DrayTek Vigor 2862N ADSL/VDSL2 Router Firewall
Product OverviewVigor 2862 Series VDSL/ADSL Router Firewall
The Vigor 2862 series is our new flagship router/firewall. Exact feature support varies by model (see specification tab). It is what we've called the 'Ultimate DSL router' supporting both ADSL or VDSL (BT Infinity™/FTTC) and packed with professional level features to increase security, flexibility and functionality, making it ideal as your standard router for almost any scenario.
As well as ADSL/VDSL support, alternative WAN ports can instead provide connectivity to Ethenet feeds (Gigabit WAN2 is switchable with LAN Port 5*), secondary xDSL modems or a 3G/4G cellular service using a supported USB adapter (or there is the Vigor 2862Ln model with 3G/4G/LTE built-in). These multiple LAN feeds can be combined for failover or load-balancing.
This latest router series includes support for other professional features such as VLAN tagging, QoS (Quality of Service Assurance), High Availability, DNS Filter, Policy Based Routing, and User Access Control. Hotspot features with customisable branding and wording which can be applied to guest network VLANs & SSIDs. If you deploy DrayTek Wireless Access Points, the Vigor 2862 can act as the Central Management controller (click on any of those links for an explanation of each feature).
A 5-port Gigabit Ethernet switch on the LAN side provides high speed connectivity for your server, other local PCs or for uplink to a larger Ethernet switch. Comprehensive security features include content filtering, web application controls and an object based firewall management system. Port 5 is switchable with 'WAN2' to use it as an Ethernet WAN port instead of a LAN port*.
*requires f/w 3.8.8 or later, otherwise 5th Ethernet port is for WAN2 only.
Runs on either ADSL or VDSL
The Vigor 2862's built in DSL interface will connect to either an ADSL or VDSL2 line. If you have a second line (of either type) you can add an additional modem (or your existing modem from your other line) to the Vigor 2862's Ethernet WAN ports. You can set the two lines up in load balancing mode, where traffic is split across both of them, or into failover mode, where the other DSL line only kicks-in if your primary DSL line fails (or vice versa). ADSL makes a particularly good method of failover for VDSL because they are delivered differently. VDSL service is provided and powered by a cabinet in your street - that's where the line terminates. ADSL service, on the other hand, comes all the way from your local exchange, which could be miles away and is powered from there. That means that if your street's VDSL cabinet is damaged, its DSLAM fails or you lose power to your street, you lose VDSL, but your ADSL line comes via a different method and route, so it's less likely that both would be affected.
Robust & Comprehensive Firewall
Security is always taken seriously with DrayTek routers. The firewall protects against attacks including DoS (Denial of Service) attacks, IP-based attacks and access by unauthorised remote systems. Wireless, Ethernet and VPN are also protected by various protection systems. The DrayTek object-based firewall allows even more setup flexibility than ever, enabling you to create combinations of users, rules and restrictions to suit multi-departmental organisations. The Vigor 2862 also allows selective direction firewall rules of LAN to WAN, WAN to LAN or LAN to VPN.
IPv6 - Next Generation Internet Routing
The Vigor 2862 supports IPv6 - the successor to the current IPv4 addressing system that has been used since the Internet was first created. IPv4 address space is full up and IPv6 allows for much more efficient routing and a larger address space. IPv6 is supported both from your own ISP, but if your ISP does not (yet) support IPv6, the Vigor 2862 also supports IPv6 broker/tunnel services to provide IPv6 access using either TSPC or AICCU via 3rd party IPv6 providers. To learn all about IPv6, you can get our detailed guide to IPv6 here and you can view the IPv6 detailed support in the product specification tab.
Web Content Filtering
The content control features of the Vigor 2862 series allow you to set restrictions on web site access, blocking download of certain file or data types, blocking specific web sites with whitelists or blacklists, blocking IM/P2P applications or other potentially harmful or wasteful content. Restrictions can be per user, per PC or universal and according to time schedules.
Content filtering can also block sites using HTTPS/SSL where URLs are encrypted (and normal routers cannot block).
Using the GlobalView service, you can block whole categories of web sites (e.g. gambling, adult sites etc.), subject to an annual subscription, which is continuously updated with new or changed site categorisations or sites which have become compromised (such as infected with Malware). A free 30-day trial is included with your new router.
WAN Load Balancing & Backup
The Vigor 2862 features multiple methods of WAN connectivity - ADSL/VDSL, Ethernet, USB port for connection of a 3G/4G modem, optional built-in 3G/4G or (on wireless models) and Wireless WAN. The Ethernet port can connect to a second ADSL/VDSL modem (e.g. Vigor 130), a cable modem or any other Ethernet-based Internet feed. The multiple WAN interfaces can be used either for WAN-Backup or Load-Balancing. WAN-Backup provides contingency (redundancy) in case of your primary ADSL line or ISP suffering temporary outage). Internet Traffic will be temporarily routed via the secondary Internet access. When normal service is restored to your primary line, all traffic is switched back to that.
