☰ Menu

Vigor2925n

  • Dual Gigabit Ethernet WAN port for failover and load-balancing
  • Two USB ports for connection to Two 3.5G/4G LTE USB mobiles, FTP server and network printer
  • 5 x Gigabit LAN ports with multiple subnets
  • Object-based SPI Firewall and CSM (Content Security Management) for network security
  • VLAN for secure and efficient workgroup management
  • 50 VPN tunnels with comprehensive secure protocols
  • VPN load-balancing and backup for site-to-site applications
  • Integrated with high-performance IEEE 802.11n wireless access point
  • Embedded Central VPN Management for 8 remote Vigor routers
  • Embedded Central AP Management for multi-deployed Vigor wireless access points *
  • Working with Smart Monitor Network Traffic Analyzer (50-nodes)
  • Working with VigorACS SI Central Management for multi-site deployment

OVERVIEW FEATURES SPECIFICATIONS APPLICATIONS DOWNLOADS
Vigor2925 Series is the IPv6 ready Dual Gigabit Ethernet WANs and Dual USB WANs broadband security firewall router. The product range is from Vigor2925, Vigor2925n, Vigor2925n plus, and Vigor2925Vn plus.
It ensures the business continuity for today and the future IPv6 network. Its two gigabit Ethernet WAN ports can accept various high-speed Ethernet-based WAN links via FTTx/xDSL/Cable. The 2 USB ports are for 3.5G/4G LTE mobile broadband access. With the multi-WAN accesses, Vigor2925 series routers provides flexible and reliable broadband connectivity for the small business office. The VPN backup and VPN load balancing assures business continuity via multi-WAN connection to the Internet. The bandwidth management, Quality of Service, VLAN for flexible workgroup management, User Management for authentication, Route Policy, Central VPN Management, Central AP Management and Firewall serve your daily office network to bring in more business opportunities

Dual Gigabit Ethernet WAN ports for failover and load-balancing

The Gigabit Ethernet WAN ports cater for any type of Internet access, including FTTx, xDSL and Cable fitting your local infrastructure. You can then use both WAN 1 and WAN 2 for failover, ensuring that you will always have an access to the Internet even if one of the WAN fails, or for load-balancing so the 2 WANs share Internet traffic requirements of your organization.

2 USB 2.0 ports for 3G/4G LTE mobile, FTP drive and network printers

The two USB ports can be used for the connection of 3G/4G mobile broadband dongle, FTP drive and network printers. A 3G/4G mobile broadband connected to one of the 2 USB ports can be used as a second WAN for bandwidth management. The USB WAN interface can also be the primary access if the local fixed line service hasn't been deployed yet. You can have 2 USB 3G/4G dongles connected to the USB ports, and assign one of these (WAN 3) to be the primary access and the other (WAN 4) as the fail-over back-up. And, you have the flexibility to convert back to fixed line services when these become available.

Secured Networking

DrayTek Vigor2925 series inherited versatile firewall mechanism from previous Vigor series routers. The firewall allows setting of Call/Data Filters and DoS/DDoS prevention, whereas the CSM covers IM/P2P/Protocol filter, URL Content Filter and Web Content Filter. The object-based design used in SPI (Stateful Packet Inspection) firewall allows users to set firewall policy with ease. The object-based firewall is flexible and allows your network be safe. With Objects settings, you can pre-define objects or groups for IP, service type, keyword, file extension, etc., and mix these with the Time Scheduler or the VLAN groups as required. Altogether this gives you peace of mind whether you are guarding a complicated network or a small office. The DoS/DDoS prevention and URL/Web content filter strengthen the security outside and control inside. The enterprise-level CSM (Content Security Management) enables users to control and manage IM (Instant Messenger) and P2P (Peer-to-Peer) applications more efficiently. The CSM hence prevents inappropriate content from distracting employees and impeding productivity. Furthermore, the CSM can keep office networks threat-free and available.

By adoption of the world-leading Cyren GlobalView Web Content Filtering, you can block whole categories of web sites (e.g. sports, online shopping), subject to an annual subscription to the Cyren GlobalView WCF, which is timely updated with changed or new site categorizations. A free 30-day trial can be activated via activation wizard of Vigor2925 series routers' web user interface.

VLAN for secure and efficient workgroup management

Not only with 5 x Gigabit LAN ports for the needs of unified communication applications, such as CRM server, FTP server, Mail server, the Vigor2925 Series has the comprehensive VLAN function for management. The VLAN functions allow 5 subnets to be allocated for multiple workgroups. When combined with the NAT and firewall functions, you can design corporate network groups in terms of traffic, security level, priority settings, etc.

Applications such as VoIP, IPTV and Wireless SSID can also be integrated into VLAN tags and firewall objects, giving you the maximum flexibility in designing workgroups for your organization.

