Vigor2962 is a high performance and dynamic firewall router with configurable WAN/LAN ports. With the selection of 2.5GbE port, 1GbE Fiber port, and 2 of 1GbE ports, users can set 4 of the ports as WAN for load balancing/failover purpose and enjoy overall 2.2Gbps NAT throughput.
including 2.5G Ethernet and SFP
IPsec VPN throughput up to 1 Gbps
Max. NAT Throughput
Recommended for a network of 250 hosts
1Power Input
2Power On/Off Switch
3Reset Button
4LED Indicator
51x 2.5G RJ-45*
61x GbE/SFP Combo*
72x GbE RJ-45*
8Fixed LAN Port: 2x GbE RJ-45
91x USB 2.0 & 1x USB 3.0
*Switchable WAN/LAN Port, up to 2 simultaneous WANs. (f/w before v4.4.3.1)
Maximize throughput and reliability by using multiple Internet connections. Learn more
Build a secure and private tunnel from the LAN of Vigor2962 to the remote offices and teleworkers over the Internet. Learn more
The VPN works through firewalls providing secure remote access to any network environment. Learn more
Helps routers behind NAT to find each other and establish a LAN-to-LAN VPN. Learn more
Use Point-to-Point connection on LAN to keep track of individual user's traffic. Setup Guide
Market your business and communicate with the guests while offering hospitality WLAN. Learn more
Prevent one device using all the bandwidth by bandwidth limit policy, session limit policy, and QoS settings.
Filter web pages by URL keyword or web category to block access to insecure or inappropriate contents.
The free DDNS service for you to access the router by a fixed hostname of your choice. Learn more
Use the Vigor2962 router as a wireless controller to maintain and monitor the VigorAPs. Learn more
Set up VLAN easily from the router and get a centralized hierarchy view of the switches. Learn more
Vigor2962 features four configurable WAN/LAN ports, including one 2.5GbE port, one SFP/GbE combo port, and two GbE ports. Up to four ports can be used as WAN port concurrently. Multi-WAN for load balancing/failover improves Internet resilience of your business.
Never trust, always verify. VPN from LAN works Zero Trust out. It provides a better security level to your network, which protects vital servers from potential threats caused by other LAN devices. The servers can only be accessed by VPN, even if the devices are on the LAN network.
Isolating remote dial-in accounts to protect VPN users from each others. They can only access company’s servers but not allowed to enter each other’s devices. This helps prevent unauthorized access to sensitive data and protect network from malware or other intrusions.
With new Two-Factor authentication, you can strength the security of VPN connections and eliminates the expense of SMS messages or license fees in a cost-effective way.
By either mirroring all packets to designated LAN port and now to VPN connection no matter LAN to LAN profile or remote Dial-in users, and even downloading .pcap file via WUI remotely, spotting an issue is easier than ever.
Hosting multiple servers to share the traffic load for the same service is common. It can avoid excessive load on a single server by distributing the load, optimizing resource usage, and preventing a single server failure.
With Server Load Balance, when massive connections enter the router, the router will distribute the inbound NAT sessions among the servers with the configured load balance weight.
Configuring NAT Port Redirection rules is the typical way to allow the internal servers to be accessible from the Internet. However, once the port opens, it is exposed to the Internet and can be scanned by the malware.
Port knocking is a technology that can add an extra layer of protection to the internal servers. Its basic idea is that only open ports are at risk of being attacked, so it allows all ports to be closed at the beginning. Do not open them, and then set a password based on the port combination. Only those who know the password can open the ports and connect.
Market your business while offering free WLAN
Redirect the hotspot guests to the company homepage, online surveys, or display promotion message.
Require the guest to leave contact info or social media accounts before they can use the Internet service.
A variety of login methods are supported to meet your business need, including Facebook Login, Google Login, SMS PIN, Voucher PIN, and RADIUS.
Supports external captive portal authentication. You can keep using the WLAN marketing solution you like.
Bandwidth management is integrated into Hotspot to control the bandwidth and session usage of the Hotspot guests.
A management platform for Vigor devices on the LAN side and offer simple and massive deployment.
Automatically discover LAN subnets and add detected VigorSwitch/AP into managed list.
Most-frequent used settings can be pre-defined on the Vigor Router, and provision to the managed VigorSwitch/AP.
Vigor Router provides a centralized view of managing devices, you may always check if the managed Vigor Switch/AP is online.
