The Ideal FTTP Gateway for Fast, Secure Business Networks
A high speed 2.5GbE / 10GbE multi WAN business router firewall designed for demanding fibre based networks. It delivers powerful routing performance, dependable failover, secure VPN access for remote teams, and flexible high performance LAN connectivity. An ideal next generation FTTP gateway for SMBs, branch offices, and organisations that need a fast, secure, and flexible network foundation.
Future-proof Multi-Gigabit Router
The DrayTek Vigor 2928 is engineered for ambitious SME and SMB environments that demand uncompromising performance and reliability. Delivering up to 9.3Gbps throughput, it ensures your business is ready for today’s high-bandwidth applications and tomorrow’s multi-gigabit fibre connections. With integrated 10GbE and 10Gb SFP+ interfaces configurable for WAN connectivity, the Vigor 2928 provides the flexibility to fully leverage high-speed fibre services while supporting seamless network expansion.
Built on DrayTek’s advanced feature set, the Vigor 2928 combines powerful routing with intelligent traffic management. Quality of Service (QoS) prioritises mission-critical applications, ensuring consistent performance for voice, video and cloud services. Comprehensive VPN capabilities enable secure site-to-site and remote access connectivity, while robust Content Filtering tools give administrators granular control over web access and network usage.

Route Policy - Routing Management for WAN & VPN
The Vigor 2928 provides full policy-based control of where and how outbound traffic is routed with Route Policy, to send traffic through VPN services and alternative LAN gateways:
| Feature | Description |
|---|---|
VPN Routing |
Send all or select traffic through VPN services. |
Service Routing |
Push specific services or ports, such as DNS, through a set WAN, an alternative Gateway or VPN Tunnel. |
Failover & Failback |
Extensive control of Failover with multiple Failover rules and paths. Manage how connections are moved back to the primary connection, after a failover has occurred with Failback settings. |
Powerful VPN Hub for Expanding Business Networks
Optimised for high-speed fibre broadband, the Vigor 2928 provides great IPsec VPN throughput, delivering fast and secure encrypted connections between sites and cloud platforms. Future firmware updates are expected to further enhance performance through hardware acceleration. Whether deployed as a central office gateway or as part of a multi-site infrastructure, the Vigor 2928 offers the scale, speed and security required for modern business connectivity.
It supports all common industry standard VPN protocols, for it to connect to VPN services, link remote offices and handle connections from all types of VPN clients. Supporting IPsec IKEv1 & IKEv2 protocols with EAP and XAuth authentication, OpenVPN and WireGuard for both LAN to LAN and Dial-In teleworker VPNs.
Connecting Remote Sites with LAN to LAN VPN
Supporting up to 50 concurrently active VPN tunnels and great VPN throughput, the Vigor 2928 series is ideal as a business router, to connect with other branches.
Once connected, they have access to your office/remote resources through a secure encrypted tunnel allowing remote desktop, file sharing and seamless access to other resources and devices.
Encrypted VPN for Dial-In Teleworkers & LAN to LAN
Connect up to 50 VPN tunnels. These encrypted tunnels securely link teleworkers or remote DrayTek Vigor routers back to your main office using SSL/TLS technology - similar to the HTTPS security that's used for most secure websites on the internet such as on-line banking and shopping services.
Teleworkers can connect with the secure IPsec, OpenVPN, or WireGuard VPN tunnels to the DrayTek Vigor 2928, using the free DrayTek Smart VPN Client app. Available for Windows, macOS, Apple iOS (iPad, iPhone) and Android devices. The latter two protocols may need additional native software installed on your mobile devices.
Download the SmartVPN client and learn more about DrayTek VPN here.
Identity and Access Control Security Framework
Identity and Access Control (IAM) framework is designed to meet network security requirements. The network administrator can define access policies, control user privileges, and coordinate group policies with the firewall and traffic shaping settings.
| Feature | Description |
|---|---|
Device Authentication |
Using each device’s unique IP and MAC address provides a strong basis for device identification and authentication. |
Reduced False Positives |
Using IP and MAC addresses reduces the likelihood of legitimate devices being blocked due to other potential factors. |
Holistic Security |
Combining user, device, and session-based policies enhances overall security without relying solely on one aspect. |
Enhanced Incident Response |
When security incidents occurs, you can quickly pinpoint the devices involved and take appropriate actions. |
Gigabit LAN Ports with VLANs

The Vigor 2928 provides 5 LAN ports: 1x switchable GbE LAN/WAN and 4x 1GbE for wired links to Computers, Servers and Network Attached Storage.
Up to four LAN subnets and VLANs allow the Vigor 2928 to manage guest networks that are fully separated from internal networks and data. Or any other configuration that can use up to four subnets, whether that's a separate LAN subnet to isolate printers, IoT and other smart devices from computers and servers, or simply providing multiple IP networks through the one router. Each network can have its own Content Filtering, Firewall, Quality of Service and Route Policy configurations.
Vigor 2928 routers have full support for 802.1Q VLAN tagging, so that these subnets can be passed to other devices that support tagged VLANs. Such as the DrayTek VigorSwitch P2100 10-port switch, for additional network ports and features.
The Wireless LAN can also utilise VLANs, making the same Guest & Private networks possible simply by using different wireless SSIDs. Or connect up a DrayTek VigorAP wireless access point, such as the VigorAP 805 to do the same, spanning the router's own wireless and any connected wireless APs.
Designed for Central Management
The Vigor 2928 can be centrally managed along with VigorAP's and switches, with the VigorACS central management platform.
This scalable solution provides visibility, control and reporting of your entire DrayTek product estate, ideal for dealers/SIs managing customers' devices or any user who wants to know what's going on with their devices. VigorACS also provides features like automated/bulk firmware updates, VPN management and alarms for connectivity or other issues.
For full details of VigorACS, click here.

