Vigor3910 is capable for bandwidth demanding network. The router features a powerful quad-core processor, eight WAN interfaces, including two 10G SFP+ for fiber connectivity, two 2.5G Ethernet, RJ-45, and four Gigabit Ethernet, RJ-45, gives you NAT throughput up to 9 Gbps. All of WAN ports are switchable between WAN and LAN to provide Network Administrator with the flexibility to make the most out of the router. In addition, the router has four Gigabit Ethernet, RJ-45 as a fixed LAN interface.
including 10G SFP+ and 2.5G Ethernet
provides 9 Gbps NAT throughput
provides 2.5 Gbps IPsec throughput
Reserve 2048 entries for Bind-IP-to-MAC
12x USB 3.0
2Reset Button
3RJ-45 Console Port
42x 10G/2.5G/1G SFP+ Port*
52x 2.5G/1G/100M Base-T, RJ-45*
64x 1G/100M/10M Base-T, RJ-45*
74x 1G/100M/10M Base-T, RJ-45
*WAN/LAN Switchable
With 8 configurable WAN/LAN ports, including 10G SFP+, 2.5GbE, 1GbE, Vigor3910 is designed to grow with your business.
Supporting 500 concurrent VPN tunnels for branches (LAN-to-LAN) and remote workers (remote dial-in).
Dialing up 500 IPSec tunnels within 80 seconds!
Supporting exporting and importing editable plaintext configuration file.
By either mirroring all packets to designated LAN port or downloading .pcap file via WUI remotely, spotting an issue is easier than ever.
All sessions accelerate without sacrificing either QoS or Bandwidth Limit functionality.
Offer excellent performance for bandwidth-demanding enterprise networks.
Provides 2x 10G-capable fiber SFP ports for WAN or LAN connection.
Maximize throughput and reliability by using multiple Internet connections. Learn more
Build a secure and private tunnel from the LAN of Vigor3910 to the remote offices and teleworkers over the Internet. Learn more
The VPN works through firewalls providing secure remote access to any network environment. Learn more
Helps routers behind NAT to find each other and establish a LAN-to-LAN VPN. Learn more
Use Point-to-Point connection on LAN to keep track of individual user's traffic. Setup Guide
Market your business and communicate with the guests while offering hospitality WLAN. Learn more
Prevent one device using all the bandwidth by bandwidth limit policy, session limit policy, and QoS settings.
Filter web pages by URL keyword or web category to block access to insecure or inappropriate contents.
The free DDNS service for you to access the router by a fixed hostname of your choice. Learn more
Use the Vigor3910 router as a wireless controller to maintain and monitor the VigorAPs. Learn more
Set up VLAN easily from the router and get a centralized hierarchy view of the switches. Learn more
An ideal choice to work with tier 2/3 ISPs and co-working spaces
For both NAT and routing network, and for both 10G-WAN and 10G-LAN, Vigor3910 is ready to deliver high throughput to your business.
With the most popular Exterior and Interior Gateway Protocols, Vigor3910 is ideal for ISP deployment.
With 200 PPPoE user accounts and 50 VLAN/LAN subnets, Vigor3910 provides up to 9 Gbps throughput, and makes subletting network infrastructure secure and easy.
Never trust, always verify. VPN from LAN works Zero Trust out. It provides a better security level to your network, which protects vital servers from potential threats caused by other LAN devices. The servers can only be accessed by VPN, even if the devices are on the LAN network.
Isolating remote dial-in accounts to protect VPN users from each others. They can only access company’s servers but not allowed to enter each other’s devices. This helps prevent unauthorized access to sensitive data and protect network from malware or other intrusions.
With new Two-Factor authentication, you can strength the security of VPN connections and eliminates the expense of SMS messages or license fees in a cost-effective way.
By either mirroring all packets to designated LAN port and now to VPN connection no matter LAN to LAN profile or remote Dial-in users, and even downloading .pcap file via WUI remotely, spotting an issue is easier than ever.
Hosting multiple servers to share the traffic load for the same service is common. It can avoid excessive load on a single server by distributing the load, optimizing resource usage, and preventing a single server failure.
With Server Load Balance, when massive connections enter the router, the router will distribute the inbound NAT sessions among the servers with the configured load balance weight.
Configuring NAT Port Redirection rules is the typical way to allow the internal servers to be accessible from the Internet. However, once the port opens, it is exposed to the Internet and can be scanned by the malware.