You may perform a factory reset, save/restore a configuration backup, or trigger a remote reboot directly on the Vigor Router. There’s no need to log in to each device’s management page.
Auto-Discovery, Provisioning, Monitoring, Centralized Hierarchy View, Reboot PoE Devices Remotely, Quick VLAN Configuration
Auto-Discovery, Provisioning, Monitoring, Centralized View, Alarm, Reboot VigorAP Remotely, Wi-Fi Client Load Balancing
Note :The stated throughput performance figures are the maximum derived from DrayTek internal testing, conducted under optimal conditions, with Hardware Acceleration enabled where available. The actual performance may vary based on network conditions and activated applications.
Model |
Performance |
NAT Session | Max. NAT (Mbps) | Max. NAT with Hardware Acceleration (Mbps) | Max. NAT with Hardware Acceleration : Single WAN (Mbps) | Max. NAT with Hardware Acceleration : Dual WAN (Mbps) | Max. NAT with Software Acceleration (single-directional) (Mbps) | Max. NAT with Software Acceleration (bi-directional) (Mbps) | Max. VDSL Link Rate (Mbps) | Max. ADSL Link Rate (Mbps) | WAN |
Ethernet (GbE) | Ethernet (2.5 GbE) | Switchable WAN/LAN (GbE) | xDSL | VDSL Standards | VDSL2 Profile | G.fast Profile | ADSL Standards | Other Standards | Band Plan | SFP | SFP (WAN/LAN Switchable) | SFP/Ethernet Combo (WAN/LAN Switchable) | Cellular (via USB) | Cellular (Built-in) | Wireless WAN (2.4GHz or 5GHz) | Wireless WAN (2.4GHz + 5GHz) | 4G LTE |
LTE Category | LTE Antenna (External Dipole) | LTE Antenna Peak Gain (dBi) | SIM Slot | Max. Rx Link Rate (Mbps) | Max. Tx Link Rate (Mbps) | FDD Band | TDD Band | WCDMA (3G) Band | SMS Gateway | 5G |
5G Band | 5G Antenna Peak Gain (dBi) | 5G NSA Max. Rx Link Rate (Mbps) | 5G NSA Max. Tx Link Rate (Mbps) | 5G SA Max. Rx Link Rate (Mbps) | 5G SA Max. Tx Link Rate (Mbps) | Note | Internet Connection |
IPv4 | IPv6 | LTE WAN Bridge | 802.1p/q Multi-VLAN Tagging | Multi-VLAN/PVC | Virtual WAN | PPPoE Pass-Through | MPoA Bridge | Failover | Load Balancing | WAN Active on Demand | Connection Detection | WAN Data Budget | Dynamic DNS | DrayDDNS | LAN |
Fixed LAN (RJ-45, GbE) | LAN Subnet | DMZ Port | VLAN | Max. Number of VLAN | DHCP Server | IPv6 Address Assignment | LAN IP Alias | IP Pool Count | PPPoE Server | Wired 802.1x Authentication | Port Mirroring | Local DNS Server | Conditional DNS Forwarding | Hotspot Web Portal (Profile No.) | Hotspot Authentication | Other Ports |
Console (RJ-45) | USB | USB Type | FXS (RJ-11) | Networking |
Routing | Policy-based Routing | Smart Action | High Availability | DNS Security (DNSSEC) | IGMP | Local RADIUS server | SMB File Sharing (Requires external storage) | IAM |
Users & Groups | Access Policies | Group Policies | Conditional Access Policy | Resources | Backup and Restore | VPN |
LAN-to-LAN | Teleworker-to-LAN | Protocols | Max. VPN Tunnels | Max. OpenVPN + SSL VPN Tunnels | IPsec VPN Throughput (AES 256 bits) (single-directional) (Mbps) | IPsec VPN Throughput (AES 256 bits) (bi-directional) (Mbps) | SSL VPN Throughput (single-directional) (Mbps) | SSL VPN Throughput (bi-directional) (Mbps) | Wireguard VPN Throughput (single-directional) (Mbps) | Wireguard VPN Throughput (bi-directional) (Mbps) | User Authentication | IKE Authentication | IPsec Authentication | Encryption | VPN Trunk (Redundancy) | Single-Armed VPN | NAT-Traversal (NAT-T) | VPN from LAN (Mainline fw only) | VPN Isolation (Mainline fw only) | VPN Packet Capture (Mainline fw only) | VPN 2FA Authentication for AD/LDAP (Mainline fw only) | VPN Matcher | Firewall & Content Filtering |
