Multi-Subnet security router
- 4-Port Gigabit WAN with load balance and redundancy to guarantee business essential data exchange
- Extra USB port for 3.5G mobile WAN or FTP/printer servers
- WAN/USB 3.5G ports enable user-defined WAN redundancy and Load Balance policy
- 1-Port Gigabit LAN switch facilitating the execution of unified communication applications in business CO/remote site
- Multiple Private LAN Subnets(Multi-Subnets)
- Firewall with SPI based IP filters, Dos/DDoS prevention, and Object-based policy for easy settings
- Enterprise level Content Security Management (CSM)
- VPN with 64 hardware-based tunnels on comprehensive VPN protocols; up to 40Mbps IPSec throughput
- Support VPN Backup and Load Balance (VPN Trunking) for WAN1 and WAN2
- Support up to 10 concurrent SSL VPN tunnels
- Active Directory/LDAP Group Management for VPN remote dial-in authentication
- Network management features including CLI/Telnet/SSH, Diagnostic tables, SNMP, 2-level Access Control, TR-069, TR-104 management, etc
- Network features including call scheduling, RADIUS support, UPnP, VLAN, QoS, Packet Forward Acceleration, etc
- Support IPv6 and IPv4 network
- Smart Monitor Traffic Analyzer (Up to 100 nodes)
- GlobalView Web Content Filter powered by CYREN-90
* Vigor3200 only
- GlobalView Web Content Filter powered by Commtouch
* Vigor3200n only
- ACS SI
- WLAN * Vigor3200n only
- 802.11n * Vigor3200n only
Features of the Vigor3200 series Multi-Subnet security routers will satisfy the network requirements of small to medium business networks. Its Multi-Subnet interface with Multi-VLAN function allows users to easily divide network into different sections based on applications, such as VoIP, web or ftp server or user groups, such as Sales, Technical Support or HR dept. Each usage/application or user group can get its dedicated bandwidth and administrator can have security control between user groups for preventing possible data leakage.
Models & Connectors
|Temperature||Operating : 0°C ~ 45°C
Storage : -25°C ~ 70°C
|Humidity||10% ~ 90% ( non-condensing )|
|Power Adapter||DC 15V / 1.34A|
|Max. Power||10 watt|
|Dimension||L241 * W165 * H44 ( mm )|
All these 4xGbps WAN ports support current xDSL/Cable/Satellite broadband and the USB port also allows connection to the 3.5G Mobile Broadband. The WAN ports can be configured to increase data throughput, backup each other (Failover mode), or share the traffic (Load Balance). If you have your own Web server, FTP server and mail server, the 4 WAN ports will provide additional bandwidth for customers. In addition, the 1xGbps LAN port switch compatible with PoE switch (e.g. VigorSwitch P2260) and Gigabit switch (e.g. VigorSwitch G2080/G2240) can support large data transfer and connect to multiple client devices (PC/servers) in small to medium LAN networks.
Vigor3200 series embedded with tag-based multi-subnet function can maximize the investment of your obtained bandwidth. For example, you can allocate your 100Mbps broadband connection(s) to timing critical applications such as VoIP, web or ftp severs and business essential departments such as Sales and Technical Support team. You additional low monthly fee DSL or cable line can be used by mail server or HR team which don’t need fast data/voice packet transmission for daily operation. SMB can get highly cost-effective and secure network as adopting Vigor3200 series.
The capability of the USB port to connect to 3.5G mobile broadband means that the router can be used in anywhere with 3.5G coverage, such as moving vehicles, temporary events, offices where xDSL or Cable are not available, etc.
Apart from supporting printer servers, the USB port also allows the connection of a USB disk or hard drive for FTP file transfer through the Internet or local networks. The network administrator can set username/password and directory/file access privilege for individual users.
The DMZ port of Vigor3200 series can provide additional layer protection to servers, such as Web server, which need to expose resources from untrusted network: e.g. Internet but also have uncompromising internal LAN security requirements.
Through the user-friendly WUI of Vigor3200 series, admin can activate DMZ by NAT or Physical mode to the chosen server. That would makes external attacks only have access to the external-facing equipment in the DMZ, not entire LAN to insert extra layer of protection to SMB’s internal network.
