We have launched the new version of the DrayTek website, and this content is no longer being maintained.
You will find more information on our new site; however, we will keep this page for a few months.

Vigor3220 Series Vigor3220 Series Vigor3220 Series blank.jpg blank.jpg blank.jpg blank.jpg blank.jpg blank.jpg blank.jpg

Vigor3220 Series

Quad-WAN Load Balancing VPN Router
  • 4 Gigabit WAN Port for load balancing or failover
  • 2 USB for 3G/4G USB mode, printer, network storage or temperature sensor
  • 100 simultaneous VPN tunnels, including up to 50 SSL VPN
  • IPv6 Support on WAN & LAN
  • SPI Firewall and content filtering by URL keyword, Apps, and web category (optional)
  • Support Central Device Management for up to 30 VigorAP and up to 10 VigorSwitch
  • Compliant with VigorACS 2


Vigor3220 series is a load balancing router that has four Gigabit Ethernet WAN ports, there is also one USB 3.0 port which can work with 3G/4G/LTE USB modems to add additional wireless Internet connectivity. With multiple WAN access and high NAT performance, Vigor3220 ensure a reliable Internet connectivity for a network that has around 200 hosts.The Vigor3220 series also offer enterprise-level features including VPN, Firewall, Content Filtering, and Central Management Solution for Vigor access points, which makes it the perfect network solution for a medium-sized business, especially for those based in multiple locations or have teleworkers.

Draytek Vigor3220 ssl vpn

WAN Load Balancing

Up to 5 WAN links can be active simultaneously on Vigor3220 series, including 4 Gigabit Ethernet and 1 3G/4G cellular connection via a USB modem attached to the USB port. With default configuration, Vigor3220 automatically distribute the traffic among all active WANs and determines the load balancing weight based on the bandwidth utilization of each interface. Aggregated bandwidth can also be achieved by using "Session-Based" Load Balancing mode. Vigor3220 series also features Data Budget Tool to track the data usage on each WAN, which will be reset monthly (or on custom cycle), administrator can configured the router to shut down the interface immediately or send a notification when the data usage reaches a threshold.

Draytek Vigor3220 multi wan

A Robust VPN Server

Vigor3220 can be the VPN server allows up to 100 simultaneous connections, including LAN-to-LAN VPN with the branch offices, or the Host-to-LAN VPN for the teleworkers. All the industry standard tunneling protocols are supported, including PPTP, L2TP, IPsec, and GRE, and therefore are compatible with 3rd party VPN devices. SSL VPN is also included on Vigor3220, and DrayTek also offers free official client App for Windows, iOS, and Android. 

Draytek Vigor3220 vpn

Vigor3220 also provides VPN redundancy to ensure the reliability of VPN connection. Two VPN tunnels to the same remote network but through different WAN interfaces can be configured into a VPN trunk. The two trunking tunnels can be set up in load balancing or failover mode.

VLAN and Multiple Subnet

Vigor3220 can provide high-speed Internet connectivity for up to 200 hosts, and the support of Virtual LAN Feature (VLAN) allows you to separate the whole LAN network into smaller logical domains, which will help to increase the local network security and improve network efficiency. Up to 8 IP subnet can be set up on Vigor3220 series, this enables each VLAN to use a different IP address range.