Comprehensive VPN

For remote teleworkers and inter-office links, Vigor2925 series provide up to 50 simultaneous VPN tunnels (such as IPSec/PPTP/L2TP protocols) for secure data exchange and communication. With a dedicated VPN co-processor, the hardware encryption of AES/DES/3DES and hardware key hash of SHA-1/MD5 are seamlessly handled, thus maintaining maximum router performance. Teleworkers can be authenticated directly with your LDAP server if preferred. The Vigor2925 series are equipped with two Gigabit Ethernet ports and USB WAN ports for WAN load-balancing and backup. The VPN trunking (VPN load-balancing and VPN backup) are hence implemented on Vigor2925 series. With VPN trunking, you can create multiple WAN connections to a remote site in order to increase bandwidth. The VPN trunking also can allow you to have failover (backup) of VPN route through a secondary WAN connection.

With SSL VPN, Vigor2925 series let teleworkers have convenient and simple remote access to central site VPN. The teleworkers do not need to install any VPN software manually. From regular web browser, you can establish VPN connection back to your main office even in a guest network or web cafe. The SSL technology is same as the encryption that you use for secure web sites such as your online bank. The SSL VPNs can be operated in either full tunnel mode or Proxy mode.

For client-to-site, remote dial-in users can use up-to 25 SSL VPN tunnels to avoid the local network infrastructure limitation, , there are 64 profiles on WUI, but it only allows 25 concurrent tunnels.

Multi-subnet

With the 5-port Gigabit switch on the LAN side provides extremely high speed connectivity for the highest speed local data transfer of any server or local PCs. The tagged VLANs (802.1q) can mark data with a VLAN identifier. This identifier can be carried through an onward Ethernet switch to specific ports. The specific VLAN clients can also pick up this identifier as it is just passed to the LAN. You can set the priorities for LAN-side QoS. You can assign each of VLANs to each of the different IP subnets that the router may also be operating, to provide even more isolation. The said functionality is tag-based Multi-subnet.

Each of the wireless SSIDs can also be grouped within one of the VLANs.

With multi-subnet, the traffic can be sent through non-NAT mode with higher performance. If you deploy Vigor2925 series with MPLS network with your main office, the multi-subnet settings will let your data transactions be carried out without NAT.

Centralized Management

With F/W 3.7.4, the embedded Central VPN Management (CVM) will let network administrator register up to 16 remote routers but run concurrent remote management over 8 remote routers.

AP Management

APM provides the 3-step installation, plug-plug-press, and then wireless clients are able to enjoy surfing internet. Moreover, through the unified user interface of Draytek routers, the status of APs is clear at the first sight.

If your network requires several VigorAP900 or VigorAP 810 units, to centrally manage and monitor them individually as a group will be expected. DrayTek central wireless management (AP Management) lets control, efficiency, monitoring and security of your company-wide wireless access easier be managed. Inside the web user interface, we call "central wireless management" as Central AP Management which supports mobility, client monitoring/reporting and load-balancing to multiple APs. For central wireless management, you will need a Vigor2860 or Vigor2925 series router; there is no per-node licensing or subscription required. For multiple wireless clients, to apply the AP Load Balancing to the multiple APs will manage wireless traffic with smooth flow and enhanced efficiency.

1.WAN Feature

  • Ethernet WAN
    • IPv4 - DHCP Client, Static IP, PPPoE, PPTP, L2TP, 802.1p/q Multi-VLAN Tagging
    • IPv6 - Tunnel Mode: PPP, TSPC, AICCU, 6rd* (6rd will be supported by firmware v3.7.3)
      Dual Stack: DHCPv6 Client, Static IPv6
  • USB WAN
    • PPP
  • Outbound Policy-based Load-balance
  • WAN Connection Failover
  • WAN Budgets*
  • 50,000 NAT Sessions

2. Network Feature

  • DHCP Client/Relay/Server
  • IGMP Snooping/Proxy Version 2 and Version 3
  • Dynamic DNS
  • NTP Client
  • Call Scheduling
  • RADIUS Client
  • DNS Cache/Proxy
  • UPnP 30 sessions
  • Multiple Subnets
  • Port-based/Tag-based VLAN (802.1q)
  • Layer-2 QoS (802.1p)
  • Routing Protocol:
    • Static Routing
    • RIP V2
  • Route Policy 

3. VPN

  • Up to 50 VPN Tunnels
  • Protocol : PPTP, IPsec, L2TP, L2TP over IPsec
  • Encryption : MPPE and Hardware-based AES/DES/3DES
  • Authentication : MD5, SHA-1
  • IKE Authentication : Pre-shared Key and Digital Signature (X.509)
  • LAN-to-LAN, Teleworker-to-LAN
  • DHCP over IPsec
  • IPsec NAT-traversal (NAT-T)
  • Dead Peer Detection (DPD)
  • VPN Pass-through
  • VPN Wizard
  • mOTP
  • SSL VPN (Up to 25 Tunnels)
  • VPN Trunk (Load Balance/Backup)

4.Firewall

  • Multi-NAT, DMZ Host, Port-redirection and Open Port
  • Object-based Firewall, Object IPv6, Group IPv6
  • MAC Address Filter
  • SPI (Stateful Packet Inspection) (Flow Track)
  • DoS / DDoS Prevention
  • IP Address Anti-spoofing
  • E-mail Alert and Logging via Syslog
  • Bind IP to MAC Address
  • Time Schedule Control
  • User Management