NAT | ALG (Application Layer Gateway) | VPN Pass-Through | IP-based Firewall Policy | Content Filtering | IP Reputation | DoS Attack Defense | Spoofing Defense | Linux Applications |
Suricata | VigorConnect | Bandwidth Management |
IP-based Bandwidth Limit | IP-based Session Limit | QoS (Quality of Service) | VoIP Prioritization | APP QoS | WLAN |
2.4GHz WLAN | 5GHz WLAN | Antennas | Antenna Type | Antenna Spec | 2.4GHz Antenna Gain (dBi) | 5GHz Antenna Gain (dBi) | 2.4GHz Max. Link Rate (Mbps) | 5GHz Max. Link Rate (Mbps) | Max. Number of SSIDs per band | Security Mode | Authentication | WiFi 6 | OFDMA | Roaming | WPS | WDS | Access Control | AirTime Fairness | Band Steering | WMM | Mesh (5GHz Only) | VoIP |
Protocols | SIP Registrars | Dial Plan | Call Features | Voice Codec | Caller ID | Management |
Local Service | Config Backup/Restore | Config File Compatibility | Firmware Upgrade | 2-Level Administration Privilege | Role-based Privilege | Access Control | Notification Alert | Netflow | SNMP | Syslog | Broadcast DSL Info to LAN | VPN Managment | AP Managment (APM) | Virtual AP Controller | Mesh (Number of manageable APs) | Switch Management (SWM) | Virtual Switch Controller | VigorACS Management (Since f/w) | Physical |
Power Input | Max. Power Consumption (watts) | Memory | Dimension (mm) | Operating Temperature | Storage Temperature | Operating Humidity (non-condensing) |
Vigor2962 |
K | 0 | 0 | 0 | 2200 | - | - | - | 0 | 0 | 3 | 0 | 0 | 0 | 1 | - | - | F | F | - | - | - | - | - | - | F Learn More | - | - | - | - | - | PPPoE DHCP Static IP |
PPP DHCPv6 Static IPv6 TSPC AICCU 6rd 6in4 Static Tunnel |
F | T | T | F | F | F | T | IP-based, Session-based | Link Failure, Traffic Threshold | ARP, Strict ARP, Ping | T | T | T | 2 | 20 | - | 802.1q Tag-based VLAN Port-based VLAN |
20 | Multiple IP Subnet Custom DHCP Options Bind-IP-to-MAC |
T | - | F | T | T | T | T | 4 | Click-Through Social Login SMS PIN RADIUS External Portal Server |
0 | 2 | 2.0 + 3.0 | - | IPv4 Static Route IPv6 Static Route Policy Route Inter-VLAN Route RIP v1/v2 BGP OSPF |
Protocol IP Address Port Domain Country |
T | T | T | IGMP v2/v3 IGMP Proxy IGMP Snooping & Fast Leave |
T | F | F | F | F | F | F | F | T | T | PPTP L2TP IPsec L2TP over IPsec SSL GRE IKEv2 IKEv2-EAP IPsec-XAuth OpenVPN(Host to LAN) Wireguard |
200 | 50 | 1000 | - | 800 | - | - | - | Local RADIUS LDAP TACACS+ mOTP TOTP |
Pre-Shared Key, X.509 | SHA-1, SHA-256, SHA-512, MD5 | MPPE DES 3DES AES |
Load Balancing, Failover | T | T | T | T | T | T | T | Port Redirection Open Ports Port Triggering DMZ Host UPnP |
SIP, RTSP, FTP, H.323 | PPTP, L2TP | T | APP URL Keyword DNS Keyword Web Features Web Category*(*subscription required) |
F | T | T | F | F | T | T | TOS DSCP 802.1p IP Address Service Type |
T | T | 0 | 0 | 0 | - | F | F | F | F | F | - | HTTP HTTPS Telnet SSH v2 FTP TR-069 |
