIUS External Portal Server |
0 | 2 | 2.0 | - | IPv4 Static Route IPv6 Static Route Policy Route Inter-VLAN Route RIP v1/v2 BGP |
Protocol IP Address Port Domain Country |
F | T | T | IGMP v2/v3 IGMP Proxy IGMP Snooping & Fast Leave |
T | T | F | F | F | F | F | F | T | T | PPTP L2TP IPsec L2TP over IPsec SSL GRE IKEv2 IKEv2-EAP IPsec-XAuth OpenVPN WireGuard |
50 | 25 | 250 | 800 | - | 120 | - | 80 | - | Local RADIUS LDAP TACACS+ mOTP |
Pre-Shared Key, X.509 | SHA-1, SHA-256 | MPPE DES 3DES AES |
Load Balancing, Failover | T | T | F | F | F | F | T | Port Redirection Open Ports Port Triggering Port Knocking DMZ Host UPnP |
SIP, RTSP, FTP, H.323 | PPTP, L2TP, IPsec | T | APP URL Keyword DNS Keyword Web Features Web Category*(*subscription required) |
F | T | T | F | F | T | T | TOS DSCP 802.1p IP Address Port Application |
T | T | 0 | 0 | 0 | - | F | F | F | F | F | HTTP HTTPS Telnet SSH v2 FTP TR-069 |
T | Vigor2926 | TFTP, HTTP, TR-069 | T | F | Access List, Brute Force Protection | SMS, E-mail | v5, v9, IPFIX | v1, v2c, v3 | T | F | 8 | 20 | 0 | - | 10 | 0 | V4.2.0.1 | DC 12V @ 2A | 21.6 | - | 241 x 165 x 44 | 0 to 45°C | -25 to 70°C | 10 to 90% |
{ "NAT Session":"K", "Max. NAT (Mbps)":"700", "Max. NAT with Hardware Acceleration (Mbps)":"0", "Max. NAT with Hardware Acceleration : Single WAN (Mbps)":"940", "Max. NAT with Hardware Acceleration : Dual WAN (Mbps)":"1800", "Max. NAT with Software Acceleration (single-directional) (Mbps)":"-", "Max. NAT with Software Acceleration (bi-directional) (Mbps)":"-", "Max. VDSL Link Rate (Mbps)":"-", "Max. ADSL Link Rate (Mbps)":"-", "Ethernet (GbE)":"", "Ethernet (2.5 GbE)":"0", "Switchable WAN/LAN (GbE)":"1", "xDSL":"0", "VDSL Standards":"", "VDSL2 Profile":"", "G.fast Profile":"", "ADSL Standards":"", "Other Standards":"", "Band Plan":"", "SFP":"1", "SFP (WAN/LAN Switchable)":"0", "SFP/Ethernet Combo (WAN/LAN Switchable)":"0", "3G/4G/LTE (via USB)":"2", "3G/4G/LTE (Built-in)":"F", "Wireless WAN (2.4GHz or 5GHz)":"F", "Wireless WAN (2.4GHz + 5GHz)":"F", "LTE Category":"-", "LTE Antenna (External Dipole)":"-", "LTE Antenna Peak Gain (dBi)":"", "SIM Slot":"-", "Max. Rx Link Rate (Mbps)":"-", "Max. Tx Link Rate (Mbps)":"-", "FDD Band":"", "TDD Band":"", "WCDMA (3G) Band":"", "SMS Gateway":"F", "5G Band":"", "5G Antenna Peak Gain (dBi)":"-", "5G NSA Max. Rx Link Rate (Mbps)":"-", "5G NSA Max. Tx Link Rate (Mbps)":"-", "5G SA Max. Rx Link Rate (Mbps)":"-", "5G SA Max. Tx Link Rate (Mbps)":"-", "Note":"", "IPv4":"PPPoEDHCPStatic IPPPTP/L2TP", "IPv6":"PPPDHCPv6Static IPv6TSPCAICCU6rd6in4 Static Tunnel", "LTE WAN Bridge":"F", "802.1p/q Multi-VLAN Tagging":"T", "Multi-VLAN/PVC":"T", "Virtual WAN":"F", "PPPoE Pass-Through":"F", "MPoA Bridge":"F", "Failover":"T", "Load Balancing":"IP-based, Session-based", "WAN Active on Demand":"Link Failure, Traffic Threshold", "Connection Detection":"ARP, Strict ARP, Ping", "WAN Data Budget":"T", "Dynamic DNS":"T", "DrayDDNS":"T", "Fixed LAN (RJ-45, GbE)":"5", "LAN Subnet":"8", "DMZ Port":"1", "VLAN":"802.1q Tag-based VLANPort-based VLAN", "Max. Number of VLAN":"16", "DHCP Server":"Multiple IP SubnetCustom DHCP OptionsBind-IP-to-MAC", "IPv6 Address Assignment":"", "LAN IP Alias":"T", "IP Pool Count":"-", "PPPoE Server":"F", "Wired 802.1x Authentication":"T", "Port Mirroring":"T", "Local DNS Server":"T", "Conditional DNS Forwarding":"T", "Hotspot Web Portal (Profile No.)":"4", "Hotspot Authentication":"Click-ThroughSocial LoginSMS PINVoucher PINRADIUSExternal Portal Server", "Console (RJ-45)":"0", "USB":"2", "USB Type":"2.0", "FXS (RJ-11)":"-", "Routing":"IPv4 Static RouteIPv6 Static RoutePolicy RouteInter-VLAN RouteRIP v1/v2BGP", "Policy-based Routing":"ProtocolIP