Port knocking is a technology that can add an extra layer of protection to the internal servers. Its basic idea is that only open ports are at risk of being attacked, so it allows all ports to be closed at the beginning. Do not open them, and then set a password based on the port combination. Only those who know the password can open the ports and connect.
Vigor Router provides a management platform for your Vigor Devices on the LAN
Automatically discover LAN subnets and add detected VigorSwitch/AP into managed list.
Most-frequent used settings can be pre-defined on the Vigor Router, and provision to the managed VigorSwitch/AP.
Vigor Router provides a centralized view of managing devices, you may always check if the managed Vigor Switch/AP is online.
Support basic maintenance remotely via Vigor Router. Such as remote reboot, factory reset, configuration backup/restore, etc.
Auto-Discovery, Provisioning, Monitoring, Centralized Hierarchy View, Reboot PoE Devices Remotely, Quick VLAN Configuration
Auto-Discovery, Provisioning, Monitoring, Centralized View, Alarm, Reboot VigorAP Remotely, Wi-Fi Client Load Balancing
Note :The stated throughput performance figures are the maximum derived from DrayTek internal testing, conducted under optimal conditions, with Hardware Acceleration enabled where available. The actual performance may vary based on network conditions and activated applications.
Model |
Performance |
NAT Session | Max. NAT (Mbps) | Max. NAT with Hardware Acceleration (Mbps) | Max. NAT with Hardware Acceleration : Single WAN (Mbps) | Max. NAT with Hardware Acceleration : Dual WAN (Mbps) | Max. NAT with Software Acceleration (single-directional) (Mbps) | Max. NAT with Software Acceleration (bi-directional) (Mbps) | Max. VDSL Link Rate (Mbps) | Max. ADSL Link Rate (Mbps) | WAN |
Ethernet (GbE) | Ethernet (2.5 GbE) | Switchable WAN/LAN (GbE) | xDSL | VDSL Standards | VDSL2 Profile | G.fast Profile | ADSL Standards | Other Standards | Band Plan | SFP | SFP (WAN/LAN Switchable) | SFP/Ethernet Combo (WAN/LAN Switchable) | Cellular (via USB) | Cellular (Built-in) | Wireless WAN (2.4GHz or 5GHz) | Wireless WAN (2.4GHz + 5GHz) | 4G LTE |
LTE Category | LTE Antenna (External Dipole) | LTE Antenna Peak Gain (dBi) | SIM Slot | Max. Rx Link Rate (Mbps) | Max. Tx Link Rate (Mbps) | FDD Band | TDD Band | WCDMA (3G) Band | SMS Gateway | 5G |
5G Band | 5G Antenna Peak Gain (dBi) | 5G NSA Max. Rx Link Rate (Mbps) | 5G NSA Max. Tx Link Rate (Mbps) | 5G SA Max. Rx Link Rate (Mbps) | 5G SA Max. Tx Link Rate (Mbps) | Note | Internet Connection |
IPv4 | IPv6 | LTE WAN Bridge | 802.1p/q Multi-VLAN Tagging | Multi-VLAN/PVC | Virtual WAN | PPPoE Pass-Through | MPoA Bridge | Failover | Load Balancing | WAN Active on Demand | Connection Detection | WAN Data Budget | Dynamic DNS | DrayDDNS | LAN |
Fixed LAN (RJ-45, GbE) | LAN Subnet | DMZ Port | VLAN | Max. Number of VLAN | DHCP Server | IPv6 Address Assignment | LAN IP Alias | IP Pool Count | PPPoE Server | Wired 802.1x Authentication | Port Mirroring | Local DNS Server | Conditional DNS Forwarding | Hotspot Web Portal (Profile No.) | Hotspot Authentication | Other Ports |
Console (RJ-45) | USB | USB Type | FXS (RJ-11) | Networking |
Routing | Policy-based Routing | Smart Action | High Availability | DNS Security (DNSSEC) | IGMP | Local RADIUS server | SMB File Sharing (Requires external storage) | IAM |
