information
Draytek Vigor 3900 Multi WAN Security Appliance Firewall Router + Rackmount Ears
In good condition and in full working order
Supplied in original box
2 Years Warranty
Included
- 1 x Draytek Vigor 3900 Multi WAN Security Appliance Firewall Router
- 1 x Set Of Rackmount Ears
Features
- Professional Router/Firewall
- Five Gigabit WAN ports (4 x Ethernet & 1 SFP)
- Up to 50 WAN ports with optional Switch
- WAN Load Balancing & WAN Failover
- High-Availability (Hardware failover)
- Up to 500 simultaneous IPSec/PPTP/L2TP Tunnels
- Up to 100 SSL VPN Tunnels
- 3 Gigabit LAN ports (2 x Ethernet & 1 x SFP)
- IPv4 & IPv6 Dual-Stack
- Two USB Ports for 3G/4G/LTE USB Modem or thermometer
- Temperature Monitoring (optional Thermometer)
- 802.1q Tagged and port-based VLANs
- QoS Assurance on different traffic types
- Mobile One-Time Passwords for Teleworker VPNs
- VPN Trunking (aggregated/failover links)
- Up to 50 WAN/LAN-side IP subnets
- Internet Content Filtering (by keyword, data type or category)
- Central Management of up to 30 DrayTek VigorAPs - New!
- Central Switch Management - New!
Specifications
- Physical Interfaces
- WAN Ports:
- WAN1 : RJ-45 Gigabit Ethernet (1000Mb/s)
- WAN2 : RJ-45 Gigabit Ethernet (1000Mb/s)
- WAN3 : RJ-45 Gigabit Ethernet (1000Mb/s)
- WAN4 : RJ-45 Gigabit Ethernet (1000Mb/s)
- WAN5 : SFP Gigabit Slot for Fibre or other module (1000Mb/s)
- LAN Ports:
- 2 X RJ-45 Gigabit Ethernet (1000Mb/s)
- 1 X SFP Gigabit Slot for Fibre or other module (1000Mb/s)
- Console Port (RJ-45 physical, RS-232 electrical)
- Performance
- Firewall: Up to 1000Mb/s
- IPSec VPN: Up to 700Mb/s
- SSL VPN: Up to 100Mb/s
- NAT Sessions : 120,000
- VPN Services
- Remote Dial In Teleworker Protocols:
- PPTP
- IPSec
- L2TP
- L2TP over IPSec
- SSL VPN
- LAN to LAN VPN Tunnel Protocols:
- PPTP
- IPSec
- SSL VPN
- GRE (LAN to LAN Tunnel) - New!
- Up to 500 simultaneous tunnels (LAN-to-LAN or Teleworker-to-LAN)
- PPTP Acceleration (90Mbps with encryption, 400Mbps without encryption)
- Dial-in and Dial-out supported
- VPN Trunking: allows alternative failover route or multiple tunnels to the same destination to increase capacity/throughput
- Multiple SA (Security Association) IPsec VPN support: send multiple Local and Remote subnets through one VPN tunnel - New!
- Teleworker - Remote Dial-In VPN Features:
- LDAP/Active Directory: Teleworker VPNs can be authenticated by a LDAP/AD server
- XAuth authentication support for IPsec Remote Dial-In Teleworker VPN tunnels - New!
- Radius Client: Authentication for Remote Dial-In Teleworkers
- Scheduled Remote Dial-In VPN - configure times that specified Teleworkers are allowed to Dial In - New!
- DrayTek Smart-VPN Software utility
- IPsec IKE Protocols:
- IKEv1
- IKEv2 - New!
- IPsec IKE Authentication:
- Pre-shared key (PSK)
- PKI Certificate (RSA): Use X.509 Digital Signatures
- Phase 1 Main Mode or Aggressive Mode
- Phase 2 selectable lifetimes
- Encryption:
- Hardware-based AES (128, 192, 256 bits)
- Hardware-based DES/3DES (56 & 168 bits)
- Hardware-based MD5, SHA-1 & SHA-256
- MPPE (40 or 128 bits)
- IKE Phase 1 DiffieHelman Groups 1,2,5 & 14
- IKE Phase 2 DiffieHelman Groups 1,2,5 & 14 (will match phase 1 selection)
- DHCP over IPSec
- GRE over IPSec
- Dead-Peer-Detection (DPD)
- NAT-Traversal (NAT-T): VPN over routes without VPN Passthrough
- No extra licencing or additional VPN client costs.
