Vigor3912 is designed for bandwidth-demanding networks, featuring a 2GHz Quad-Core CPU for fast connection speed, even with multiple connected devices. The router has 8 WAN interface, including 2x 10G SFP+ for fiber connectivity, 2x 2.5G Ethernet, and 4x 1G Ethernet, providing ultra-fast NAT throughput. Port1 to port8 are configurable independently for WAN or LAN to offer flexibility and optimize the router performance.
Vigor3912 can serve as a VPN server to establish LAN-to-LAN or remote dial-in VPN connections. It includes SMB-friendly features like VPN 2FA authentication and VPN from LAN, ensuring a more secure and efficient VPN network.
including 10G SFP+ and 2.5G Ethernet
provides 15.6 Gbps NAT throughput*
provides 5.7 Gbps IPsec throughput*
Reserve 2048 entries for Bind-IP-to-MAC
*bi-directional(TX+RX) performance
12x USB 3.0
2Reset Button
3RJ-45 Console Port
42x 10G/2.5G/1G SFP+ Port*
52x 2.5G/1G/100M/10M Base-T, RJ-45*
64x 1G/100M/10M Base-T, RJ-45*
74x 1G/100M/10M Base-T, RJ-45
*WAN/LAN Switchable
*bi-directional(TX+RX) performance
This feature optimizes the processing and forwarding of data packets, resulting in quicker transmission and minimizing network latency. It is beneficial for real-time applications such as online gaming or voice calls, enhancing network efficiency and providing a better network experience for users.
Offer excellent performance for bandwidth-demanding enterprise networks.
Provides 2x 10G-capable fiber SFP ports for WAN or LAN connection.
Maximize throughput and reliability by using multiple Internet connections. Learn more
Build a secure and private tunnel from the LAN of Vigor3912 to the remote offices and teleworkers over the Internet. Learn more
The VPN works through firewalls providing secure remote access to any network environment. Learn more
Enhance the security for remote VPN connections and eliminate the cost for an official authentication system. Learn more
Helps routers behind NAT to find each other and establish a LAN-to-LAN VPN. Learn more
Use Point-to-Point connection on LAN to keep track of individual user's traffic. Setup Guide
Market your business and communicate with the guests while offering hospitality WLAN. Learn more
Prevent one device using all the bandwidth by bandwidth limit policy, session limit policy, and QoS settings.
Filter web pages by URL keyword or web category to block access to insecure or inappropriate contents.
The free DDNS service for you to access the router by a fixed hostname of your choice. Learn more
Use the Vigor3912 router as a wireless controller to maintain and monitor the VigorAPs. Learn more
Set up VLAN easily from the router and get a centralized hierarchy view of the switches. Learn more
An ideal choice to work with tier 2/3 ISPs and co-working spaces
For both NAT and routing network, and for both 10G-WAN and 10G-LAN, Vigor3912 is ready to deliver high throughput to your business.
With the most popular Exterior and Interior Gateway Protocols, Vigor3912 is ideal for ISP deployment.
With 200 PPPoE user accounts and 100 VLAN/LAN subnets, Vigor3912 provides up to 15.6 Gbps throughput(bi-directional), and makes subletting network infrastructure secure and easy.
A more secure way to connect to the servers, restricting LAN clients's access to LAN servers through VPN only. This means that data transmission between LAN clients and the server will be encrypted by VPN, thereby protecting critical data and enhancing security.
Opening a PC/laptop and activating a VPN connection to access the company's internet for work has become a common working routine nowadays.
When a teleworker connects to the company's VPN, not only can they reach the company's server, but VPN users can also access each other. However, these connections between VPN users are unnecessary and may pose security risks. By simply enabling "Isolate VPN Users from each other" option, each VPN user can be isolated, creating a secure VPN network.
Using two-factor with AD/LDAP server enhances the security of remote dial-in VPN connections. DrayTek provides various authentication methods, including TOTP, Email, SMS, or URL links. This not only adds an extra layer of security but also helps save the expense of SMS messages or license fees for the official authentication systems.
Vigor Router provides a management platform for your Vigor Devices on the LAN
Automatically discover LAN subnets and add detected VigorSwitch/AP into managed list.