Draytek Vigor3220 multi subnet
  • 4 Gigabit Ethernet WAN ports
  • 1 Gigabit Ethernet LAN port
  • 1 Gigabit Ethernet DMZ Port
  • 1 USB 2.0 port
  • 1 USB 3.0 port
  • 1 Console port
  • Factory Reset Button
  • AC 100-240V @1.0A
  • Max. Power Consumption: 19 watts
  • Operating: 0 ~ 45°C 
  • Storage: -20°C ~ 70°C
  • Operating: 10% ~ 90%
Dimension (mm)
  • 273(L) x 171(W) x 45(H)
NAT Session
  • 100,000 sessions
Ethernet Connection (IPv4)
  • PPPoE Client
  • DHCP Client
  • Static IP
  • 802.1Q VLAN Tagging
  • Triple-Play Applications
Ethernet Connection (IPv6)
  • PPP
  • DHCPv6 Client
  • Static IPv6
  • TSPC
  • AICCU (AYIYA/Heartbeat)
  • 6rd
  • 6in4 Static Tunnel
Load Balance
  • IP-based Load Balancing
  • Session-based Load Balancing
  • WAN Data Budget 
  • Failover by Link Failure
Connectivity Detection
  • ARP
  • Ping Probe
High Availability
  • Method: Active-Standby /Hot-Standby
  • Automatic Configuration Sync
  • WCF License Key Sharing
LAN Managment
  • Up to 8 VLAN
  • 802.1Q Tag-based VLAN
  • Port-based VLAN
DHCP Server
  • Up to 8 IP Subnet
  • DHCP Server
  • Bind-IP-to-MAC (DHCP Reservation)
  • Wired 802.1x 
DNS Control
  • Local Name Server
  • Conditional DNS Forwarding
Hotspot Portal
  • Authentication by Click-Through, Social Login, and SMS PIN
  • Custom Portal Page
  • URL Redirection
  • Walled-Garden
  • User Info Collection
Static Route
  • 40 IPv4 Static Routing Rules
  • 40 IPv6 Static Routing Rules
Dynamic Routing
  • RIPv1/v2
Policy Routing
  • 60 Route Policy
  • Criteria: Protocol, Source IP, Destination IP, Destination Port
  • Failover options
  • Up to 100 concurrent tunnels
  • Max. 50 concurrent SSL VPN
  • PPTP, L2TP, IPsec, L2TP over IPsec, SSL, GRE
  • LAN-to-LAN VPN
  • Teleworker-to-LAN VPN
  • MPPE 40/128 bit
  • Hardware-based AES/DES/3DES
  • MD5, SHA-1
  • Pre-Shared Key, Digital Signature (X.509)
  • mOTP
  • Hub-and-Spoke Topology support
  • DHCP over IPsec
  • VPN Redundancy for Load Balancing or Failover
  • One-to-One Port Redirection
  • Range-to-Range Port Redirection
  • Open Ports
  • Port Triggering
  • DMZ Host
  • ALG: SIP, RTSP, FTP, TFTP, H.323
  • VPN Pass-Through: PPTP, L2TP, IPsec
  • UPnP
Firewall Filter
  • IP-based Firewall Policy
  • User-based Firewall Policy
  • Object-based Configuration
  • Schedule Enable/Disable
Content Filtering
  • URL Keyword Filtering
  • Category Filtering (subscription required)
  • DNS Keyword Filtering
  • Web Features Filtering
Attack Protection
  • DoS Defense
Bandwidth Management
Bandwidth Policy
  • Session Limit
  • Bandwidth Limit
  • IP-Based Policy
  • Scheduled Enable/Disable
Quality of Service
  • Layer 3 QoS (TOS/DSCP)
  • Layer 2 QoS (802.1p)
  • 4-Level Priority with user-defined classification
  • Bandwidth Borrowing
  • Guaranteed bandwidth for VoIP traffic
  • APP QoS
Network Features
  • Dynamic DNS
  • DNS Security
  • Bonjour
  • IGMP Proxy
  • IGMP Snooping
  • SMB File Sharing
User Authentication
  • Local User Database
  • RADIUS Server
  • Active Directory/LDAP
  • Internal RADIUS Server
Wireless LAN
  • IEEE 802.11 b/g/n 2.4G
  • SSID-based 802.1Q VLAN
Radio Management
  • Auto Channel Selection
  • Auto Channel Width (2.4G)
  • Wi-Fi Scheduling
  • WEP, WEP-802.1x, WPA-PSK, WPA-802.1x, WPA2-PSK, WPA2-802.1x
  • Hidden SSID
  • Client Isolation
  • Access Control per SSID
  • WPS
  • Rate Control per SSID
  • WMM
  • Bridge
  • Repeater
  • Web Interface: HTTP, HTTPS
  • Command-Line Interface: Telnet, SSH
  • TR-069 via VigorACS
  • Configuration File Export & Import
  • Compliant with the configuration file exported from Vigor3200
F/W Upgrade
  •  TFTP, HTTP, TR-069
Admin Access Control
  • 2-level Administration Privilege
  • Access from the Internet
  • Access List
  • Brute Force Protection
  • Dashboard
  • Syslog
  • SMS/E-mail Alert
  • TR-069 via VigorACS
  • SNMP v2, v3
  • Port Mirroring
Central Management
  • Wireless Controller for up to 30 VigorAP
  • 10 Vigor Switch
  • 8 Vigor Router (CVM)


2.4G WLAN -
Wi-Fi Antenna - 2