- Interoperability : Compatible with other 3rd party VPN devices
- Firewall
- Stateful Packet Inspection (SPI)
- Content Security Management (CSM)
- Multi-NAT: Set one-to-one mappings between your private and public IP addresses
- NAT Port Forward Features:
- Port Redirection - 256 entries with 16 port ranges per entry
- DMZ Host
- Server Load Balance & Inbound Load Balance
- SIP Application Layer Gateway (ALG)
- H.323 Application Layer Gateway (ALG)
- Policy-based IP Packet Filter. Fully configurable policies based on IP address, MAC address (source or destination), DiffServ attribute, direction, bandwidth, remote site
- DoS/DDoS Protection
- IP Address Anti-spoofing
- Object-Based Firewall
- Notification: Email alerts and logs to syslog
- Bind IP to MAC address
- User-Controlled Rules: Interrogates LDAP server to permit access or enforce policies
- DNSSEC support - New!
- LAN DNS Features:
- Control DNS resolution for A and CNAME records for configured hostnames
- Wildcard support
- Conditional Forwarding to specified DNS Server(s)
- Web Content Filtering & CSM
- URL Keyword Blocking: Blacklist or Whitelist
- Content Type Blocking: Java applet, cookies, Active-X
- Application Enforcement (APPE): IM, P2P, Protocol, Tunnelling, Streaming, Remote Cotnrol, Wed HD
- Auto APPE Signature Upgrade
- Block P2P Applications (inc. Kazza, WinMX, Bittorrent)
- Block Instant messaging
- Block access of web sites by direct IP address (thus URLs only)
- Block HTTP download of compressed, executable or multimedia files
- Web Content Filter: GlobalView filtering of 64 web site categories (e.g. adult, gambling sites etc.). subscription required (free trial included)
- Time Scheduling: Blocking rules can be activated based on time schedules
- User Management
- Manage account features through User Profiles - VPN, PPPoE, Web Portal, FTP, Samba
- Internal RADIUS Server
- External LDAP / Active Directory server authentication with SSL support
- External RADIUS server authentication
- PPPoE Server
- Guest Profiles with Guest Account Generator
- Web Portal Features:
- User Authentication for Internet access with Time Quotas
- SMS Authentication (requires SMS provider)
- Web Portal Login Page Customisation
- Login History
- System Management
- Web-Based User Interface: Integrated server for router management (via HTTP or HTTPS)
- Telnet/SSH : Command line control and configuration
- Configuration Backup/Restore
- Built-in diagnostics, dial-out triger, routing table, ARP table, DHCP Table, NAT Sessions Table, data flow monitor, traffic graph, ping diagnostics, traceroute
- Firmware Upgrade by HTTP, TFTP & FTP
- Syslog Logging
- SNMP Management: v1/v2/v3, MIB II
- Mail Alert & Mail Notifications with SSL & StartTLS encryption support
- Vigor ACS-SI Centralised Management: TR-069 compatible for ACS platform
- Compatible with Smart Monitor Traffic Analyser : Windows software for up to 100 users
- Central Management
- AP Management - Manage up to 30 compatible VigorAP access points - New!
- Switch Management - Manage up to 20 compatible VigorSwitch switches - New!
- VPN Management - Manage up to 16 DrayTek Vigor routers
- Certificate Management
- Local Certificates for HTTPS, SSL & VPN
- Remote Certificates; Sign and manage certificates from other devices - New!
- Bandwidth Management
- Traffic Shaping: Dynamic bandwidth management with IP traffic shaping
- Bandwidth Reservation: Connection or client based
- Packet Size Control
- DiffServ Codepoint Classifying
- 4 Priority Levels (Inbound/Outbound)
- Individual IP Bandwidth Session Limits per user/group
- Bandwidth Borrowing
- User-defined class-based rules
- Routing Functions
- IPv4 & IPv6 Dual-Stack
- Up to 50 LAN Subnets / VLANs
- WAN Protocols: PPPoE, PPTP, DHCP Client, Static IP
- Load Balancing: Policy based or automatic
- WAN Failover: Switch to other connection when primary WAN lost
- DNS Cache/Proxy
- DHCP Client, Server & Relay
- DHCP Options: 1,3,6,51,53,54,58,59,60,61,66,125
- IGMP v1/v2 & Proxy/Snooping
- uPnP: 500 Sessions
- NAT: 120,000 Sessions
- NTP Client with DST Adjustments
- Static routing
- Policy-based routing with scheduling - New!
- BGP Routing protocol
- Dynamic DNS : Updates DDNS servers with public IP address
- Port-Based VLAN
- Tag-Based VLAN: 802.1q
- Client/Call Scheduling : Real-time clock, with NTP updating schedules access or connectivity
- Wake-on-LAN : Passed from WAN to preset LAN device
VAT IS NOT PAYABLE BY PURCHASERS OUTSIDE OF THE UK
LM 256608
specifications
-
MPN:Vigor 3900
to request a price please fill out the form below...
close