Users & Groups | Access Policies | Group Policies | Conditional Access Policy | Resources | Backup and Restore | VPN |
LAN-to-LAN | Teleworker-to-LAN | Protocols | Max. VPN Tunnels | Max. OpenVPN + SSL VPN Tunnels | IPsec VPN Throughput (AES 256 bits) (single-directional) (Mbps) | IPsec VPN Throughput (AES 256 bits) (bi-directional) (Mbps) | SSL VPN Throughput (single-directional) (Mbps) | SSL VPN Throughput (bi-directional) (Mbps) | Wireguard VPN Throughput (single-directional) (Mbps) | Wireguard VPN Throughput (bi-directional) (Mbps) | User Authentication | IKE Authentication | IPsec Authentication | Encryption | VPN Trunk (Redundancy) | Single-Armed VPN | NAT-Traversal (NAT-T) | VPN from LAN (Mainline fw only) | VPN Isolation (Mainline fw only) | VPN Packet Capture (Mainline fw only) | VPN 2FA Authentication for AD/LDAP (Mainline fw only) | VPN Matcher | Firewall & Content Filtering |
NAT | ALG (Application Layer Gateway) | VPN Pass-Through | IP-based Firewall Policy | Content Filtering | IP Reputation | DoS Attack Defense | Spoofing Defense | Linux Applications |
Suricata | VigorConnect | Bandwidth Management |
IP-based Bandwidth Limit | IP-based Session Limit | QoS (Quality of Service) | VoIP Prioritization | APP QoS | WLAN |
2.4GHz WLAN | 5GHz WLAN | Antennas | Antenna Type | Antenna Spec | 2.4GHz Antenna Gain (dBi) | 5GHz Antenna Gain (dBi) | 2.4GHz Max. Link Rate (Mbps) | 5GHz Max. Link Rate (Mbps) | Max. Number of SSIDs per band | Security Mode | Authentication | WiFi 6 | OFDMA | Roaming | WPS | WDS | Access Control | AirTime Fairness | Band Steering | WMM | Mesh (5GHz Only) | VoIP |
Protocols | SIP Registrars | Dial Plan | Call Features | Voice Codec | Caller ID | Management |
Local Service | Config Backup/Restore | Config File Compatibility | Firmware Upgrade | 2-Level Administration Privilege | Role-based Privilege | Access Control | Notification Alert | Netflow | SNMP | Syslog | Broadcast DSL Info to LAN | VPN Managment | AP Managment (APM) | Virtual AP Controller | Mesh (Number of manageable APs) | Switch Management (SWM) | Virtual Switch Controller | VigorACS Management (Since f/w) | Physical |
Power Input | Max. Power Consumption (watts) | Memory | Dimension (mm) | Operating Temperature | Storage Temperature | Operating Humidity (non-condensing) |
Vigor3910 |
K ( 500K since f/w v4.4.3) | 0 | 0 | 0 | 9000 | - | - | - | 0 | 0 | 6 | 0 | 0 | 2 | 0 | - | - | - | F | - | - | - | - | - | - | F Learn More | - | - | - | - | - | PPPoE DHCP Static IP |
PPP DHCPv6 Static IPv6 TSPC AICCU 6rd 6in4 Static Tunnel |
F | T | T | F | F | F | T | IP-based, Session-based | Link Failure, Traffic Threshold | ARP, Ping, Strict ARP | T | T | T | 4 | 100 | - | 802.1q Tag-based VLAN Port-based VLAN |
100 | Multiple IP Subnet Custom DHCP Options Bind-IP-to-MAC |
T | 4000 | T | F | T | T | T | 4 | Click-Through Social Login SMS PIN RADIUS External Portal Server |
1 | 2 | 3.0 | - | IPv4 Static Route IPv6 Static Route Policy Route Inter-VLAN Route RIP v1/v2 BGP OSPFv2 |
Protocol IP Address Port Domain Country |
T | T | T | IGMP v2/v3 IGMP Proxy IGMP Snooping & Fast Leave |
T | F | F | F | F | F | F | F | T | T | PPTP L2TP IPsec L2TP over IPsec SSL GRE IKEv2 IPsec-XAuth OpenVPN(Host to LAN) Wireguard |
500 | 200 | 2500 | - | 1300 | - | - | - | Local RADIUS LDAP TACACS+ mOTP TOTP |
Pre-Shared Key, X.509, XAuth, EAP | SHA-1, SHA-256, SHA-512, MD5 | MPPE DES 3DES AES |