Most-frequent used settings can be pre-defined on the Vigor Router, and provision to the managed VigorSwitch/AP.
Vigor Router provides a centralized view of managing devices, you may always check if the managed Vigor Switch/AP is online.
Support basic maintenance remotely via Vigor Router. Such as remote reboot, factory reset, configuration backup/restore, etc.
Auto-Discovery, Provisioning, Monitoring, Centralized Hierarchy View, Reboot PoE Devices Remotely, Quick VLAN Configuration
Auto-Discovery, Provisioning, Monitoring, Centralized View, Alarm, Reboot VigorAP Remotely, Wi-Fi Client Load Balancing
Note :The stated throughput performance figures are the maximum derived from DrayTek internal testing, conducted under optimal conditions, with Hardware Acceleration enabled where available. The actual performance may vary based on network conditions and activated applications.
Model |
Performance |
NAT Session | Max. NAT (Mbps) | Max. NAT with Hardware Acceleration (Mbps) | Max. NAT with Hardware Acceleration : Single WAN (Mbps) | Max. NAT with Hardware Acceleration : Dual WAN (Mbps) | Max. NAT with Software Acceleration (single-directional) (Mbps) | Max. NAT with Software Acceleration (bi-directional) (Mbps) | Max. VDSL Link Rate (Mbps) | Max. ADSL Link Rate (Mbps) | WAN |
Ethernet (GbE) | Switchable WAN/LAN (GbE) | xDSL | VDSL Standards | VDSL2 Profile | G.fast Profile | ADSL Standards | Other Standards | Band Plan | SFP | SFP (WAN/LAN Switchable) | SFP/Ethernet Combo (WAN/LAN Switchable) | Cellular (via USB) | Cellular (Built-in) | Wireless WAN (2.4GHz or 5GHz) | Wireless WAN (2.4GHz + 5GHz) | 4G LTE |
LTE Category | LTE Antenna (External Dipole) | SIM Slot | Max. Rx Link Rate (Mbps) | Max. Tx Link Rate (Mbps) | FDD Band | TDD Band | WCDMA (3G) Band | SMS Gateway | 5G |
5G Band | 5G NSA Max. Rx Link Rate (Mbps) | 5G NSA Max. Tx Link Rate (Mbps) | 5G SA Max. Rx Link Rate (Mbps) | 5G SA Max. Tx Link Rate (Mbps) | Internet Connection |
IPv4 | IPv6 | LTE WAN Bridge | 802.1p/q Multi-VLAN Tagging | Multi-VLAN/PVC | Virtual WAN | PPPoE Pass-Through | MPoA Bridge | Failover | Load Balancing | WAN Active on Demand | Connection Detection | WAN Data Budget | Dynamic DNS | DrayDDNS | LAN |
Fixed LAN (RJ-45, GbE) | LAN Subnet | DMZ Port | VLAN | Max. Number of VLAN | DHCP Server | IPv6 Address Assignment | LAN IP Alias | IP Pool Count | PPPoE Server | Wired 802.1x Authentication | Port Mirroring | Local DNS Server | Conditional DNS Forwarding | Hotspot Web Portal (Profile No.) | Hotspot Authentication | Other Ports |
Console (RJ-45) | USB | USB Type | FXS (RJ-11) | Networking |
Routing | Policy-based Routing | Smart Action | High Availability | DNS Security (DNSSEC) | IGMP | Local RADIUS server | SMB File Sharing (Requires external storage) | VPN |
LAN-to-LAN | Teleworker-to-LAN | Protocols | Max. VPN Tunnels | Max. OpenVPN + SSL VPN Tunnels | IPsec VPN Throughput (AES 256 bits) (single-directional) (Mbps) | IPsec VPN Throughput (AES 256 bits) (bi-directional) (Mbps) | SSL VPN Throughput (single-directional) (Mbps) | SSL VPN Throughput (bi-directional) (Mbps) | Wireguard VPN Throughput (single-directional) (Mbps) | Wireguard VPN Throughput (bi-directional) (Mbps) | User Authentication | IKE Authentication | IPsec Authentication | Encryption | VPN Trunk (Redundancy) | Single-Armed VPN | NAT-Traversal (NAT-T) | VPN from LAN | VPN Isolation | VPN Packet Capture | VPN 2FA Authentication for AD/LDAP | VPN Matcher | Firewall & Content Filtering |
NAT | ALG (Application Layer Gateway) | VPN Pass-Through | IP-based Firewall Policy | Content Filtering | DoS Attack Defense | Spoofing Defense | Bandwidth Management |
IP-based Bandwidth Limit | IP-based Session Limit | QoS (Quality of Service) | VoIP Prioritization | APP QoS | WLAN |
2.4G WLAN | 5G WLAN | Antennas | Antenna Type | 2.4G Gain (dBi) | 5G Gain (dBi) | 2.4G Max. Link Rate (Mbps) | 5G Max. Link Rate (Mbps) | Max. Number of SSIDs per band | Security Mode | Authentication | WiFi 6 | OFDMA | WPS | WDS | Access Control | AirTime Fairness | Band Steering | WMM | Mesh (5G Only) | VoIP |
Protocols | SIP Registrars | Dial Plan | Call Features | Voice Codec | Caller ID | Management |
Local Service | Config Backup/Restore | Config File Compatibility | Firmware Upgrade | 2-Level Administration Privilege | Access Control | Notification Alert | Netflow | SNMP | Syslog | Broadcast DSL Info to LAN | VPN Managment | AP Managment (APM) | Mesh (Number of manageable APs) | Switch Management (SWM) | VigorACS Management (Since f/w) | Physical |
Power Input | Max. Power Consumption (watts) | Dimension (mm) | Weight (g) | Operating Temperature | Storage Temperature | Operating Humidity (non-condensing) |
Vigor3912 |
K | 0 | 0 | 0 | 9450 | 156000 | - | - | 0 | 6 | 0 | 0 | 2 | 0 | - | - | - | F | - | - | - | - | - | F Learn More | - | - | - | - | PPPoE DHCP Static IP |
PPP DHCPv6 Static IPv6 TSPC AICCU 6rd 6in4 Static Tunnel |
F | T | T | F | F | F | T | IP-based, Session-based | Link Failure, Traffic Threshold | ARP, Ping, Strict ARP | T | T | T | 4 | 100 | - | 802.1q Tag-based VLAN Port-based VLAN |
100 | Multiple IP Subnet Custom DHCP Options Bind-IP-to-MAC |
T | 4000 | T | F | T | T | T | 4 | Click-Through Social Login SMS PIN RADIUS External Portal Server |
1 | 2 | 3.0 | - | IPv4 Static Route IPv6 Static Route Policy Route Inter-VLAN Route Fast Routing RIP v1/v2 BGP OSPFv2 |
Protocol IP Address Port Domain Country |
T | T | T | IGMP v2/v3 IGMP Proxy IGMP Snooping & Fast Leave |
T | F | T | T | PPTP L2TP IPsec L2TP over IPsec SSL GRE IKEv2 IPsec-XAuth OpenVPN(Host to LAN) Wireguard |
500 | 200 | 3300 | 5700 | 3300 | 4300 | 900 | 1080 | Local RADIUS LDAP TACACS+ mOTP TOTP |
Pre-Shared Key, X.509, XAuth, EAP | SHA-1, SHA-256, SHA-512, MD5 | MPPE DES 3DES AES |
Load Balancing, Failover | T | T | T | T | T | T | T | Port Redirection Open Ports Port Triggering Port Knocking Fast NAT DMZ Host UPnP Server Load Balance |
SIP, RTSP, FTP, H.323 | PPTP, L2TP, IPsec | T | APP URL Keyword DNS Keyword Web Features Web Category*(*subscription required) |
T | T | T | T | TOS DSCP 802.1p IP Address Service Type |
T | T | 0 | 0 | 0 | - | F | F | F | F | F | - | HTTP HTTPS Telnet SSH v2 FTP TR-069 |
T | - | TFTP, HTTP, TR-069 | T | Access List, Brute Force Protection | SMS, E-mail | v1, v2c, v3 | T | F | 0 | 50 | - | 30 | V4.3.5.1 | AC 100~240V @ 0.6A | 35 | 443 x 285 x 45 | 3350 | 0 to 45°C | -10 to 55°C | 10 to 90% |
{ "NAT Session":"K", "Max. NAT (Mbps)":"", "Max. NAT with Hardware Acceleration (Mbps)":"0", "Max. NAT with Hardware Acceleration : Single WAN (Mbps)":"0", "Max. NAT with Hardware Acceleration : Dual WAN (Mbps)":"0", "Max. NAT with Software Acceleration (single-directional) (Mbps)":"9450", "Max. NAT with Software Acceleration (bi-directional) (Mbps)":"156000", "Max. VDSL Link Rate (Mbps)":"-", "Max. ADSL Link Rate (Mbps)":"-", "Ethernet (GbE)":"0", "Switchable WAN/LAN (GbE)":"6", "xDSL":"0", "VDSL Standards":"", "VDSL2 Profile":"", "G.fast Profile":"", "ADSL Standards":"", "Other Standards":"", "Band Plan":"", "SFP":"0", "SFP (WAN/LAN Switchable)":"2", "SFP/Ethernet Combo (WAN/LAN Switchable)":"0", "3G/4G/LTE (via USB)":"-", "3G/4G/LTE (Built-in)":"-", "Wireless WAN (2.4GHz or 5GHz)":"-", "Wireless WAN (2.4GHz + 5GHz)":"F", "LTE Category":"-", "LTE Antenna (External Dipole)":"-", "SIM Slot":"-", "Max. Rx Link Rate (Mbps)":"-", "Max. Tx Link Rate (Mbps)":"-", "FDD Band":"", "TDD Band":"", "WCDMA (3G) Band":"", "SMS Gateway":"F", "5G Band":"", "5G NSA Max. Rx Link Rate (Mbps)":"-", "5G NSA Max. Tx Link Rate (Mbps)":"-", "5G SA Max. Rx Link Rate (Mbps)":"-", "5G SA Max. Tx Link Rate (Mbps)":"-", "IPv4":"PPPoEDHCPStatic IP", "IPv6":"PPPDHCPv6Static IPv6TSPCAICCU6rd6in4 Static Tunnel", "LTE WAN Bridge":"F", "802.1p/q Multi-VLAN Tagging":"T", "Multi-VLAN/PVC":"T", "Virtual WAN":"F", "PPPoE Pass-Through":"F", "MPoA Bridge":"F", "Failover":"T", "Load Balancing":"IP-based, Session-based", "WAN Active on Demand":"Link Failure, Traffic Threshold", "Connection Detection":"ARP, Ping, Strict ARP", "WAN Data Budget":"T", "Dynamic DNS":"T", "DrayDDNS":"T", "Fixed LAN (RJ-45, GbE)":"4", "LAN Subnet":"100", "DMZ Port":"-", "VLAN":"802.1q Tag-based VLANPort-based VLAN", "Max. Number of VLAN":"100", "DHCP Server":"Multiple IP SubnetCustom DHCP OptionsBind-IP-to-MAC", "IPv6 Address Assignment":"", "LAN IP Alias":"T", "IP Pool Count":"4000", "PPPoE Server":"T", "Wired 802.1x Authentication":"F", "Port Mirroring":"T", "Local DNS Server":"T", "Conditional DNS Forwarding":"T", "Hotspot Web Portal (Profile No.)":"4", "Hotspot Authentication":"Click-ThroughSocial LoginSMS PINRADIUSExternal Portal Server", "Console (RJ-45)":"1", "USB":"2", "USB Type":"3.0", "FXS (RJ-11)":"-", "Routing":"IPv4 Static RouteIPv6 Static RoutePolicy RouteInter-VLAN RouteFast RoutingRIP v1/v2BGPOSPFv2", "Policy-based Routing":"ProtocolIP AddressPortDomainCountry", "Smart Action":"T", "High Availability":"T", "DNS Security (DNSSEC)":"T", "IGMP":"IGMP v2/v3IGMP ProxyIGMP Snooping & Fast Leave", "Local RADIUS server":"T", "SMB File Sharing (Requires external storage)":"F", "LAN-to-LAN":"T", "Teleworker-to-LAN":"T", "VPN Protocols":"PPTPL2TPIPsecL2TP over IPsecSSLGREIKEv2IPsec-XAuthOpenVPN(Host to LAN)Wireguard", "Max. VPN":"500", "Max. OpenVPN + SSL VPN":"200", "IPsec VPN (AES 256 bits) (single-directional) (Mbps)":"3300", "IPsec VPN (AES 256 bits) (bi-directional) (Mbps)":"5700", "SSL VPN (single-directional) (Mbps)":"3300", "SSL VPN (bi-directional) (Mbps)":"4300", "Wireguard VPN (single-directional) (Mbps)":"900", "Wireguard VPN (bi-directional) (Mbps)":"1080", "User Authentication":"LocalRADIUSLDAPTACACS+mOTPTOTP", "IKE Authentication":"Pre-Shared Key, X.509, XAuth, EAP", "IPsec Authentication":"SHA-1, SHA-256, SHA-512, MD5", "Encryption":"MPPEDES3DESAES", "VPN Trunk (Redundancy)":"Load Balancing, Failover", "Single-Armed VPN":"T", "NAT-Traversal (NAT-T)":"T", "VPN from LAN":"T", "VPN Isolation":"T", "VPN Packet Capture":"T", "VPN 2FA Authentication for AD/LDAP":"T", "VPN Matcher":"T", "NAT":"Port RedirectionOpen PortsPort TriggeringPort KnockingFast NATDMZ HostUPnPServer Load Balance", "ALG (Application Layer Gateway)":"SIP, RTSP, FTP, H.323", "VPN Pass-Through":"PPTP, L2TP, IPsec", "IP-based Firewall Policy":"T", "Content Filtering":"APPURL KeywordDNS KeywordWeb FeaturesWeb Category*(*subscription required)", "DoS Attack Defense":"T", "Spoofing Defense":"T", "IP-based Bandwidth Limit":"T", "IP-based Session Limit":"T", "QoS (Quality of Service)":"TOSDSCP802.1pIP AddressService Type", "VoIP Prioritization":"T", "APP QoS":"T", "2.4G WLAN":"", "5G WLAN":"", "Antennas":"0", "Antenna Type":"", "2.4G Gain (dBi)":"", "5G Gain (dBi)":"", "2.4G Max. Link Rate (Mbps) ":"0", "5G Max. Link Rate (Mbps)":"0", "Max. Number of SSIDs per band":"-", "Security Mode":"", "Authentication":"", "WiFi 6":"F", "OFDMA":"F", "WPS":"", "WDS":"", "Access Control WLAN":"", "AirTime Fairness":"F", "Band Steering":"F", "WMM":"F", "Mesh (5G Only)":"", "Protocols":"", "SIP Registrars":"-", "Dial Plan":"", "Call Features":"", "Voice Codec":"", "Caller ID":"", "Local Service":"HTTPHTTPSTelnetSSH v2FTPTR-069", "Config Backup/Restore":"T", "Config File Compatibility":"-", "Firmware Upgrade":"TFTP, HTTP, TR-069", "2-Level Administration Privilege":"T", "Access Control":"Access List, Brute Force Protection", "Notification Alert":"SMS, E-mail", "Netflow":"", "SNMP":"v1, v2c, v3", "Syslog":"T", "Broadcast DSL Info to LAN":"F", "VPN Managment":"0", "AP Managment (APM)":"50", "Mesh (Number of manageable APs)":"-", "Switch Management (SWM)":"30", "VigorACS Management (Since f/w)":"V4.3.5.1", "Power Input":"AC 100~240V @ 0.6A", "Max. Power Consumption (watts)":"35", "Dimension (mm)":"443 x 285 x 45", "Weight (g)":"3350", "Operating Temperature":"0 to 45°C", "Storage Temperature":"-10 to 55°C", "Operating Humidity (non-condensing)":"10 to 90%" }
Note :The stated throughput performance figures are the maximum derived from DrayTek internal testing, conducted under optimal conditions, with Hardware Acceleration enabled where available. The actual performance may vary based on network conditions and activated applications.