Vigor 2862 Series


VDSL2 & ADSL2+ Dual-WAN Security Router

* 1 VDSL2/ADSL2+ RJ-11 WAN Port
* 1 Gigabit Ethernet WAN Port
* 2 USB ports for 3G/4G cellular modem, network storage, or USB temperature sensor
* Up to 4 WAN for Load Balancing or Failover
* VDSL2 Bonding Support (B/Bn model)
* 802.11ac Wave 2 dual-band wireless for speed up to 1.7 Gbps (ac/Vac model)
* 32 Simultaneous VPN Tunnels for remote offices or teleworkers
* SPI Firewall with Content Filtering
* Central Management for VigorAP & Vigor Switch

Vigor2862 Series is a VDSL2/ADSL2+ Security Firewall router which is compatible with variants of ADSL and VDSL, VDSL bonding is also supported on model Vigor2862B and Vigor2862Bn. All the models have an RJ-11 DSL port, and a Gigabit Ethernet WAN port which can be used with a cable-modem to connect to a second line for load balancing or failover, there are also two USB ports which can work with 3G/4G/LTE USB modems to add wireless connectivity. Vigor2862 Series features comprehensive firewall and content security management (CSM) to secure the local network.It can also be a central management portal for Vigor APs and Vigor Switches, providing Network Administrator a simpler way to maintain all the network devices.

Comprehensive DSL Connectivity

The VDSL/ADSL modem built-in Vigor2862 Series is compatible with various versions of xDSL, including ADSL, ADSL2, ADSL2+, VDSL, and VDSL2, automatically fall back is also supported. The Vigor2862”B” and Vigor2862”Bn” also supports VDSL2 bonding, the technology that combines 2 VDSL lines into a aggregated connection of double throughput, thus are compatible with the DSL services provided through bonded VDSL.

WAN Load Balancing & Failover

Except for the DSL interface, there is also a Gigabit Ethernet WAN port that can be used for any types of connection and add an additional connectivity to share the traffic load. 3G/4G/LTE USB modem can also be attached to the USB ports of the router, and offer wireless Internet connectivity in case the fixed lines are not available, In fact, all of the WAN interfaces can be configured to operated in either Load Balancing mode, which will be active all the time, or in Failover mode, which will be active only when detecting connection loss or heavy load on the primary connection.

On Vigor2862 Series, Load Balancing can be set in either IP-based mode, which means the packets destined to different IP address will be distributed across different WANs, or Session-based mode, which means the packets belong to different sessions can take different paths, this allows a multiple-session connection to be established across multiple WANs, and the maximum data rate will be all the WAN's bandwidth combined. Policy-based Load Balancing is also supported so that you may specify the path for some certain packets.

To increase network accessibility more, Vigor2862 Series also support High Availability feature and allows one or more redundant Vigor2862B Series to be added to the network and operated in standby mode.

Flexible LAN Management

The 4-port Gigabit Ethernet switch on the LAN side provides high-speed connectivity for the servers and PCs on the local network, and the Virtual LAN (VLAN) features allow you to separate the LAN clients into different logical domains thus to increase the security and network efficiency. Vigor2862 Series support 802.1Q standard and can build a Tag-based VLAN system with an 802.1Q-support switch, Port-based VLAN is also supported that each LAN port can be configured as a member of different VLAN and be isolated from each other without the use of VLAN tag. Moreover, up to 8 IP subnet can be set up on Vigor2862 Series, so each VLAN can use different IP addressing space.

Vigor2862 Series has implemented an integrated solution to work as a public Wi-Fi hotspot. While providing Internet access to the guest users, the Hotspot Web Portal can be used to collect the users' information, informing the terms and conditions, and presenting a landing page to them.

Firewall & Security

Vigor2862 Series support Stateful Packet Inspection (SPI) Firewall and flexible filtering rules, it can accept or deny packets based on the information in the packet header (such as source IP, destination IP, protocol, and port number) or the packet's application. IP-based restrictions can be set to filter certain HTTP traffic as well as various application software and help you to prevent time and network resource wasting on inappropriate network activities.

With an annual subscription to Cyren Web Content Filtering service, you may also filter the websites by their categories, and set up restrictions to block the whole categories of websites (such as Social Networking, Gambling.. etc.) without the need to specify every site you would like to block. The Cyren service is constantly updating the categorization, and a free 30-day trial is included in every new router.

The Vigor2862 Series firewall also includes DoS (Denial of Service) Defense to protect the network against variants of attacks.

Comprehensive VPN

Vigor2862 Series support both LAN-to-LAN VPN and Remote Dial-in VPN, up to 32 VPN tunnels can be set up simultaneously. All the industry standard tunneling protocols are supported, including PPTP, L2TP, IPsec, and GRE, and it's compatible with 3rd party VPN devices.

