Loading
LOADING IMAGES
Vigor2952 Series Vigor2952 Series Vigor2952 Series Vigor2952 Series Vigor2952 Series Vigor2952 Series Vigor2952 Series blank.jpg blank.jpg blank.jpg

Vigor2952 Series

Dual-WAN High-Performance Firewall VPN Router
  • Dual Gigabit Ethernet WAN
  • 2 USB ports for 3G/4G cellular modem, network storage, or USB temperature sensor
  • Up to 4 WAN for load-balancing and failover
  • High-Performance VPN allowing 100 concurrent tunnels, and up to 50 concurrent SSL VPN
  • IPv6 support on WAN & LAN
  • Up to 8 IP subnet on LAN, PPPoE Server support
  • High Availability (Hardware Redundancy) support
  • Integrated controller for up to 30 VigorAP and up to 10 VigorSwitch
  • PoE+(802.3at)-capable ports available (Pn model)

About

DrayTek Vigor2952 Series serves as a VPN gateway and a central firewall for multi-site offices and teleworkers. With its high data throughput of two-Gigabit Ethernet, Dual WAN, VPN trunking and 4 Gigabit Ethernet LAN ports, the device facilitates productivity of versatile business operations. The establishment of VPN tunnels up to 100 simultaneous tunnels (including 50 SSL VPN tunnels) can provide secure communications between sites.

 

 

WAN Load Balancing & Failover

Vigor2952 Serie has two Gigabit Ethernet WAN ports that can be used for any types of connection, 3G/4G/LTE USB cellular modem can also be attached to the two USB ports on the router to add wireless connectivity. Up to 4 WAN can active simultaneously to share the traffic load, or some of them can be configured to Failover mode, which will be automatically activated when detecting connection loss or heavy load on the primary connection.

For Load Balancing, Vigor2952 Series can either do the standard IP-based traffic balancing, or the session-based traffic balancing, which allows sessions in the same connection to take different routes, thus the maximum throughput of a single connection can be the combination of all the WAN's bandwidth.

draytek Vigor2952 multi WAN

 

Secure Business Network

Vigor2952 Series has implemented Stateful Packet Inspection (SPI) Firewall, flexible filtering rules can be set up  to accept or deny packets based on source IP, destination IP, protocol, port number, or even the packet's contents. Content Filtering by URL keyword or application can help you to prevent time and network resource wasting on inappropriate network activities.

draytek Vigor2952 security

With an annual subscription to CYREN Web Content Filtering service, you may also filter the websites by their categories, and set up restrictions to block the whole categories of websites (such as Social Networking, Gambling.. etc.) without the need to specify each site you would like to block. The CYREN service is constantly updating the categorization, and a free 30-day trial is included in each new router.

Vigor2952 Series is also a robust VPN server which is perfect for a company having multiple branches or teleworkers. Vigor2952 Series supports all common industry standard protocols, and also DrayTek SSL VPN with official VPN client App provided.

To ensure the reliability of VPN connections, VPN Trunking is also supported by Vigor2952 Series, this allows you to set up a pair of VPN tunnels to the same remote network but through different WAN interfaces. The two trunking tunnels can be set up in load balancing or failover mode.

draytek Vigor2952 VPN

 

High Availability

To ensure the network reliability, Vigor2952 Series provides high-availability feature and allows another (or more) redundant Vigor2952 to be added to the network. A pair (or more) Vigor2952 can be set up in master/slave configuration. Normally, only the Master Vigor2952 will be active and provide internet connectivity to the LAN network. In the event of a hardware failure on the primary Vigor2952 or its WAN connection, the Standby Vigor2925 will automatically take over the traffic without any re-configuration required.

draytek Vigor2952 HA

 

Power-over-Ethernet (P/Pn model)

The Vigor2952 Series comes in two models that equipped with PoE+ LAN switch - Vigor2952P and Vigor2952Pn (with 802.11n WLAN built-in).  The 4 PoE ports of Vigor2952P/Pn allow direct connectivity and offer power for wireless access point, IP phones, and IP surveillance, this function makes installation of network devices easier.