T | - | TFTP, HTTP, TR-069 | T | F | Access List, Brute Force Protection | SMS, E-mail | v1, v2c, v3 | T | F | 0 | 50 | 0 | - | 30 | 0 | V3.9.3 | AC 110-220V @ 1A | 15 | - | 273 x 171 x 45 | 0 to 45°C | -25 to 70°C | 10 to 90% |
{ "NAT Session":"K", "Max. NAT (Mbps)":"", "Max. NAT with Hardware Acceleration (Mbps)":"0", "Max. NAT with Hardware Acceleration : Single WAN (Mbps)":"0", "Max. NAT with Hardware Acceleration : Dual WAN (Mbps)":"0", "Max. NAT with Software Acceleration (single-directional) (Mbps)":"2200", "Max. NAT with Software Acceleration (bi-directional) (Mbps)":"-", "Max. VDSL Link Rate (Mbps)":"-", "Max. ADSL Link Rate (Mbps)":"-", "Ethernet (GbE)":"0", "Ethernet (2.5 GbE)":"0", "Switchable WAN/LAN (GbE)":"3", "xDSL":"0", "VDSL Standards":"", "VDSL2 Profile":"", "G.fast Profile":"", "ADSL Standards":"", "Other Standards":"", "Band Plan":"", "SFP":"0", "SFP (WAN/LAN Switchable)":"0", "SFP/Ethernet Combo (WAN/LAN Switchable)":"1", "3G/4G/LTE (via USB)":"-", "3G/4G/LTE (Built-in)":"F", "Wireless WAN (2.4GHz or 5GHz)":"F", "Wireless WAN (2.4GHz + 5GHz)":"F", "LTE Category":"-", "LTE Antenna (External Dipole)":"-", "LTE Antenna Peak Gain (dBi)":"", "SIM Slot":"-", "Max. Rx Link Rate (Mbps)":"-", "Max. Tx Link Rate (Mbps)":"-", "FDD Band":"", "TDD Band":"", "WCDMA (3G) Band":"", "SMS Gateway":"F", "5G Band":"", "5G Antenna Peak Gain (dBi)":"-", "5G NSA Max. Rx Link Rate (Mbps)":"-", "5G NSA Max. Tx Link Rate (Mbps)":"-", "5G SA Max. Rx Link Rate (Mbps)":"-", "5G SA Max. Tx Link Rate (Mbps)":"-", "Note":"", "IPv4":"PPPoEDHCPStatic IP", "IPv6":"PPPDHCPv6Static IPv6TSPCAICCU6rd6in4 Static Tunnel", "LTE WAN Bridge":"F", "802.1p/q Multi-VLAN Tagging":"T", "Multi-VLAN/PVC":"T", "Virtual WAN":"F", "PPPoE Pass-Through":"F", "MPoA Bridge":"F", "Failover":"T", "Load Balancing":"IP-based, Session-based", "WAN Active on Demand":"Link Failure, Traffic Threshold", "Connection Detection":"ARP, Strict ARP, Ping", "WAN Data Budget":"T", "Dynamic DNS":"T", "DrayDDNS":"T", "Fixed LAN (RJ-45, GbE)":"2", "LAN Subnet":"20", "DMZ Port":"-", "VLAN":"802.1q Tag-based VLANPort-based VLAN", "Max. Number of VLAN":"20", "DHCP Server":"Multiple IP SubnetCustom DHCP OptionsBind-IP-to-MAC", "IPv6 Address Assignment":"", "LAN IP Alias":"T", "IP Pool Count":"-", "PPPoE Server":"F", "Wired 802.1x Authentication":"T", "Port Mirroring":"T", "Local DNS Server":"T", "Conditional DNS Forwarding":"T", "Hotspot Web Portal (Profile No.)":"4", "Hotspot Authentication":"Click-ThroughSocial LoginSMS PINRADIUSExternal Portal Server", "Console (RJ-45)":"0", "USB":"2", "USB Type":"2.0 + 3.0", "FXS (RJ-11)":"-", "Routing":"IPv4 Static RouteIPv6 Static RoutePolicy RouteInter-VLAN RouteRIP v1/v2BGPOSPF", "Policy-based Routing":"ProtocolIP AddressPortDomainCountry", "Smart Action":"T", "High Availability":"T", "DNS Security (DNSSEC)":"T", "IGMP":"IGMP v2/v3IGMP ProxyIGMP Snooping & Fast Leave", "Local RADIUS server":"T", "SMB File Sharing (Requires external storage)":"F", "LAN-to-LAN":"T", "Teleworker-to-LAN":"T", "VPN Protocols":"PPTPL2TPIPsecL2TP over IPsecSSLGREIKEv2IKEv2-EAPIPsec-XAuthOpenVPN(Host to LAN)Wireguard", "Max. VPN":"200", "Max. OpenVPN + SSL VPN":"50", "IPsec VPN (AES 256 