Vigor2862 Series also support SSL VPN - a type of VPN based on the very common encryption method which is used by all the HTTPS websites. While the traditional VPN protocols might be filtered by the firewall and NAT of public networks, SSL VPN will be passed as long as the HTTPS is allowed. DrayTek also offers free official client App for Windows, iOS, and Android.

VPN Trunking is also supported by Vigor2862 Series, this allows you establish two VPN tunnels to the same remote site but through different WAN interfaces. The two trunking tunnels can be set up in load balancing or failover mode.

Central Management

Vigor2862 Series can act as a Central Management portal for all the Vigor devices on the network, including VigorAPs, Vigor Switches, and even Vigor Routers. With Central Management feature, device maintenance (such as firmware upgrading, configuration backup and restore) and monitoring can all be done from a single portal, which is the Web User Interface of Vigor2862 Series.

Vigor2862 Series can manage up to 20 VigorAP on its LAN. Automatic Provisioning can be triggered when a VigorAP newly join the network and this makes AP deployment much faster. You may also get the client or traffic history of all the AP from Vigor2862B Series, and set up load balancing rules for the AP.

Central Switch Management allows you to manage up to 10 Vigor Switches from Vigor2862 Series, the status of every port can be directly viewed from the router. Vigor2862 Series also support VLAN configuration for the switches, setting that matches the router's VLAN settings and the switch hierarchy is automatically provided which makes the VLAN configuration much simplified