Load Balancing, Failover | T | T | T | T | T | T | T | Port Redirection Open Ports Port Triggering DMZ Host UPnP |
SIP, RTSP, FTP, H.323 | PPTP, L2TP, IPsec | T | APP URL Keyword DNS Keyword Web Features Web Category*(*subscription required) |
F | T | T | F | F | T | T | TOS DSCP 802.1p IP Address Service Type |
T | T | 0 | 0 | 0 | - | F | F | F | F | F | - | HTTP HTTPS Telnet SSH v2 FTP TR-069 |
T | - | TFTP, HTTP, TR-069 | T | F | Access List, Brute Force Protection | SMS, E-mail | v1, v2c, v3 | T | F | 0 | 50 | 0 | - | 30 | 0 | V3.9.2 | AC 110~220V @ 1A | 35 | - | 443 x 285 x 45 | 0 to 45°C | -10 to 55°C | 10 to 90% |
{ "NAT Session":"K", "Max. NAT (Mbps)":"", "Max. NAT with Hardware Acceleration (Mbps)":"0", "Max. NAT with Hardware Acceleration : Single WAN (Mbps)":"0", "Max. NAT with Hardware Acceleration : Dual WAN (Mbps)":"0", "Max. NAT with Software Acceleration (single-directional) (Mbps)":"9000", "Max. NAT with Software Acceleration (bi-directional) (Mbps)":"-", "Max. VDSL Link Rate (Mbps)":"-", "Max. ADSL Link Rate (Mbps)":"-", "Ethernet (GbE)":"0", "Ethernet (2.5 GbE)":"0", "Switchable WAN/LAN (GbE)":"6", "xDSL":"0", "VDSL Standards":"", "VDSL2 Profile":"", "G.fast Profile":"", "ADSL Standards":"", "Other Standards":"", "Band Plan":"", "SFP":"0", "SFP (WAN/LAN Switchable)":"2", "SFP/Ethernet Combo (WAN/LAN Switchable)":"0", "3G/4G/LTE (via USB)":"-", "3G/4G/LTE (Built-in)":"-", "Wireless WAN (2.4GHz or 5GHz)":"-", "Wireless WAN (2.4GHz + 5GHz)":"F", "LTE Category":"-", "LTE Antenna (External Dipole)":"-", "LTE Antenna Peak Gain (dBi)":"", "SIM Slot":"-", "Max. Rx Link Rate (Mbps)":"-", "Max. Tx Link Rate (Mbps)":"-", "FDD Band":"", "TDD Band":"", "WCDMA (3G) Band":"", "SMS Gateway":"F", "5G Band":"", "5G Antenna Peak Gain (dBi)":"-", "5G NSA Max. Rx Link Rate (Mbps)":"-", "5G NSA Max. Tx Link Rate (Mbps)":"-", "5G SA Max. Rx Link Rate (Mbps)":"-", "5G SA Max. Tx Link Rate (Mbps)":"-", "Note":"", "IPv4":"PPPoEDHCPStatic IP", "IPv6":"PPPDHCPv6Static IPv6TSPCAICCU6rd6in4 Static Tunnel", "LTE WAN Bridge":"F", "802.1p/q Multi-VLAN Tagging":"T", "Multi-VLAN/PVC":"T", "Virtual WAN":"F", "PPPoE Pass-Through":"F", "MPoA Bridge":"F", "Failover":"T", "Load Balancing":"IP-based, Session-based", "WAN Active on Demand":"Link Failure, Traffic Threshold", "Connection Detection":"ARP, Ping, Strict ARP", "WAN Data Budget":"T", "Dynamic DNS":"T", "DrayDDNS":"T", "Fixed LAN (RJ-45, GbE)":"4", "LAN Subnet":"100", "DMZ Port":"-", "VLAN":"802.1q Tag-based VLANPort-based VLAN", "Max. Number of VLAN":"100", "DHCP Server":"Multiple IP SubnetCustom DHCP OptionsBind-IP-to-MAC", "IPv6 Address Assignment":"", "LAN IP Alias":"T", "IP Pool Count":"4000", "PPPoE Server":"T", "Wired 802.1x Authentication":"F", "Port Mirroring":"T", "Local DNS Server":"T", "Conditional DNS Forwarding":"T", "Hotspot Web Portal (Profile No.)":"4", "Hotspot Authentication":"Click-ThroughSocial LoginSMS PINRADIUSExternal Portal Server", "Console (RJ-45)":"1", "USB":"2", "USB Type":"3.0", "FXS (RJ-11)":"-", "Routing":"IPv4 Static RouteIPv6 Static RoutePolicy RouteInter-VLAN RouteRIP v1/v2BGPOSPFv2", "Policy-based Routing":"ProtocolIP AddressPortDomainCountry", "Smart Action":"T", "High Availability":"T", "DNS Security (DNSSEC)":"T", "IGMP":"IGMP v2/v3IGMP ProxyIGMP Snooping & Fast Leave", "Local RADIUS server":"T", "SMB File Sharing (Requires external storage)":"F", "LAN-to-LAN":"T", "Teleworker-to-LAN":"T", "VPN