2952P-PoE
Hardware
Interface
  • WAN1: Gigabit Ethernet  or SFP Slot
  • WAN2: Gigabit Ethernet
  • LAN:
    4 x Gigabit Ethernet
    PoE+ capable with power budget up to 60 watts (P/Pn model)
  • USB 1: USB 2.0
  • USB 2: USB 3.0
  • Factory Reset Button
  • Power On/Off Switch
Power
  • 2925 and 2925n:
    • AC100-240V/ 1.0A
    • Power Consumption: 19 watts
  • 2925P and 2925Pn:
    • AC56V/ 1.79A
    • Power Consumption: 100 watts
Temperature
  • 2925 and 2925n:
    • Operating: 0 ~ 45°C 
    • Storage: -20°C ~ 70°C
  • 2925P and 2925Pn:
    • Operating: 0 ~ 40°C
    • Storage: -20°C ~ 70°C
Humidity
  • Operating: 10% ~ 90%
    (non-condensing)
Dimension (mm)
  • 273(L) x 176(W) x 46(H)
    (10.7" x 7.0" x 1.8")
WAN
Ethernet Connection
  • PPPoE Client
  • DHCP Client
  • Static IP
  • PPTP/L2TP
  • 802.1Q VLAN Tagging
  • Triple-Play Applications
IPv6
  • PPP
  • DHCPv6 Client
  • Static IPv6
  • TSPC
  • AICCU (AYIYA/Heartbeat)
  • 6rd
  • 6in4 Static Tunnel
Load Balancing
  • IP-based Load Balancing
  • Session-based Load Balancing
  • WAN Data Budget 
Failover
  • Failover by Link Failure
  • Failover by Traffic Threshold
Connectivity Detection
  • ARP
  • Ping Probe
High Availability
  • Method: Active-Standby /Hot-Standby
  • Automatic Configuration Sync
  • WCF License Key Sharing
LAN Managment
VLAN
  • Up to 8 VLAN
  • 802.1Q Tag-based VLAN
  • Port-based VLAN
IP Assignment
  • Up to 8 IP Subnet
  • DHCP Server
  • PPPoE Server
  • Bind-IP-to-MAC
Security
  • Wired 802.1x 
DNS Control
  • Local Name Server
  • Conditional DNS Forwarding
Hotspot Portal
  • Authentication by Click-Through, Social Media Accounts, SMS PIN
  • Custom Portal Page
  • URL Redirection
  • Bulletin Message
  • White List
PoE (P/Pn model)
  • Schedule Enable/Disable
  • PD Device Check
Routing
Static Route
  • 40 IPv4 Static Routing Rules
  • 40 IPv6 Static Routing Rules
Dynamic Routing
  • RIP v1/v2
  • BGP (f/w 3.8.7 or later)
Policy-Based Routing
  • 10 Route Policy
  • Criteria: Protocol, Source IP, Destination IP, Destination Domain Name, Destination Country, Destination Port
  • Failover options
VPN
Performance
  • Up to 100 concurrent tunnels
  • Up to 50 concurrent SSL VPN
Protocols
  • PPTP, L2TP, IPsec, L2TP over IPsec, SSL, GRE over IPSec
  • IKEv2 (f/w 3.8.7 or later)
  • LAN-to-LAN VPN
  • Teleworker-to-LAN VPN
Encryption
  • MPPE 40/128 bit
  • Hardware-based AES/DES/3DES
Authentication
  • PAP, CHAP, MS-CHAP, MS-CHAPv2
  • MD5, SHA-1
  • Pre-Shared Key, Digital Signature (X.509)
  • mOTP
Advanced
  • Hub-and-Spoke Topology support
  • DHCP over IPsec
  • VPN Redundancy for Load Balancing or Failover
  • Single-Armed VPN
Firewall
 NAT
  • One-to-One Port Redirection
  • Range-to-Range Port Redirection
  • Open Ports
  • Port Triggering
  • DMZ Host
  • ALG: SIP, RTSP, FTP, TFTP, H.323
  • VPN Pass-Through: PPTP, L2TP, IPsec
  • UPnP
 Firewall Filter
  • IP-based Firewall Policy
  • User-based Firewall Policy
  • Object-based Configuration
  • Schedule Enable/Disable
 Content Filtering
  • URL Keyword Filtering
  • Category Filtering (subscription required)
  • DNS Keyword Filtering
  • Web Features Filtering
Attack Protection
  • DoS Defense
Bandwidth Management
Bandwidth Management
  • Session Limit
  • Bandwidth Limit
  • IP-Based Policy
  • Scheduled Enable/Disable
Quality of Service
  • Layer 3 QoS (TOS/DSCP)
  • Layer 2 QoS (802.1p)
  • 4-Level Priority with user-defined classification
  • Bandwidth Borrowing
  • Guaranteed bandwidth for VoIP traffic
  • APP QoS
Network Features 
Network Features
  • Dynamic DNS
  • DNS Security
  • Bonjour
  • IGMP Proxy
  • IGMP Snooping
  • SMB File Sharing
User Authentication
  • Local User Database
  • RADIUS Server
  • Active Directory/LDAP
  • TACACS+
  • Internal RADIUS Server
Wireless LAN  (n/Pn model)
Standards
  • IEEE 802.11 b/g/n 2.4G
SSID
  • Up to 4 SSIDs
  • SSID-based 802.1Q VLAN
Radio Management
  • Auto Channel Selection
  • Auto Channel Width (2.4GHz)
  • Wi-Fi Scheduling
Security
  • WEP, WEP-802.1x, WPA-PSK, WPA-802.1x, WPA2-PSK, WPA2-802.1x
  • Hidden SSID
  • Client Isolation
  • Access Control per SSID
  • WPS
Advanced
  • Rate Control per SSID
  • AirTime Fairness
  • WMM
WDS
  • Bridge
  • Repeater
Management
Configuration
  • Web Interface: HTTP, HTTPS
  • Command-Line Interface: Telnet, SSH
  • TR-069 via VigorACS
  • Configuration File Export & Import
  • Compliant with the configuration file exported from Vigor2925, Vigor2920, Vigor2930, Vigor2950, Vigor2955
F/W Upgrade
  •  TFTP, HTTP, TR-069
Admin Access Control
  • 2-level Administration Privilege
  • Access from the Internet
  • Access List
Monitoring
  • Dashboard
  • Syslog
  • SMS/E-mail Alert
  • TR-069 via VigorACS
  • SNMP v2, v3
  • Port Mirroring
Central Management
  • Wireless Controller for up to 30 VigorAP
  • 10 Vigor Switch
  • 8 Vigor Router (CVM)

 

ModelVigor2952Vigor2952nVigor2952PVigor2952Pn
2.4G WLAN -

Yes

-

Yes

Wi-Fi Antenna - 2 - 2
PoE+ Port - - 4 4