* ANSI T1.413 (ADSL)
* ITU G.992.1 G.dmt (ADSL)
* ITU G.992.2 G.lite (ADSL)
* ITU G.992.3 (ADSL2)
* ITU G.992.3 Annex M/J (ADSL2)
* ITU G.992.5 (ADSL2+)
* AITU G.992.5 Annex M/J (ADSL2+)
* ITU G.993.1 (VDSL), ITU-T G997.1
* ITU G.993.2 (VDSL2)
* VDSL Band Plan: 997, 998
* VDSL2 Profile: 8a, 8b, 8c, 8d, 12a, 12b, 17a, 30a
* Support fallback to ADSL2/2+ when fail to connect in VDSL2
* xDSL WAN    * DHCP Client
    * Static IP
    * PPPoE (and pass through)
    * PPPoA
    * MPoA
    * 802.1p/q VLAN Tagging
    * Default VLAN/PVC profile by region
* Giga Ethernet WAN    * DHCP Client
    * Static IP
    * PPPoE
    * PPTP
    * L2TP
    * 802.1q VLAN Tagging
    * Support PPP / DHCP mode (for 3G/4G)
Dual WAN
* Load Balance and Route Policy : 50 profiles
* WAN connection failover
* Multiple-VLAN
* Support IPv6 LAN
* Port-based / Tag-based VLAN
* Bind IP to MAC Address    * Disable / Enable / Strict Bind
    * IP Bind list: 1024 entries
* LAN Port Mirror
* Wired 802.1x
* Web Portal
* Support IP Pool Count more than 253 (up to 1022) for LAN1~3 subnet
* 8 x Multiple Subnet LAN
* NAT    * DMZ Host (for DSL / GbE / Backup WAN)
    * Port-Redirection (40 profiles)
    * Open Port (40 profiles)
    * Port Trigger (20 profiles)
* Object-based Firewall (v3)
* SPI (Stateful Packet Inspection) (Flow Track)
* DoS Defense
* E-Mail alert (DoS Attack/APPE) and logging via syslog
* Time Schedule Control
* User Management    * User-based / Rule-based
    * Up to 200 Profiles
    * Support external authentication by LDAP/RADIUS/TACACS+
    * Support Data-base & Time-base Quota
    * Schedule Control to delete or disable account automatically
* Service Activation Wizard
* APP Enforcement (IM/P2P Application v3)    * Up to 32 Profile
    * APPE Signature Upgrade
* URL Content Filter :    * URL Access Control (Keyword Blocking)
    * Pass / Block Web Feature(Cookie, Proxy, Upload File extension)
    * Support File Extension Object: Image, Video, Audio, Java, Active X, Compression, Execution, P2P
* WEB Content Filter    * Service activation wizard in main bar
    * Support Cyren / BPjM
    * White/Black list for Keyword Object/Group
* DNS Filter for WCF/UCF
* 32 Simultaneous VPN
* Protocol: PPTP, IPsec, L2TP, L2TP over IPsec
* Encryption: MPPE and Hardware-based AES/DES/3DES
* Authentication: MDS, SHA-1
* IKE Authentication: Pre-shared Key and Digital Signature (X.509)
* LAN-to-LAN, Teleworker-to-LAN(Remote Dial-in User)
* DHCP over IPSec
* IPSec NAT-Traversal (NAT-T)
* Dead Peer Detection (DPD)
* VPN Pass-Through
* VPN Wizard
* mOTP
* SSL VPN : 16 Tunnels
* Support TLS/SSL Encryption v3.0
* VPN Trunk with Load Balance / Backup
* Static Route (IPv4 up-to 30 entries / IPv6 up-to 40 entries)
* RIPv2
* Policy-based Routing
* Inter-VLAN Routing
Bandwidth Management
* Bandwidth Limitation
* Session Limitation (Up to 20 lists)
* QoS (Quality of Service)    * Guaranteed bandwidth for VoIP
    * Class-based Bandwidth Guaranteed by user-defined traffic categories
    * DiffServ Code Point classifying
    * 4-level priority for each direction (Inbound/Outbound)
* Layer-3 (TOS/DSCP) QoS Mapping
Central Management
* AP Management: 20 (independent with External Device feature)
* VPN Management : 8
* External Devices : 30
Network Feature
* Packet Forwarding Acceleration (Default is disabled)
* DHCP Client/Relay/Server
* DHCP Option: 1,3,6,51,53,54,58,59,60,61,66,125
* IGMP Proxy V2/V3
* IGMP Snooping
* Dynamic DNS
* LAN DNS / DNS Forwarding
* NTP client
* Call Scheduling
* RADIUS / TACACS+ client
* Internal RADIUS server
* Active Directory /LDAP compatible (client)
* DNS Cache/Proxy
* UPnP 50 sessions
* Wake on LAN
* Bonjour service
* Support SmartMonitor (Up to 30 PCs)
System Management
* Web-based user interface (HTTP/HTTPS)
* Quick Start Wizard
* Dashboard
* CLI (Command Line Interface, Telnet/SSH)
* Administration access control
* Login Page Greeting
* Configuration backup/restore
* Built-in diagnostic function
* Firmware upgrade via TFTP/FTP/HTTP/TR-069
* Logging via syslog
* SNMP V2/V2c/V3
* Data Flow Monitor
* Support SMS/E-mail Alert
* External Device (Master Mode)
* TR-069
* TR-104
* Support Multi-Firmware Upgrade Utility
* Two-level management (admin/user mode)
* Printer Sharing
* File System    * Support FAT32 file system
    * Support FTP function for file sharing
    * File explorer
    * Support Samba for file sharing (DrayTek’s own SMB protocol stack)
* Support USB Temperature Sensor
* Support USB Device Status for Disk, Modem, Printer and Sensor
* 3.5G (HSDPA) and 4G (LTE) as WAN3/WAN4 by using USB dongle
Wireless AP  (n/Bn/ac/Vac model)
* Support Single 2.4G (n/Bn model)
* Support Simultaneous 2.4G/5G Dual-Band (ac/Vac model)
* Auto channel selection
* Multiple SSID
* Hidden SSID
* Wireless LAN Isolation
* Wireless Rate-Control
* 64/128-bit WEP
* MAC Address Access Control (Total 64 entries)
* WDS (Wireless Distribution System)
* Access Point Discovery
* 802.1x Authentication
* Station List / Control
* Wireless Wizard
* SSID VLAN grouping with LAN port (Port-based VLAN)
VoIP  (Vac model)
* Protocol: SIP, RTP/RTCP
* VoIP Wizard
* VoIP Status
* 12 SIP Registrars
* G.168 Line Echo-cancellation
* Automatic Gain control
* Jitter Buffer
* Voice codec:    * G.711
    * G.723.1
    * G.726
    * G.729 A/B
    * VAD/CNG
* DTMF Tone :    * Inband
    * Outband (RFC-2833)
    * SIP Info
* FAX/Modem Support :    * Tone Detection
    * G.711 Pass-through
    * T.38 for FAX
* Supplemental Services :    * Internal Call (dial 10 or 20 for Phone 1 or Phone 2. Only for

  • debug usage)

    * Call Hold/Retrieve/Waiting
    * Call Waiting
    * Call Waiting with Caller ID
    * Call Transfer
    * Call Forwarding (Always, Busy and No Answer)
    * CLIR (Calling Line Identification Restriction)
    * Call Barring (Incoming/Outgoing)
    * DND (Do Not Disturb)
    * MWI (Message Waiting Indicator) (RFC-3842)
    * Hotline
    * ZRTP
* PSTN Loop-through When Power Failure

* Dial Plan :    * Phone Book
    * Digit Map
    * Call Barring
    * Regional
    * PSTN Setu


This feature helps business isolate different work groups, preventing important and valuable information from any leakage.


Multi-site business deployment 

Combining VPN and Firewall features to create a private and secure office. 


Central Management - AP / Switch / VPN Management 


USB Thermometer


VDSL bonding  (B/Bn model)

VDSL bonding enlarges Router bandwidth and offers the better network performance to users.


802.11ac Wave 2  (ac/Vac model)

802.11ac Wave 2 can simultaneously stream to multiple users to maximize bandwidth utilization


Flexible Installation with Rackmount