AddressPortDomainCountry", "Smart Action":"F", "High Availability":"T", "DNS Security (DNSSEC)":"T", "IGMP":"IGMP v2/v3IGMP ProxyIGMP Snooping & Fast Leave", "Local RADIUS server":"T", "SMB File Sharing (Requires external storage)":"T", "LAN-to-LAN":"T", "Teleworker-to-LAN":"T", "VPN Protocols":"PPTPL2TPIPsecL2TP over IPsecSSLGREIKEv2IKEv2-EAPIPsec-XAuthOpenVPNWireGuard", "Max. VPN":"50", "Max. OpenVPN + SSL VPN":"25", "IPsec VPN (AES 256 bits) (single-directional) (Mbps)":"250", "IPsec VPN (AES 256 bits) (bi-directional) (Mbps)":"-", "SSL VPN (single-directional) (Mbps)":"120", "SSL VPN (bi-directional) (Mbps)":"-", "Wireguard VPN (single-directional) (Mbps)":"80", "Wireguard VPN (bi-directional) (Mbps)":"-", "User Authentication":"LocalRADIUSLDAPTACACS+mOTP", "IKE Authentication":"Pre-Shared Key, X.509", "IPsec Authentication":"SHA-1, SHA-256", "Encryption":"MPPEDES3DESAES", "VPN Trunk (Redundancy)":"Load Balancing, Failover", "Single-Armed VPN":"T", "NAT-Traversal (NAT-T)":"T", "VPN from LAN (Mainline fw only)":"F", "VPN Isolation (Mainline fw only)":"F", "VPN Packet Capture (Mainline fw only)":"F", "VPN 2FA Authentication for AD/LDAP (Mainline fw only)":"F", "VPN Matcher":"T", "NAT":"Port RedirectionOpen PortsPort TriggeringPort KnockingDMZ HostUPnP", "ALG (Application Layer Gateway)":"SIP, RTSP, FTP, H.323", "VPN Pass-Through":"PPTP, L2TP, IPsec", "IP-based Firewall Policy":"T", "Content Filtering":"APPURL KeywordDNS KeywordWeb FeaturesWeb Category*(*subscription required)", "IP Reputation":"F", "DoS Attack Defense":"T", "Spoofing Defense":"T", "Suricata":"F", "VigorConnect":"F", "IP-based Bandwidth Limit":"T", "IP-based Session Limit":"T", "QoS (Quality of Service)":"TOSDSCP802.1pIP AddressPortApplication", "VoIP Prioritization":"T", "APP QoS":"T", "2.4GHz WLAN":"", "5GHz WLAN":"", "Antennas":"0", "Antenna Type":"", "Antenna Spec":"", "2.4GHz Antenna Gain (dBi)":"", "5GHz Antenna Gain (dBi)":"", "2.4GHz Max. Link Rate (Mbps) ":"0", "5GHz Max. Link Rate (Mbps)":"0", "Max. Number of SSIDs per band":"-", "Security Mode":"", "Authentication":"", "WiFi 6":"F", "OFDMA":"F", "WPS":"", "WDS":"", "Access Control WLAN":"", "AirTime Fairness":"F", "Band Steering":"F", "WMM":"F", "Mesh (5GHz Only)":"", "Protocols":"", "SIP Registrars":"", "Dial Plan":"", "Call Features":"", "Voice Codec":"", "Caller ID":"", "Local Service":"HTTPHTTPSTelnetSSH v2FTPTR-069", "Config Backup/Restore":"T", "Config File Compatibility":"Vigor2926", "Firmware Upgrade":"TFTP, HTTP, TR-069", "2-Level Administration Privilege":"T", "Role-based Privilege":"F", "Access Control":"Access List, Brute Force Protection", "Notification Alert":"SMS, E-mail", "Netflow":"v5, v9, IPFIX", "SNMP":"v1, v2c, v3", "Syslog":"T", "Broadcast DSL Info to LAN":"F", "VPN Managment":"8", "AP Managment (APM)":"20", "Virtual AP Controller":"0", "Mesh (Number of manageable APs)":"-", "Switch Management (SWM)":"10", "Virtual Switch Controller":"0", "VigorACS Management (Since f/w)":"V4.2.0.1", "Power Input":"DC 12V @ 2A", "Max. Power Consumption (watts)":"21.6", "Memory":"-", "Dimension (mm)":"241 x 165 x 44", "Weight (g)":"-", "Operating Temperature":"0 to 45°C", "Storage Temperature":"-25 to 70°C", "Operating Humidity (non-condensing)":"10 to 90%", "IAM - Users & Groups":"F", "IAM - Access Policies":"F", "IAM - Group Policies":"F", "IAM - Confidential Access Policy":"", "IAM - Resources":"F", "IAM - Backup and Restore":"F" }
Note :The stated throughput performance figures are the maximum derived from DrayTek internal testing, conducted under optimal conditions, with Hardware Acceleration enabled where available. The actual performance may vary based on network conditions and activated applications.