Mailing List
Mailing List
Sign Up Here
Like, follow & share: visit DrayTek UK's Facebook page visit DrayTek UK's Twitter page visit DrayTek UK's Linkedin page
  • High Performance Firewall Router
  • Ideal for Cellular & telecoms backhaul applications
  • Synchronous Ethernet (SyncE Phase 2) on WAN2 (slave/relay)
  • IEEE1588 v2 Precision Time Protocol (PTP)
  • PoE Powered or AC or DC (Option)
  • Ruggedised:
    • IP66 Outdoor Rated
    • Operating Range : -10°C - 60°C
  • Multiple IP Subnets
  • 802.1ad Q-in-Q
  • Up to 200 VPN Tunnels (IPSec/PPTP)
  • VLAN based Bandwidth control
  • 802.1p QoS (up to 4 Queues)
  • WAN Connectivity (to order):
    • WAN1: Gigabit Ethernet or SFP
      or 3G/4G/LTE Cellular
    • WAN2: Gigabit Ethernet (RJ-45)
    • VDSL2 / ADSL2+ (To order)
  • LAN Connectivity (to order):
    • 2 X Gigabit Ethernet (RJ-45)
    • 802.11n or 802.11ac (option)
  • IPv4/IPv6 Dual Stack
  • 500Mb/s Firewall Performance
  • Availability: Special (Project) Order Only (see below)


Vigor M9000 Industrial M2M Ruggedised Router / Firewall

The Vigor M9000 is a ruggesised, high-performance router suitable for various industrial applications where external or robust installation is required.  It is particularly suitable for Cellular or Telecoms backhaul with its inclusion of Syncrhonised Ethernet (Sync-E) and IEEE 5888.   It also provides the full firewall/router experience typical of other DrayTek routers and can be centrally managed/monitored using our ACS-SI platform.  It can be pole/wall mounted or attached to other local plant infrastructure.  WAN connectivity options include RJ-45 Gigabit Ethernet, Fibre (SFP) or 3G/4G/LTE Cellular. On the LAN side, power can be provided by PoE on the copper Ethernet, with optional wireless LAN (802.11n or 802.11ac). AC or DC power are also options.

Sync-E and IEEE 5888

Synchronised Ethernet and IEEE 5888 are essential features required for any backhaul requirements which are timing critical. TDM methods require that the clocks at each end of a link are syncrhonised.  The Vigor M9000 provides both of these methods; with Sync-E, an external clock source on WAN2 can be passed through.


Vigor M9000 can be pole/wall mounted

Flexible Interfaces Configuration

The unit has four ports which can be configured to provide a variety of different options. Each port has a waterproof seal (if unused) or a IP65 cable gland if in use. The options (when ordering) are:

Port 1 : LAN Gigabit Ethernet RJ-45 with PoE PD
            or AC or DC Power input (depending on configuration)

Port 2 : LAN or WAN Gigabit Ethernet (Copper RJ-45)

Port 3 : LAN or WAN Gigabit Ethernet (Copper RJ-45)

Port 4 : WAN Gigabit Ethernet (Copper RJ-45)
            or WAN SFP Slot
            or WAN ADSL/VDSL
            or Coax cable outlet (3G/4G/Wireless LAN Aerial)


The Vigor M9000 is not a retail product - i.e. not available 'off-the-shelf' like regular DrayTek channel products. It is produced in various configurations with power and interfaces to to suit specific projects in volume. If your organisation has interest in this product you should, in the first instance, get in touch with the DrayTek sales team to discuss your applications and requirements.


