We have launched the new version of the DrayTek website, and this content is no longer being maintained.
You will find more information on our new site; however, we will keep this page for a few months.

Vigor2912Fn blank.jpg blank.jpg blank.jpg blank.jpg blank.jpg blank.jpg blank.jpg blank.jpg blank.jpg


Fiber WAN VPN Router for Small Offices
  • 1 Fiber WAN + 1 Ethernet WAN for load balancing or redundancy
  • 1 USB port for 3G/4G WAN, printer, or network storage
  • 16 concurrent VPN tunnels, including 8 concurrent SSL VPN
  • Bandwidth management & QoS for the best VoIP quality
  • SPI Firewall with Content Filtering by Apps, URL keyword, and web category
  • IPv6 Support
  • Built-in 802.11n Wi-Fi
  • Support DrayDDNS since firmware v3.8.5 new


The Vigor2912Fn is an integrated network management solution that comes with 1 Fiber slot WAN and 4 Fast Ethernet LAN Switch. The 1st LAN port can be configured as a secondary WAN for load balancing or failover, and 3G/4G cellular connectivity can also be added to Vigor2912Fn via its USB port. The Vigor2912Fn is also a robust VPN server for up to 16 concurrent tunnels, it has Firewall and Content Filtering features built-in to secure the local network, and it offers bandwidth management functions to optimize the bandwidth allocation and make the most out of the limited bandwidth.

Dual-WAN Load-balance and Redundancy

The primary WAN interface of Vigor2912Fn is a fiber slot, a secondary WAN can be enabled on the W2/P1 switchable port, and a 3G/4G USB modem can be attached to the USB port to add a cellular connectivity as WAN 3. All 3 WANs can be active simultaneously to share the traffic load, or some of them can be set up in "failover", which means the WAN interface will be standing-by normally, but be activated automatically in the event of link failure or heavy traffic.


VPN for Secure Remote Access

Vigor2912Fn is also a robust VPN server for 16 concurrent VPN tunnels, including Site-to-Site VPN and Remote Access VPN. For Site-to-Site VPN, Vigor2912Fn also allows a redundant VPN tunnel to be built on the alternative WAN, so that if the main VPN fails due to the disconnection of the WAN, a backup VPN can be established automatically over the alternative WAN.


Secure the Local Network

bject-based Firewall with Web Content Filtering

Vigor2912Fn has built-in Stateful Packet Inspection (SPI) Firewall and supports flexible filtering rules to help you protect the network clients from insecure websites, and also improve productivity by preventing time and network resource wasting on inappropriate network activities.

With an annual subscription to CYREN Web Content Filtering service (a free 30-day trial is included in every new router.), you may also filter the websites by their categories, and set up restrictions to block the whole categories of websites (such as Social Networking, Gambling.. etc.) without the need to specify every site you would like to block.

Bandwidth Management

Vigor2912Fn features Bandwidth Limit and Session Limit to restrict the maximum bandwidth or session number that a host can use, thus to prevent the bandwidth and the router's resources being occupied by a single host. Quality of Service (QoS) allows you to reserve a certain amount of bandwidth for the critical clients or time-sensitive applications, such as audio and video, it also offers VoIP prioritization to ensure the best call quality even if the Internet speed is slow.

Bandwidth management with intelligent VoIP QoS

Built-In 802.11n W-Fi

Vigor2912Fn has built-in Wi-Fi that is compliant with the 802.11n standard, delivers data rate up to 300Mbps. Up to 4 SSID can be enabled, and each of them can be mapped to different VLAN of the router, allows you to separate the Wi-Fi clients and apply different policies easily.