With all this connectivity, your LAN and WAN increases in complexity, but the comprehensive VLAN and QoS enables your efficient utilization of your bandwidth on your LAN and WAN side. The 802.1q VLAN is supported on both the LAN and WAN ports. By applying 802.1q VLAN tagging, the marked packets will be transmitted together and split further along in your network topology, as required, or merely dropped/ignored if they fall outside a device's VLAN settings.
The Quality of Service (QoS) allows you to give specific traffic types or clients different levels of priority when it comes to transmitting data so that the most appropriate amount of total bandwidth is reserved for the most important data. The VLAN groups and QoS (802.1p & TOS/DSCP Methods) can be combined with QoS rules for transmission to the Internet. After you set up VLAN groups for your office network, you can define firewall rules together with VLAN groups to let remote VPN links to only access the specific LAN ports. The Vigor3200 series are with four LAN subnets which are very useful for multi-tenanted applications or where there is necessity of department segmentation.
The VLAN setup can be applied to the four LAN subnets for isolated connection. For example, you are running a public web server on your network. The VLAN segmentation with different subnets will give a fully isolated connection to the said public web server.
The Vigor3200 series offer you robust firewall options with both IP-layer and content-based protection. The DoS/DDoS prevention and URL/Web content filter strengthen the security outside and inside the network. The enterprise-level CSM (Content Security Management) enables users to control and manage IM (Instant Messenger) and P2P (Peer-to-Peer) applications more efficiently. The CSM hence prevents inappropriate content from distracting employees and impeding productivity. Furthermore, the CSM can keep office networks threat-free and available.
The "User Management" implemented on your router firmware can allow you to prevent any computer from accessing your Internet connection without a username or password. You can also allocate time budgets to your employees within office network.
Up to 64 simultaneous hardware based VPN tunnels are supported providing a throughput up to 40Mbps. Each of these can be configured to use any of the common VPN protocols: PPTP, IPSec, L2TP, L2TP over IPSec, etc., and with any of the most up-to-date encryption (MPPE, AES/DES/3DES), Authentication (MD5, SHA-1), Pre-shared Key, Digital Signature (X.509). These tunnels can be used for LAN-to-LAN or remote dial-in.
The Vigor3200 series support up to 64 concurrent VPN tunnels for LAN-to-LAN and remote access. There are up 10 concurrent tunnels of SSL Web Proxy and SSL Applications on Vigor3200 series for teleworkers. Along with Ethernet WAN ports, the VPN trunking (VPN load-balancing and VPN backup) are available on Vigor3200 series.
Vigor3200 supports 100-Node DrayTek Smart Monitor Traffic Analyser which enables you to analyze in great depth your Internet traffic, as a professional aid to improving efficiency and detecting potential problems.
Configuring Vigor3200 router is easy with the web based configuration pages, plus the CLI/Telnet/SSH methods. Tools allowing network administrators to manage and maintain the networks with ease include:
- Diagnostic Tables that show network connection status
- SNMP for network traffic monitoring
- Two levels of Access Control to prevent unauthorized access to the router
- TR-069 for service providers to manage user devices remotely
DrayTek makes authentication for VPN Remote Access with ease by Vigor3200 Series.
Network administrator doesn't have to create new Remote Dial-in User Profiles for authentication mechanism but applies existed user accounts saved in the external server (e.g. Active Directory/LDAP). This enhancement significantly saves the time of IT Dept while establishing the secure remote access network for tele-workers.
More features are available to support business networks’ operations, such as Call Scheduling, RADIUS support, UP&P, VLAN, QoS, Packet Forward Acceleration, etc.
The Vigor3200n model includes a built-in 802.11n Wireless Access Point (WAP) delivering wireless network speed up to 300Mbps. For upmost security, it supports WEP/WPA/WPA2 (64bit/128bit), MAC Address Access Control, 4 x SSID, 802.1x Authentication and WLAN Isolation. Other enhanced features include: WDS (Wireless Distribution System) to extend the coverage range, Wireless Rate Control to manage bandwidth allocation to wireless devices, and WMM (Wi-Fi Multimedia) to prioritize voice, video and data within the WLAN network.