Protocols":"PPTPL2TPIPsecL2TP over IPsecSSLGREIKEv2IPsec-XAuthOpenVPN(Host to LAN)Wireguard", "Max. VPN":"500", "Max. OpenVPN + SSL VPN":"200", "IPsec VPN (AES 256 bits) (single-directional) (Mbps)":"2500", "IPsec VPN (AES 256 bits) (bi-directional) (Mbps)":"-", "SSL VPN (single-directional) (Mbps)":"1300", "SSL VPN (bi-directional) (Mbps)":"-", "Wireguard VPN (single-directional) (Mbps)":"-", "Wireguard VPN (bi-directional) (Mbps)":"-", "User Authentication":"LocalRADIUSLDAPTACACS+mOTPTOTP", "IKE Authentication":"Pre-Shared Key, X.509, XAuth, EAP", "IPsec Authentication":"SHA-1, SHA-256, SHA-512, MD5", "Encryption":"MPPEDES3DESAES", "VPN Trunk (Redundancy)":"Load Balancing, Failover", "Single-Armed VPN":"T", "NAT-Traversal (NAT-T)":"T", "VPN from LAN (Mainline fw only)":"T", "VPN Isolation (Mainline fw only)":"T", "VPN Packet Capture (Mainline fw only)":"T", "VPN 2FA Authentication for AD/LDAP (Mainline fw only)":"T", "VPN Matcher":"T", "NAT":"Port RedirectionOpen PortsPort TriggeringDMZ HostUPnP", "ALG (Application Layer Gateway)":"SIP, RTSP, FTP, H.323", "VPN Pass-Through":"PPTP, L2TP, IPsec", "IP-based Firewall Policy":"T", "Content Filtering":"APPURL KeywordDNS KeywordWeb FeaturesWeb Category*(*subscription required)", "IP Reputation":"F", "DoS Attack Defense":"T", "Spoofing Defense":"T", "Suricata":"F", "VigorConnect":"F", "IP-based Bandwidth Limit":"T", "IP-based Session Limit":"T", "QoS (Quality of Service)":"TOSDSCP802.1pIP AddressService Type", "VoIP Prioritization":"T", "APP QoS":"T", "2.4GHz WLAN":"", "5GHz WLAN":"", "Antennas":"0", "Antenna Type":"", "Antenna Spec":"", "2.4GHz Antenna Gain (dBi)":"", "5GHz Antenna Gain (dBi)":"", "2.4GHz Max. Link Rate (Mbps) ":"0", "5GHz Max. Link Rate (Mbps)":"0", "Max. Number of SSIDs per band":"-", "Security Mode":"", "Authentication":"", "WiFi 6":"F", "OFDMA":"F", "WPS":"", "WDS":"", "Access Control WLAN":"", "AirTime Fairness":"F", "Band Steering":"F", "WMM":"F", "Mesh (5GHz Only)":"", "Protocols":"", "SIP Registrars":"-", "Dial Plan":"", "Call Features":"", "Voice Codec":"", "Caller ID":"", "Local Service":"HTTPHTTPSTelnetSSH v2FTPTR-069", "Config Backup/Restore":"T", "Config File Compatibility":"-", "Firmware Upgrade":"TFTP, HTTP, TR-069", "2-Level Administration Privilege":"T", "Role-based Privilege":"F", "Access Control":"Access List, Brute Force Protection", "Notification Alert":"SMS, E-mail", "Netflow":"", "SNMP":"v1, v2c, v3", "Syslog":"T", "Broadcast DSL Info to LAN":"F", "VPN Managment":"0", "AP Managment (APM)":"50", "Virtual AP Controller":"0", "Mesh (Number of manageable APs)":"-", "Switch Management (SWM)":"30", "Virtual Switch Controller":"0", "VigorACS Management (Since f/w)":"V3.9.2", "Power Input":"AC 110~220V @ 1A", "Max. Power Consumption (watts)":"35", "Memory":"-", "Dimension (mm)":"443 x 285 x 45", "Weight (g)":"3230", "Operating Temperature":"0 to 45°C", "Storage Temperature":"-10 to 55°C", "Operating Humidity (non-condensing)":"10 to 90%", "IAM - Users & Groups":"F", "IAM - Access Policies":"F", "IAM - Group Policies":"F", "IAM - Confidential Access Policy":"", "IAM - Resources":"F", "IAM - Backup and Restore":"F" }
Note :The stated throughput performance figures are the maximum derived from DrayTek internal testing, conducted under optimal conditions, with Hardware Acceleration enabled where available. The actual performance may vary based on network conditions and activated applications.