Secure Business Wi-Fi Network
  • 1 100M SFP Slot WAN port
  • 1 FE WAN/LAN switchable port
  • 3 FE LAN ports
  • 1 USB 2.0 port
  • Factory Reset Button
  • DC 12V @1.5A – 2.0A
  • Max. Power Consumption: 24 watts
  • Operating: 0°C ~ 45°C
  • Storage: -25°C ~ 70°C
  • Operating: 10% ~ 90%
Dimension (mm)
  • 220(L) x 160(W) x 36(H)
Ethernet Connection (IPv4)
  • PPPoE Client
  • DHCP Client
  • Static IP
  • 802.1Q VLAN Tagging
  • Triple-Play Applications
Ethernet Connection (IPv6)
  • PPP
  • DHCPv6 Client
  • Static IPv6
  • TSPC
  • AICCU (AYIYA/Heartbeat)
  • 6rd
  • 6in4 Static Tunnel
Load Balance
  • IP-based Load Balancing
  • Session-based Load Balancing
  • Failover by Link Failure
  • Failover by Traffic Threshold
Connectivity Detection
  • ARP
  • Ping Probe
LAN Managment
  • Up to 8 VLAN
  • 802.1Q Tag-based VLAN
  • Port-based VLAN
DHCP Server
  • Up to 2 IP Subnet
  • Bind-IP-to-MAC
  • Custom DHCP Option
DNS Control
  • Local Name Server
Static Route
  • 10 IPv4 Static Routing 
  • 10 IPv6 Static Routing 
  • Inter-VLAN Routing
Dynamic Routing
  • RIPv2
Policy Routing
  • 10 Route Policy
  • Criteria: Protocol, Source IP, Destination IP, Destination Domain Name, Destination Country, Destination Port
  • Failover options
  • Up to 16 concurrent VPN tunnels
  • Max. 8 concurrent SSL VPN
  • PPTP, L2TP, IPsec, L2TP over IPsec, SSL, GRE, IKEv2
  • LAN-to-LAN VPN
  • Teleworker-to-LAN VPN
  • MPPE 40/128 bit
  • Hardware-based AES/DES/3DES
  • MD5, SHA-1
  • Pre-Shared Key, Digital Signature (X.509)
  • mOTP
  • Hub-and-Spoke Topology support
  • DHCP over IPsec
  • VPN Redundancy for Failover
  • One-to-One Port Redirection
  • Range-to-Range Port Redirection
  • Open Ports
  • Port Triggering
  • DMZ Host
  • ALG: SIP, RTSP, FTP, TFTP, H.323
  • VPN Pass-Through: PPTP, L2TP, IPsec
  • UPnP
Firewall Filter
  • IP-based Firewall Policy
  • User-based Firewall Policy
  • Object-based Configuration
  • Schedule Enable/Disable
Content Filtering
  • URL Keyword Filtering
  • Category Filtering (subscription required)
  • DNS Keyword Filtering
  • Web Features Filtering
Attack Protection
  • DoS Defense
Bandwidth Management
Bandwidth Policy
  • Session Limit
  • Bandwidth Limit
  • IP-Based Policy
  • Scheduled Enable/Disable
Quality of Service
  • Layer 3 QoS (TOS/DSCP)
  • Layer 2 QoS (802.1p)
  • 4-Level Priority with user-defined classification
  • Bandwidth Borrowing
  • Guaranteed bandwidth for VoIP traffic
  • APP QoS
Network Features
  • Dynamic DNS
  • Bonjour
  • IGMP Proxy
  • IGMP Snooping
  • SMB File Sharing
User Authentication
  • Local User Database
  • RADIUS Server
  • Active Directory/LDAP
Wireless LAN
  • IEEE 802.11 b/g/n (2.4G)
  • Up to 4 per radio
  • SSID-based 802.1Q VLAN
Radio Management
  • Auto Channel Selection
  • Auto Channel Width (2.4G)
  • Wi-Fi Scheduling
  • WEP, WEP-802.1x, WPA-PSK, WPA-802.1x, WPA2-PSK, WPA2-802.1x
  • Hidden SSID
  • Client Isolation
  • Access Control per SSID
  • WPS
  • Rate Control per SSID
  • AirTime Fairness
  • WMM
  • Bridge
  • Repeater
  • Web Interface: HTTP, HTTPS
  • Command-Line Interface: Telnet, SSH
  • TR-069 via VigorACS
  • Configuration File Export & Import
  • Compliant with the configuration file exported from Vigor2910
F/W Upgrade
  • TFTP, HTTP, TR-069
Admin Access Control
  • 2-level Administration Privilege
  • Access from the Internet
  • Access List
  • Brute Force Protection
  • Dashboard
  • Syslog
  • SMS/E-mail Alert
  • TR-069 via VigorACS
  • SNMP V2, V2c, V3