bits) (single-directional) (Mbps)":"1000", "IPsec VPN (AES 256 bits) (bi-directional) (Mbps)":"-", "SSL VPN (single-directional) (Mbps)":"800", "SSL VPN (bi-directional) (Mbps)":"-", "Wireguard VPN (single-directional) (Mbps)":"-", "Wireguard VPN (bi-directional) (Mbps)":"-", "User Authentication":"LocalRADIUSLDAPTACACS+mOTPTOTP", "IKE Authentication":"Pre-Shared Key, X.509", "IPsec Authentication":"SHA-1, SHA-256, SHA-512, MD5", "Encryption":"MPPEDES3DESAES", "VPN Trunk (Redundancy)":"Load Balancing, Failover", "Single-Armed VPN":"T", "NAT-Traversal (NAT-T)":"T", "VPN from LAN (Mainline fw only)":"T", "VPN Isolation (Mainline fw only)":"T", "VPN Packet Capture (Mainline fw only)":"T", "VPN 2FA Authentication for AD/LDAP (Mainline fw only)":"T", "VPN Matcher":"T", "NAT":"Port RedirectionOpen PortsPort TriggeringDMZ HostUPnP", "ALG (Application Layer Gateway)":"SIP, RTSP, FTP, H.323", "VPN Pass-Through":"PPTP, L2TP", "IP-based Firewall Policy":"T", "Content Filtering":"APPURL KeywordDNS KeywordWeb FeaturesWeb Category*(*subscription required)", "IP Reputation":"F", "DoS Attack Defense":"T", "Spoofing Defense":"T", "Suricata":"F", "VigorConnect":"F", "IP-based Bandwidth Limit":"T", "IP-based Session Limit":"T", "QoS (Quality of Service)":"TOSDSCP802.1pIP AddressService Type", "VoIP Prioritization":"T", "APP QoS":"T", "2.4GHz WLAN":"", "5GHz WLAN":"", "Antennas":"0", "Antenna Type":"", "Antenna Spec":"", "2.4GHz Antenna Gain (dBi)":"", "5GHz Antenna Gain (dBi)":"", "2.4GHz Max. Link Rate (Mbps) ":"0", "5GHz Max. Link Rate (Mbps)":"0", "Max. Number of SSIDs per band":"-", "Security Mode":"", "Authentication":"", "WiFi 6":"F", "OFDMA":"F", "WPS":"", "WDS":"", "Access Control WLAN":"", "AirTime Fairness":"F", "Band Steering":"F", "WMM":"F", "Mesh (5GHz Only)":"", "Protocols":"", "SIP Registrars":"-", "Dial Plan":"", "Call Features":"", "Voice Codec":"", "Caller ID":"", "Local Service":"HTTPHTTPSTelnetSSH v2FTPTR-069", "Config Backup/Restore":"T", "Config File Compatibility":"-", "Firmware Upgrade":"TFTP, HTTP, TR-069", "2-Level Administration Privilege":"T", "Role-based Privilege":"F", "Access Control":"Access List, Brute Force Protection", "Notification Alert":"SMS, E-mail", "Netflow":"", "SNMP":"v1, v2c, v3", "Syslog":"T", "Broadcast DSL Info to LAN":"F", "VPN Managment":"0", "AP Managment (APM)":"50", "Virtual AP Controller":"0", "Mesh (Number of manageable APs)":"-", "Switch Management (SWM)":"30", "Virtual Switch Controller":"0", "VigorACS Management (Since f/w)":"V3.9.3", "Power Input":"AC 110-220V @ 1A", "Max. Power Consumption (watts)":"15", "Memory":"-", "Dimension (mm)":"273 x 171 x 45", "Weight (g)":"-", "Operating Temperature":"0 to 45°C", "Storage Temperature":"-25 to 70°C", "Operating Humidity (non-condensing)":"10 to 90%", "IAM - Users & Groups":"F", "IAM - Access Policies":"F", "IAM - Group Policies":"F", "IAM - Confidential Access Policy":"", "IAM - Resources":"F", "IAM - Backup and Restore":"F" }
Note :The stated throughput performance figures are the maximum derived from DrayTek internal testing, conducted under optimal conditions, with Hardware Acceleration enabled where available. The actual performance may vary based on network conditions and activated applications.