LAN Ports (Switch)
5 X Gigabit Ethernet (1000Mb/s) Ports
LAN Port 5 Switchable with WAN2 (req. f/w 3.8.8 or later)
WAN1 : ADSL/VDSL, RJ11
WAN2 : Gigabit Ethernet (1000Mb/s) Ethernet for load balance and WAN failover
Switchable with LAN Port 5
WAN3 : USB 2.0 Port for 3G/4G Modem, thermometer or Printer
WAN4 : USB 2.0 Port for 3G/4G Modem or Printer (Not on vigor 2862Ln)
Wireless WAN - Wireless interface can provide WAN connectivity
Firewall: Up to 400Mb/s max
IPSec VPN: Up to 60Mb/s max
ANSI T1.413 Issue2
ITU-T G.992.1 G.dmt (ADSL)
ITU-T G.992.2 G.lite
ITU-T G.992.3 ADSL2
ITU-T G.992.5 ADSL2+
Annex L (READSL)
ANFP Issue 3 Compliant/Certified (for Annex A & Annex M)
DSL Forum : TR-048/67 & TR-100
BT Infinity Option 1 & Option 2 Compatible
BT SIN 498 MCT Approved
Support for G.INP & Vectoring
ITU-T VDSL2 G.993.2
ITU-T G.993.1, G.997.1
Band Plan: G.998, G.997
Annex A, Annex B, Annex C
VDSL2 Profile: 8a, 8b, 8c, 8d, 12a, 12b, 17a, 30a
OLR, UPBO, DPBO Supported
Loop Diagnostic Mode
DSL Forum WT-114
Load Balance/Failover Features:
Outbound Policy-Based Load-Balance to direct traffic via:
NAT or Routing
Specific LAN Gateway
IP-Based or Session-Based Load Balance modes NEW!
WAN Connection Fail-over
BoD (Bandwidth on Demand)
WAN1 PPPoE/PPPoA Fallback account, used if the primary details are unable to establish a working connection NEW!
Configurable Load-Balance pool, specify WAN interfaces to load balance
Vigor 2862 ATM Protocols (DSL):
RFC-2684/RFC-1483 Multiple Protocol over AAL5
RFC-2516 PPP over Ethernet
RFC-2364 PPP over AAL5
PPPoE pass through LAN/WLAN
Transparent bridge for MPoA
Multiple PVC support for Triple Play Applications (up to 8 simultaneous)
Support for RFC4638 for MTU up to 1500
Wireless LAN Features ('n' and 'ac' Models Only):
802.11g/b/n and 802.11ac (Vigor 2862ac only)
Backward Compatibility for 802.11b/g
Wireless Features on Vigor 2862ac:
4x4 MU-Mimo (5Ghz)
Up to 4 Spacial Streams
TX Beam Forming
1733Mb/s Link Rate (5Ghz) + 300Mb/s (2.4Ghz)
Dual-band (2.4/5Ghz) simultaneous wireless
Extended DFS frequency range
Multiple SSID : Create up to 4 virtual wireless LANs (independent or joined)
Packet Aggregation and Channel Bonding
Optional Higher Gain or directional aerials available - Click Here.
Active Client list in Web Interface
Wireless LAN Isolation (from VLAN groups and wired Ethernet interfaces)
64/128-bit WEP Encryption
Switchable Hidden SSID
Restricted access list for clients (by MAC address)
Time Scheduling (WLAN radio can be disabled at certain times of day)
Time Scheduling for individual SSIDs NEW!
Access Point Discovery
WDS (Wireless Distribution system) for WLAN Bridging and Repeating
802.1x Radius Authentication
Automatic Power Management
802.11e WMM (Wi-Fi Multimedia)
Station Control, limit wireless client access time per day
Airtime Fairness NEW!
Band Steering NEW!
Wireless WAN mode for WAN2, switchable with Ethernet (Wireless models only) NEW!
WAN Protocols (Ethernet):
Firewall & Security Features:
CSM (Content Security Management):
URL Keyword Filtering - Whitelist or Blacklist specific sites or keywords in URLs
Block Web sites by category (e.g. Adult, Gambling etc. Subject to subscription)
Prevent accessing of web sites by using their direct IP address (thus URLs only)
Blocking automatic download of Java applets and ActiveX controls
Blocking of web site cookies
Block http downloads of file types :
Binary Executable : .EXE / .COM / .BAT / .SCR / .PIF
Compressed : .ZIP / .SIT / .ARC / .CAB/. ARJ / .RAR
Multimedia : .MOV / .MP3 / .MPEG / .MPG / .WMV / .WAV / .RAM / .RA / .RM / .AVI / .AU
Time Schedules for enabling/disabling the restrictions
Block popular P2P (Peer-to-Peer) file sharing programs
Block Instant Messaging programs (e.g. IRC, Skype/Yahoo Messenger etc.)