Vigor M900 VDSL/ADSL Card - Technical Specification

  • Physical Interfaces/controls:
      • LAN Interfaces (to order):
        • RJ-45 Gigabit Copper Ethernet (up to 2)
      • WAN Interfaces (to order):
        • RJ11 (VDSL2/ADSL2+) or
        • SFP (for SFP modules) or
        • RJ-45 Gigabit Copper Ethernet (up to 2)
    • ADSL/VDSL Compliance (to order):
      • ITU-T VDSL2 G.993.2
      • ITU-T G.vectoring
      • Auto Fall back to ADSL2/2+
      • VDSL Band Plan: 997, 998
      • VDSL2 Profile: 8a, 8b, 8c, 8d, 12a, 12b, 17a, 30a
      • Annex A, Annex B, Annex M, Annex J
      • ANSI T1.413 Issue2
      • ITU-T G.992.1 G.dmt
      • ITU-T G.992.3 ADSL2 (G.dmt.bis)
      • ITU-T G.992.5 ADSL2+
      • Loop diagnostic mode
      • Annex A (POTS)
    • Ethernet Timing Methods:
      • SyncE (Phase 2)
      • IEEE 5888
    • WAN Protocols:
      • DMZ Host, Port-redirection and Open Ports
      • MAC Address Filter
      • SPI (Stateful Packet Inspection)
      • DoS/DDoS Prevention
      • E-mail Alert and Logging via Syslog
      • Time Schedule Control
      • VPN Pass-through (IPsec, PPTP, L2TP)
      • Static IP
      • DHCP Client
      • PPPoE
      • PPPoA (ADSL only)
      • MPoA (RFC1483/2684)
      • 802.1q VLAN Tagging
      • Multi-PVC (Up to 5)
      • TR-069 Management
      • Firewall/NAT:
    • VPN support:
      • Protocols : PPTP, IPSec, L2P, L2TP over IPSec
      • Up to 200 simultaneous tunnels (LAN-to-LAN or Teleworker-to-LAN)
      • PPTP Acceleration
      • Dial-in and Dial-out supported
      • VPN Trunking - allows alternative failover route or multiple tunnels to the same destination to increase capacity/throughput
      • LDAP/Active Directory : Teleworker VPNs can be auththenticated by a LDAP/AD server
      • NAT-Traversal (NAT-T): VPN over routes without VPN Passthrough
      • PKI Certificates: Use X.509 Digital Signatures
      • IKE Authentication: Pre-shared key (PSK), Phase 1 agressive/standard, Phase 2 selectable lifetimes
      • Encryption:
        • Hardware-based AES (128, 192, 256 bits)
        • Hardware-based DES/3DES (56 & 168 bits)
        • Hardware-based MD5, SHA-1 & SHA-256
        • MPPE (40 or 128 bits)
      • IKE Phase 1 DiffieHelman Groups 1,2,5 & 14
      • IKE Phase 2 DiffieHelman Groups 1,2,5 & 14 (will match phase 1 selection)
      • Radius Client: Authentication for PPTP remote dial-in teleworkers
      • DHCP over IPSec
      • GRE over IPSec
      • Dead-Peer-Detection (DPD)
    • Wireless (to order):
      • 3G/4G/LTE WAN
      • 802.11n / ac  LAN
    • Routing Functions:
      • IPv4 & IPv6 Dual-Stack
      • DNS Cache/Proxy
      • DHCP Client, Server & Relay
      • DHCP Options: 1,3,6,51,53,54,58,59,60,61,66,125
      • IGMP v1/v2 & Proxy/Snooping
      • uPnP: 500 Sessions
      • NAT: 80,000 Sessions
      • NTP Client with DST Adjustments
      • Static routing
      • Policy-based routing
      • BGP Routing protocol
      • Dynamic DNS : Updates DDNS servers with public IP address
      • Port-Based VLAN (depending on configuration)
      • Tag-Based VLAN: 802.1q
      • Client/Call Scheduling : Real-time clock, with NTP updating schedules access or connectivity
      • Wake-on-LAN : Passed from WAN to preset LAN device
    • Firewall:
      • Stateful Packet Inspection (SPI)
      • Content Security Management (CSM)
      • Multi-NAT: Set one-to-one mappings between your private and public IP addresses
      • Port Redirection & Open Ports
      • Policy-based IP Packet Filter. Fully configurable policies based on IP address, MAC address (source or destination), DiffServ attribute, direction, bandwidth, remote site
      • DoS/DDoS Protection
      • IP Address Anti-spoofing
      • Object-Based Firewall
      • Notification: Email alerts and logs to syslog
      • Bind IP to MAC address
      • User-Controlled Rules: Interrogates LDAP server to permit access or enforce policies
      • URL Content Filter:
        • URL Keyword Filter (White List and Black List)
        • Content Type Blocking: Java Applet, Cookies, Active X, Compressed, Executable, Multimedia File Blocking
        • Categoric Web Site Filtering (Cyren)
    • Network Features:
      • Router/Bridge Configurable
      • IGMP Proxy V2/V3
      • DHCP Client/Relay/Server
      • UPnP 100 Sessions
      • DNS Cache/Proxy
      • Dynamic DNS
      • NTP Client
      • Static Routes
      • RIP v1/v2
    • Bandwidth Management:
      • Traffic Shaping: Dynamic bandwidth management with IP traffic shaping
      • Bandwidth Reservation: Connection or client based
      • Packet Size Control
      • DiffServ Codepoint Classifying
      • 4 Priority Levels (Inbound/Outbound)
      • Individual IP Bandwidth Session Limits per user/group
      • Bandwidth Borrowing
      • User-defined class-based rules
    • Management:
      • Web-based User Interface (HTTP/HTTPs)
      • CLI (Command Line Interface, Telnet/SSH)
      • Administration Access Control
      • Configuration Backup/Restore
      • Built-in Diagnostic Function
      • Firmware Upgrade via TFTP/FTP/WUI/TR-069
      • Logging via Syslog
      • TR-069 Compliance with DrayTek's ACS-SI Management Platform
      • SNMP v1/v2c
    • Performance : Firewall/NAT Throughput : 500Mb/s Max
    • Physical Characteristics:
      • IP66 Rated for outdoor use
      • Power Requirements (depending on configuration):
        • PoE (802.1af) or
        • AC 110-240VAC or
        • DC 130-350VDC
      • Power Consumption : 20W typical, 25W Max (Depending on configuration)
      • Wall Mountable or Pole Mountable
      • Operating Range : -10°C - 60°C
      • Humidity : Up to 95% non-condensing
      • Dimensions : 185 x 280 x 78 mm
    • Warranty : Two (2) Years RTB