1. Multi-WAN (Ethernet / 3.5G)
- Outbound Policy-based Load-balance
- WAN Connection Failover
2. Network Features
- Packet Forwarding Acceleration
- DHCP Client/Relay/Server
- DHCP Option
- IGMP V2
- Dynamic DNS
- NTP Client
- Call Scheduling
- RADIUS Client
- DNS Proxy
- UPnP 30 Sessions
- Routing Protocol:
- Static Routing
- RIP V2
- Multiple Private LAN Subnets(Multi-Subnets)
- VLAN Tagging (802.1q) on WAN
3. WAN Protocol
- DHCP Client
- Static IP
- Up to 64 VPN Tunnels
- Protocol: PPTP, IPSec, L2TP, L2TP over IPSec
- Encryption: MPPE and Hardware-based AES/DES/3DES
- Authentication: Hardware-based MD5, SHA-1
- IKE Authentication: Pre-shared Key and Digital Signature (X.509)
- LAN-to-LAN, Teleworker-to-LAN
- DHCP over IPSec
- NAT-Traversal (NAT-T)
- Dead Peer Detection (DPD)
- VPN Pass-through
- VPN Wizard
- SSL VPN
- Multi-NAT, DMZ Host, Port-redirection and Open Port
- Object-based Firewall
- MAC Address Filter
- SPI (Stateful Packet Inspection) (Flow Track)
- DoS / DDoS Prevention
- IP Address Anti-spoofing
- E-mail Alert and Logging via Syslog
- Bind IP to MAC Address
- Time Schedule Control
- 3.5G USB Modem as 5th WAN
- Printer Sharing
- File System :
- Support FAT32 / FAT16 File System
- Support FTP Function for File Sharing
7. Bandwidth Management
- QoS :
- Guarantee Bandwidth for VoIP
- Class-based Bandwidth Guarantee by User-defined Traffic Categories
- DiffServ Code Point Classifying
- 4-level Priority for Each Direction (Inbound/Outbound)
- Bandwidth Borrowed
- Bandwidth / Session Limitation
- Layer-2 (802.1p) and Layer-3 (TOS / DSCP) QoS Mapping *
8. Network Management
- Web-Based User Interface (HTTP/HTTPS)
- Quick Start Wizard
- CLI (Command Line Interface, Telnet/SSH)
- Administration Access Control
- Configuration Backup/Restore
- Built-in Diagnostic Function
- Firmware Upgrade via TFTP/FTP/HTTP/TR-069
- Logging via Syslog
- SNMP Management with MIB-II
- Management Session Time Out
- 2-level management (Admin/User Mode)
- TR-069 Management
- TR-104 Management
9. Content Security Management
- IM/P2P Applications V3 (APP Enforcement)
- URL Content Filter :
- URL Keyword Blocking (White List and Black List)
- Java Applet, Cookies, Active X, Compressed, Executable, Multimedia File Blocking
- Excepting Subnets
- Time Schedule Control
- GlobalView Web Content Filter ( Vigor3200 Powered by , Vigor3200n Powered by ) *
10. Declaration of Conformity
11. Wireless Access Point
- IEEE 802.11b/g/n Compliant
- Wireless Client List
- Wireless LAN Isolation
- 64/128-bit WEP/WPA/WPA2
- MAC Address Access Control
- Access Point Discovery
- WDS (Wireless Distribution System)
- 802.1x Authentication
- Hidden SSID
- Multiple SSID
- Wireless Rate-control
- WMM (Wi-Fi Multimedia)
- All specifications are subject to change without notice. Please check with your supplier for exact offers. Products may not be available in all markets.
- PCB color and bundled software versions are subject to change without notice.
- Brand and product names mentioned are trademarks of their respective companies.
Advance Business Network (Multi WAN / SSL VPN)
Support up-to 10 SSL VPN tunnels
Multi-WAN Load Balancing / Failover LAN & WAN Status
Multi subnet with VLAN tag - Multi-tenant applications along with FTTx
VPN failover / backup by VPN trunk management
Active Directory/LDAP Group Management for VPN remote dial-in authentication
Working with Smart Monitor Traffic Analyzer
The version 3.3.7 firmware of Vigor3200 supports 100-Node DrayTek Smart Monitor Traffic Analyzer which enables you to analyze in great depth your Internet traffic, as a professional aid to improving efficiency and detecting potential problems.