5. USB

  • 3.5G (HSDPA)/4G (LTE) as WAN
  • Printer Sharing
  • File System : *
    • Support FAT32 File System *
    • Support FTP Function for File Sharing *
    • Support Samba for File Sharing *

6. Bandwidth Management

  • QoS :
    • Class-based Bandwidth Guarantee by User-defined Traffic Categories
    • Guarantee Bandwidth for VoIP
    • DiffServ Code Point Classifying
    • 4-level Priority for Each Direction (Inbound/Outbound)
    • Bandwidth Borrowed
  • Session Limitation
    • Default & Specific Limitation
  • Bandwidth Limitation
    • Default & Specific Limitation
    • Auto Adjustment by Exceeding Session/Available Bandwidth
  • TOS/DSCP QoS Mapping

7. Network Management

  • Web-Based User Interface (HTTP/HTTPS)
  • Quick Start Wizard
  • CLI (Command Line Interface, Telnet/SSH)
  • Administration Access Control
  • Configuration Backup/Restore
  • Built-in Diagnostic Function
  • Firmware Upgrade via TFTP/FTP/HTTP/TR-069
  • Logging via Syslog
  • SNMP Management MIB-II (v2/v3)
  • Management Session Time Out
  • 2-level management (Admin/User Mode)
  • TR-069 
  • TR-104
  • LAN Port Monitoring
  • Support Smart Monitor (Up to 50 nodes)
  • Central AP Management (Up to 20 APs)

8. Content Security Management

  • IM/P2P Applications
  • GlobalView Web Content Filter*
  • URL Content Filter
    • URL Keyword Blocking (Whitelist and Blacklist)
    • Java Applet, Cookies, Active X, Compressed, Executable, Multimedia File Blocking
    • Excepting Subnets

9. Wireless AP

  • IEEE802.11n Compliant (2.4GHz)
  • Wireless Client List
  • Wireless LAN Isolation
  • 64/128-bit WEP
  • WPA/WPA2
  • Hidden SSID
  • WPS
  • MAC Address Access Control
  • Access Point Discovery
  • WDS (Wireless Distribution System)
  • 802.1x Authentication
  • Multiple SSID
  • Wireless Rate-control
  • IEEE802.11e: WMM (Wi-Fi Multimedia)
  • SSID VLAN Grouping with LAN Port*
Specifications
Hardware Interface 2 x 1000Base-TX, RJ-45 (WAN1/WAN2)
5 x 10/100/1000Base-TX LAN, RJ-45 Configurable Physical DMZ on Port1
2 Detachable Antennas
2 x USB Host 2.0 (for Printer/3G USB Modem/USB Disk)
1 x Factory Reset Button
1 x Wireless On/Off/ WPS Button
Temperature

Operation : 0° C ~ 45° C

Storage : -25° C ~ 70° C

Humidity 10% ~ 90 % (Non-codensing)
Power Consumption 15 Watt
Dimension L240.96 x W165.07 x H43.96 ( mm )
Voltage of 802.3af PoE 44v~57v
Adapter DC12V@1.5A

Vigor2925 Series is the IPv6 ready dual WAN broadband security firewall router. It ensures the business continuity for today and the future IPv6 network. Its two gigabit Ethernet WAN port can accept various high-speed Ethernet-based WAN links via FTTx/xDSL/Cable. The 2 USB ports are for 3G/4G LTE mobile broadband access. With the multi-WAN accesses, Vigor2925 routers support bandwidth management functions such as failover and load-balancing, making them ideal solutions for reliable and flexible broadband connectivity for the small business office.

The specifications cover many functions that are required by modern day businesses, including secure but easy to apply firewall, comprehensive VPN capability, Gigabit LAN ports, USB ports for 3G/4G mobile dongles, FTP servers and network printers, VLAN for flexible workgroup management, and much more.


Load-balance and backup

You can combine the bandwidth of the Dual WAN to speed up the transmission through the network. The Gigabit WAN port is ideal for connection to fast Internet feed such as Fiber and VDSL2. The 10/100 Base-Tx port can act as back up or primary WAN, which is suitable for sharing bandwidth of xDSL or cable modem. In case of your primary ISP or DSL line suffering temporary outage, WAN-backup offers you redundancy to let the secondary Internet access temporarily route Internet traffic. All traffic will be switched back to your normal communication port as services are resumed.


VPN backup

The VPN backup ensures the stable LAN-to-LAN (site-to-site) remote access


CVM (Central VPN Management)

VLAN for Secure and Efficent Workgroup Management

AP Management

Security & Productivity -SSID

Flexibility WLAN

Support Smart Monitor up to 50 PC Users

Vigor2925 series with rackmount bracket

Firmware
Firmware Version 3.7.8.1 Vigor2925_v3.7.8.1.zip

Documentation
User's Guide UG_Vigor2925_V3.0.pdf
Datasheet 2925-datasheet-V3-131101.pdf

Product Image
Vigor2925n Vigor2925n.png