DNS Filter: Use DNS to enforce categorisation
Multi-NAT (32 WAN IPs per WAN1 & WAN2)
DMZ Port (via LAN port P1, switchable)
40 Port Redirection rules
40 Open Port rules (10 port ranges per rule)
MAC Address Filter
SPI ( Stateful Packet Inspection ) with new FlowTrack Mechanism
DoS / DDoS Protection
IP Address Anti-spoofing
E-Mail Alert and Logging via Syslog
Bind IP to MAC Address
Up to 200 Profiles
Supports external authentication via LDAP or RADIUS
Per User Bandwidth and Time Quota
Schedule Control to delete or disable account automatically
Quality of Service (QoS)
Guaranteed Bandwidth for VoIP
Class-based Bandwidth Guarantee by User-Defined Traffic Categories
Layer 2&3 (802.1p & TOS/DCSP)
DiffServ Code Point Classifying
4-level Priority for each Direction (Inbound / Outbound)
App QoS: Classify traffic by Application
Temporary (5 minute) Quick Blocking of any LAN Client
Bandwidth Limit (Shared or individual limit)
Smart Bandwidth Limitation (Triggered by Traffic / Session)
Web-Based User Interface (HTTP / HTTPS)
CLI ( Command Line Interface ) / Telnet / SSH
Web Console: Access CLI through Web Interface
Administration Access Control
Brute Force Protection
Configuration Backup / Restore
Configuration Import from Vigor 2820, Vigor 2830, Vigor 2850 & Vigor 2860
Built-in Diagnostic Function
Firmware Upgrade via Web Interface, TFTP, FTP
Logging via Syslog
Supports SmartMonitor (up to 50 IPs monitored)
SNMP v2 & v3 Management with MIB-II
Access Point Management: Centrally Manage up to 20 DrayTek VigorAPs
Switch Management: Centrally Manage up to 10 DrayTek VigorSwitches
Up to 32 Concurrent VPN Tunnels (incoming or outgoing)
L2TP over IPSec
IPSec Main and Agressive modes
IKE Phase 1 DiffieHelman Groups 1,2,5 & 14
IKE Phase 2 DiffieHelman Groups 1,2,5 & 14 (will match phase 1 selection)
IKEv2 & IKEv2 NEW!
Encryption : MPPE, DES / 3DES (168bits) and Hardware-Based AES (128/192/256bits)
Authentication : Hardware-Based MD5, SHA-1 and SHA-256 (f/w 3.8.3 and later)
IKE Authentication : Pre-shared Key or X.509 Digital Signature
SSL VPN for teleworkers - Up to 16 simultaneous users. Proxy or tunnel
LAN-to-LAN & Teleworker-to-LAN connectivity
DHCP over IPSec
NAT-Traversal ( NAT-T )
Dead Peer Detection (DPD)
MOTP (Mobile One Time Password) for two factor authentication (2FA)
Virtual IP Mapping, map a remote IP subnet/range to another range to resolve IP subnet/range conflicts
Port forwarding (Port Redirection, Open Ports) to remote clients connected via an IPsec LAN to LAN VPN NEW!
Port-Based VLAN (Inclusive/Exclusive Groups)
802.1q VLAN Tagging
802.1X Port Authentication
Multi Subnet DHCP Servers with DHCP Relay
LAN Clients : Up to 1022 per subnet (for subnets 1-3)
Custom DHCP Option support
DNSSEC support NEW!
DNS Transparent Proxy
LAN DNS (supports CNAME)
NTP Client (Synchronise Router Time)
Call Scheduling (Enable/Trigger Internet Access by Time)
Internal RADIUS Server
Microsoft™ UPnP Support
Maximum MTU 1534
Static Routing (30 routes)
RIPng for IPv6 NEW!
Rack Mountable (Optional Vigor RM1 mounting bracket required)
Temperature Operating : 0°C ~ 45°C
Storage : -25°C ~ 70°C
Humidity 10% ~ 90% (non-condensing)
Power Consumption: 18 Watt Max.
Dimensions: L240.96 * W165.07 * H43.96 ( mm )
Operating Power: DC 12V (via external PSU, supplied)
Warranty : Two (2) Years RTB
Power Requirements : 220-240VAC
|Warranty Type||Manufacturer via Aria|
Comments, Questions & Reviews: