- ADSL2+/VDSL2, Gigabit Ethernet WAN port, Dual USB ports for failover and load-balancing
- Two USB ports for connection to two 3.5G/4G LTE USB mobiles, FTP server and network printer
- 6 x Gigabit LAN ports with multiple subnets
- Integrated IEEE 802.11ac wireless Access Point; dual band; up to 1300Mbps throughput
- VoIP (2 x FXS and 1 x FXO Line Port) for Vigor2860Vac
- Object-based SPI Firewall and CSM (Content Security Management) for network security
- VLAN for secure and efficient workgroup management
- 32 VPN tunnels with comprehensive secure protocols
- VPN load-balancing and backup for site-to-site applications
- Embedded Central VPN Management for 8 remote Vigor routers
- Embedded Central AP Management for multi-deployed Vigor wireless access points
- Working with Smart Monitor Network Traffic Analyzer (30-nodes)
- Working with VigorACS SI Central Management for multi-site deployment
Overview
Vigor2860 series security firewall routers have built-in VDSL2/ADSL2+
modem, plus a second Ethernet WAN port for Cable or Satellite
broadband, and 2 USB ports for 3G/4G mobile broadband access. With the
multi-WAN accesses, Vigor2860 series router supports multi-wan fail-over
and load-balancing for USB WANs, VDSL2/ADSL2+, FTTx broadband. If your
premise can not subscribe fixed broadband line, you can rely on the
3G/4G LTE (connected to USB WANs) as primary connection.
The specifications cover many functions that are required by modern day
businesses, including secure but easy to apply firewall, comprehensive
VPN capability, Gigabit LAN ports, USB ports for 3G/4G mobile dongles,
FTP and Samba server and network printers, VLAN for flexible workgroup
management, and much more.
The Vigor2860Vac provides you with 2.4GHz/5GHz dual band WLAN access
point. The Vigor2860Vac plus is with IEEE802.11ac to ensure best
performance and encryption processing. In addition, IEEE802.11ac allows
you to have greater coverage and resilience to interference compared to
previous wireless standards thanks to the Vigor’s antennae diversity
arrangement and the MIMO technology. The Vigor2860Vac plus provides you
with different levels of security including authentication (802.11x),
encryption (up to WPA2) and methods such as DHCP fixing to restrict
access to authorized users only and Mac address locking. Through the Web
User Interface (WUI), you can see how many and which clients are
currently connected and how much bandwidth usage they consume. The
wireless VLAN function lets you isolate wireless clients from each other
or from the “wired” LAN. You can set certain password for your guest to
let guests access your WLAN with “password”. The Web-portal setup
(log-in) can let you have four rules along with 4 multiple SSIDs. When
users connect to your WLAN, they will be directed with your log-in
screen before any Internet access is permitted. You can customize your
Web-portal setup (log-in) page. The multiple SSID features can let your
network administrator set up four common or distinct virtual wireless
access points. e.g. those with SSID1 can access to your ERP, those with
SSID2 can surf internet. With the button of WPS (Wi-Fi protected setup),
your client PC can get its security keys by pressing the WPS button on
front of the router. There are several wireless channels for you to
choose the best channel where is with the least congested wireless
traffic. DrayTek Vigor2860 series are implemented with AP Management to
facilitate deployment of multiple VigorAP 810 SOHO-level access point
and VigorAP 900 enterprise-level access point. You can have overview
over the status of multiple APs. For multiple wireless clients, to apply
the AP Load Balancing to the multiple APs will manage wireless traffic
with smooth flow and enhanced efficiency.
Fail-over and Load Balancing with a second Gigabit Ethernet WAN
The Gigabit Ethernet WAN port caters for any type of Internet access,
including ADSL, Cable or Satellite broadband. You can then use both WAN
1 and WAN 2 for Fail-over, ensuring that you will always have an access
to the Internet even if one of the WAN fails, or for Load Balancing so
the 2 WANs share Internet traffic requirements of your organization.
Comprehensive VPN
For remote teleworkers and inter-office links, Vigor2860 series
provide up to 32 simultaneous VPN tunnels (such as IPSec/PPTP/L2TP
protocols) for secure data exchange and communication. With a dedicated
VPN co-processor, the hardware encryption of AES/DES/3DES and hardware
key hash of SHA-1/MD5 are seamlessly handled, thus maintaining maximum
router performance. Teleworkers can be authenticated directly with your
LDAP server if preferred. The Vigor2860 series are equipped physical DSL
port and Gigabit Ethernet port for WAN load-balancing and backup. The
VPN trunking (VPN load-balancing and VPN backup) are hence implemented
on Vigor2860 series. With VPN trunking, you can create multiple WAN
connections to a remote site in order to increase bandwidth. The VPN
trunking also can allow you to have failover (backup) of VPN route
through a secondary WAN connection.
With SSL VPN, Vigor2860 series let teleworkers have convenient and
simple remote access to central site VPN. The teleworkers do not need to
install any VPN software manually. From regular web browser, you can
establish VPN connection back to your main office even in a guest
network or web cafe. The SSL technology is same as the encryption that
you use for secure web sites such as your online bank. The SSL VPNs can
be operated in either full tunnel mode or Proxy mode. After F/W 3.7.3,
the Vigor2860 series allow up to 16 simultaneous incoming users.
Centralized Management
With F/W 3.7.3, the embedded Central VPN Management (CVM) will let
network administrator register up to 16 remote routers but run
concurrent remote management over 8 remote routers.
AP Management
APM provides the 3-step installation, plug-plug-press, and then
wireless clients are able to enjoy surfing internet. Moreover, through
the unified user interface of Draytek routers, the status of APs is
clear at the first sight.
If your network requires several VigorAP900 or VigorAP 810 units, to
centrally manage and monitor them individually as a group will be
expected. DrayTek central wireless management (AP Management) lets
control, efficiency, monitoring and security of your company-wide
wireless access easier be managed. Inside the web user interface, we
call “central wireless management” as Central AP Management which
supports mobility, client monitoring/reporting and load-balancing to
multiple APs. For central wireless management, you will need a Vigor2860
or Vigor2925 series router; there is no per-node licensing or
subscription required. For multiple wireless clients, to apply the AP
Load Balancing to the multiple APs will manage wireless traffic with
smooth flow and enhanced efficiency.
Multi-subnets
With the 6-port Gigabit switch on the LAN side provides extremely
high speed connectivity for the highest speed local data transfer of any
server or local PCs. The tagged VLANs (802.1q) can mark data with a
VLAN identifier. This identifier can be carried through an onward
Ethernet switch to specific ports. The specific VLAN clients can also
pick up this identifier as it is just passed to the LAN. You can set the
priorities for LAN-side QoS. You can assign each of VLANs to each of
the different IP subnets that the router may also be operating, to
provide even more isolation. The said functionality is tag-based
Multi-subnet.
On the Wireless-equipped models (Vigor2860n/Vigor2860n plus/Vigor2860Vn
plus/Vigor2860ac/Vigor2860Vac) each of the wireless SSIDs can also be
grouped within one of the VLANs.
With multi-subnet, the traffic can be sent through non-NAT mode with higher performance.If you deploy Vigor2860 series with MPLS network with your main office, the multi-subnet settings will let your data transactions be carried out without NAT.
DrayTek IPv6 solutions
We support Dual Stack (PPP, DHCPv6 Client, Static IPv6, 6rd) and
Tunnel Mode (TSPC, AICCU, 6in4 static-tunnel) to let your business
operation successfully be migrated to the era of IPv6. Because the IPv4
addresses are limited and IPv6 allows for a larger address space and
much more efficient routing. The Vigor2860 series support IPv6 and IPv4.
The Vigor2860 series can support IPv6 broker/tunnel services to provide
IPv6 access using either AICCU or TSPC via 3rd party IPv6 providers if
your ISP does not support IPv6 yet.
- can be run on any one of the WAN ports (ADSL/VDSL2, Ethernet or 3G; but the USB WAN port can run AICCU/TSPC tunnel mode only)
- can connect to direct native IPv6 ISPs
- can build tunnel to 3rd party IPv6 brokers using either AICCU or TSPC methods
- Default stateful firewall for all IPv6 LAN clients/ devices
- DHCPv6 Client
- Static IPv6 Client
- DHCPv6 & RADVD (Router Advertisement Server) for client configuration
- QoS for IPv6 with DiffServ
- IP Filtering Rules
- Router Management over IPv6 (Telnet/HTTP) with IPv6 access list
- Concurrent operation with IPv4 (“Dual-Stack”)
- Other router features are only available on IPv4
Multi-task USB functionalities
Through mobility, brought by cellular networks, you can connect
3.5G/4G USB mobile to 2.0 version USB port on Vigor2860 series. This can
be a backup broadband connection if the primary fixed line drops. You
can connect USB disk or hard-drive to USB port for memory storage and
file sharing. The Vigor2860 series provide you with FTP access file
uploading/downloading, which can be used from the local LAN or from
anywhere on the Internet. The access can be using “username and
password” or ‘public’. Each of them can have their own directories
and/or file access rights. The VDSL2/ADSL2+ interface, Gigabit Ethernet
interface and USB mobile can be used either for WAN-backup or load
balancing.
Secured networking
DrayTek Vigor2860 series inherited versatile firewall mechanism from
previous Vigor series routers. The object-based design used in SPI
(Stateful Packet Inspection) firewall allows users to set firewall
policy with ease. Object-based firewall is flexible and allows your
network be safe. DoS/DDoS prevention and URL/Web content filter
strengthen the security outside and control inside. The enterprise-level
CSM (Content Security Management) enables users to control and manage
IM(Instant Messenger) and P2P (Peer-to-Peer) applications more
efficiently. The CSM hence prevents inappropriate content from
distracting employees and impeding productivity. Furthermore, the CSM
can keep office networks threat-free and available.
By adoption of the world-leading CYREN GlobalView Web Content
Filtering, you can block whole categories of web sites (e.g. sports,
online shopping), subject to an annual subscription to the CYREN
GlobalView WCF, which is timely updated with changed or new site
categorizations. A free 30-day trial can be activated via activation
wizard of WUI.
The “User Management” implemented on your router firmware can allow
you to prevent any computer from accessing your Internet connection
without a username or password. You can set scheduler or maximum usage
time to your employees within office network. The user accounts can also
be restricted by any other aspect of the firewall rule on a
user-by-user basis.
Vigor2860 series support DrayTek’s SmartMonitor network traffic
analyzer (up to 30 users), which captures actual live data of activities
in your managed network, such as the content of MSN entering to or out
of your network. You can track specified files download/upload or view
statistics on data type activities to realize what corporate related
information have been released accidentally or on purpose.
Integration of Telephony
It supports multiple SIP Registrars with high flexible configuration and call handing options. You can connect your regular analogue line (PSTN/POTS*) to the Line port of Vigor2860Vac. While you enable VoIP facility, you still can access fixed line (analogue line) to make calls just by dialing #0. The phone connected to two FXS ports (via analogue phone adapter) can be used for both analogue calls and VoIP calls because the incoming calls are automatically switched through to your telephone(s) (either one or both). As a result, both analogue telephones plugged into your router allow you to access VoIP and analogue line. Furthermore, you can set rules through “Digit Map” function about particular call destinations using either your SIP/VoIP service or the POTS line. For example, you can route local calls via your PSTN line (if you have a free calls package) whereas international calls go via your preferred VoIP provider; there is flexibility to have several Digit Map rules.
Dashboard implementing in DrayTek Vigor2860 series summarizes the status of WAN/LAN/WLAN/VPN
The feature of tag-based Multi-subnets helps business isolate different work groups, preventing important and valuable information from any leakage.
On the Wireless-equipped models, each of the wireless SSIDs can also be grouped within one of the VLANs
Features
- VDSL2/ADSL2/2+
- ITU-T G.993.2 (VDSL2)
- ITU-T G.992.1/3/5 (ADSL1/2/2+) Annex A & Annex B
- DSL Forum Performance Speci?cation: ADSL TR-048/67, TR-100; VDSL: WT-114
- Erasure Decoding, Increased Interleaver Depth and Re-transmission
- EFM (IEEE 802.3 ah)
- VDSL2 Profile: up to 30a
- WAN Protocol
- DSL (WAN-1)/Giga Ethernet (WAN-2)
- DHCP Client
- Static IP
- PPPoE
- PPTP / L2TP (WAN-2 only)
- PPPoA (ADSL2 only)
- 802.1q Multi-VLAN Tagging
- USB (WAN-3)
- IPv6
- Tunnel Mode: TSPC, AICCU, 6rd, Static 6in4
- Dual Stack: PPP, DHCPv6 Client, Static IPv6
- USB
- 3.5G (HSDPA) as WAN
- Printer Sharing
- File System :
- Support FAT32 File System
- Support FTP Function for File Sharing
- Support Samba for File Sharing
- LTE USB mobile Support List Please Contact [email protected]
- VPN
- Up to 32 VPN Tunnels
- Protocol : PPTP, IPsec, L2TP, L2TP over IPsec
- Encryption : MPPE and Hardware-based AES/DES/3DES
- Authentication : MD5, SHA-1
- IKE Authentication : Pre-shared Key and Digital Signature (X.509)
- LAN-to-LAN, Teleworker-to-LAN
- DHCP over IPsec
- IPsec NAT-traversal (NAT-T)
- Dead Peer Detection (DPD)
- VPN Pass-through
- VPN Wizard
- mOTP
- SSL VPN: 16 Tunnels
- VPN Trunk (Load Balance/Backup)
- Multi-WAN
- Load-Balance/Route Policy(The VDSL2/ADSL2+ interface, Gigabit
Ethernet interface and USB mobile can be used either for WAN-backup or
load balancing.)
- WAN Connection Failover
- CSM (Content Security Management)
- IM/P2P Application
- GlobalView Web Content Filter (Powered by )
- URL Content Filter :
- URL Keyword Blocking (Whitelist and Blacklist)
- Java Applet, Cookies, Active X, Compressed, Executable, Multimedia File Blocking
- Excepting Subnets
- Bandwidth Management
- QoS
- Guarantee Bandwidth for VoIP
- Class-based Bandwidth Guarantee by User-defined Traffic Categories
- DiffServ Code Point Classifying
- 4-level Priority for Each Direction (Inbound/Outbound)
- Bandwidth Borrowed
- Bandwidth/Session Limitation
- Layer-2 (802.1p) and Layer-3 (TOS/DSCP) QoS Mapping
- Network Feature
- Packet Forwarding Acceleration *
- DHCP Client/Relay/Server
- IGMP Snooping/Proxy V2 and V3
- Triple-Play Application
- Dynamic DNS
- NTP Client
- Call Scheduling
- RADIUS Client
- DNS Cache/Proxy and LAN DNS
- UPnP 30 sessions
- Multiple Subnets
- Port-based/Tag-based VLAN (802.1q)
- Routing Protocol:
- Network Management
- Web-based User Interface (HTTP/HTTPS)
- Quick Start Wizard
- CLI (Command Line Interface, Telnet/SSH)
- Administration Access Control
- Configuration Backup/Restore
- Built-in Diagnostic Function
- Firmware Upgrade via TFTP/FTP/HTTP/TR-069
- Logging via Syslog
- SNMP Management MIB-II
- Management Session Time Out
- 2-level Management (Admin/User Mode)
- TR-069
- TR-104
- LAN Port Monitoring
- Support Smart Monitor (30 nodes)
- Central AP Management
- Central VPN Management (Up to 8 Remote Routers)
- Firewall
- Multi-NAT, DMZ Host, Port-redirection and Open Port
- Object-based Firewall, Object IPv6, Group IPv6
- MAC Address Filter
- SPI (Stateful Packet Inspection) (Flow Track)
- DoS/DDoS Prevention
- IP Address Anti-spoofing
- E-mail Alert and Logging via Syslog
- Bind IP to MAC Address
- Time Schedule Control
- User Management
- Wireless AP
- 802.11ac WLAN with Concurrent 2.4/5 GHz Frequency
- Wireless Client List
- Wireless LAN Isolation
- 64/128-bit WEP
- WPA/WPA2
- Wireless Wizard
- Hidden SSID
- WPS
- MAC Address Access Control
- Access Point Discovery
- WDS (Wireless Distribution System)
- 802.1x Authentication
- Multiple SSID
- Wireless Rate-control
- IEEE802.11e: WMM (Wi-Fi Multimedia)
- SSID VLAN Grouping with LAN Port (Port-based VLAN)
- VOIP
- Protocol: SIP, RTP/RTCP
- 12 SIP Registrars
- G.168 Line Echo-cancellation
- Jitter Buffer
- WPA/WPA2
- Voice codec:
- G.711
- G.732.1
- G.726
- G.729 A/B
- VAD/CNG
- DTMF Tone:
- Inband
- Outband (RFC-2833)
- SIP Info
- Fax/Modem Support:
- Tone Detection
- G.711 Pass-through
- T.38
- Supplemental Services:
- Call Hold/ Retrieve/ Waiting
- Call Waiting with Caller ID
- Call Transfer
- Call Forwarding (Always, Busy and No Answer)
- Call Barring (Incoming/Outgoing)
- DND (Do Not Disturb)
- MWI (Message Waiting Indicator)(RFC-3842)
- Hotline
- Secure Phone (ZRTP + SRTP)
- PSTN Loop-through When Power Failure
- Dial Plan:
- Phone Book
- Digital Map
- Call Barring
- Regional
Specifications:
Interface of Vigor2860Vac
|
Hardware Interface |
LAN |
6 x 10/100/1000Base-Tx LAN Switch, RJ-45
|
WAN |
1 x VDSL2/ADSL2/2+ WAN Port (WAN1), RJ-11 for Annex A/RJ-45 for Annex B
|
1 x 10/100/1000Base-Tx, RJ-45 (WAN2)
|
USB |
2 x USB Host 2.0 |
3 x Detachable Antennas
|
2 x FXS and #1 x Life Line Port, RJ11
|
1 x Factory Reset Button |
1 x Wireless On/ Off/ WPS Button |
Temperature |
Operating : 0°C ~ 45°C |
Storage : -25°C ~ 70°C |
Humidity |
10% ~ 90% (non-condensing) |
Max. Power |
24 Watt |
Dimension |
L241 * W165 * H44 (mm) |
Power |
DC 12V @ 1.5A ~ 2A |