Robust & Comprehensive IPv4 / IPv6 Firewall
Security is always taken seriously with DrayTek routers. The firewall protects against attacks including DoS (Denial of Service) attacks, IP-based attacks and access by unauthorised remote systems. Wireless, Ethernet and VPN are also protected by various protection systems.
The DrayTek object-based firewall enables you to create combinations of Firewall rules and Content Filtering to suit a home or small office environment, applying Content Filtering to the whole network, only specified devices or just the network that guests can connect to.
The Vigor 2928 supports both IPv4 and IPv6 with Dual-Stack IPv4/IPv6. Advanced networking features, such as the object-based Firewall, Quality of Service, Content Filtering and VLANs support both IPv4 and IPv6 networks.

Web Content Filtering with DNS Filter

The content control features of the Vigor 2928 allow you to set restrictions on web site access, blocking download of certain file or data types, blocking specific web sites with whitelists or blacklists, blocking IM/P2P applications or other potentially harmful or wasteful content. Restrictions can be per user, per PC or universal and according to time schedules.
Content filtering can also block sites using HTTPS/SSL where URLs are encrypted (and normal routers cannot block).
Using the GlobalView service, you can block whole categories of web sites (e.g. gambling, adult sites etc.), subject to an annual subscription, which is continuously updated with new or changed site categorisations or sites which have become compromised (such as infected with Malware). A free 30-day trial is included with your new router.
Quality of Service with App QoS
Prioritise latency-sensitive applications on your network with Quality of Service.
App QoS simplifies setting up Quality of Service significantly, simply select which applications or services to prioritise, such as Zoom and Skype.
Use 4 separate queues to give priority to servers & PCs (IP address), services such as VoIP or DNS, or packet tagging used by IP phones with 802.1p and DSCP support
Auto Voice VLAN allows the router to automatically prioritise VoIP calls as they pass through the router without additional configuration.
Control throughput with Bandwidth Limit, by setting speed limits for all clients individually, groups of IPs, or a shared bandwidth limit for a whole subnet, such as a Guest network.
DrayDDNS - DrayTek Dynamic DNS Address
DrayTek provides a free Dynamic DNS address to each Vigor 2928 router, allowing you to link the router's current IP address to a memorable "drayddns.com" hostname, such as "vigor2928.drayddns.com".
This address automatically updates whenever the Internet connection's IP changes, so if one WAN’s IP address allocation is dynamic, or the IP changes when switching from the primary WAN connection to a backup, you can easily locate and access your Vigor 2928 router. Just use the hostname to access the router's VPN services, management and any other services you have made accessible through the router.
The Vigor 2928 can also authenticate your DrayDDNS hostname with free SSL/TLS certificates provided by LetsEncrypt, the router manages and automates the certificate process. Keeping the certificate up to date and ready for use with SSL VPN and other services.
Virtual Controller
Virtual Controller is a management feature that helps with deployment and monitoring of DrayTek VigorAPs and VigorSwitches. The system can auto detect access points and switches. For smaller setups with fewer than 8 APs, it seamlessly enables Mesh mode where 1 root AP and up to 7 nodes can be linked together. In larger wired deployments, it activates AP management mode for up to 20 APs, while switch management supports up to 5 switches, ensuring enhanced control and scalability.

Wireless Management

DrayTek Vigor 2928 series routers can manage up to 20 DrayTek VigorAP access points with Vitrual Controller AP Management profiles, with an option to Auto Provision - auto configuring newly installed VigorAP access points with the Auto Provisioning profile, upon initial connection to the DrayTek Vigor router's network. This enables you to centrally control, manage and administer a full DrayTek network installed around the home or office, through the router's web interface. Ideal for local or remote management.
Switch Management
DrayTek DrayOS 5 routers such as the Vigor 2928 series can also manage up to 5 VigorSwitches. The Vitrual Controller helps with finding devices on the network, auto configuration of newly added VigorSwitches, monitoring of the devices, port control and maintenance.

Virtual Controller
Discover, adopt, synch configuration, maintain and monitor your DrayTek wireless access points and switches thanks to the Virtual Controller management system

IAM - Identity and Access Control
Configure IAM users and groups and apply network security policies

Specifications
Vigor 2928 Router
Key Specifications
- Multi-WAN Ethernet FTTP Router with Failover and Load Balancing
- 10 Gigabit and SFP+ Ports for future-proof connectivity
- Up to 9.3Gbps Total Maximum Throughput
- Up to 430Mbps IPsec VPN Throughput
- 50 LAN-to-LAN & Remote Teleworker VPN Tunnels
- Switchable 10GbE/SFP+ and dedicated 1x 2.5GbE and 3x GbE RJ-45 LAN Ports
- QoS and VLAN support for traffic prioritisation and network segmentation
- SPI Firewall and Content Filtering
- Optional VigorCare Available
- Can be centrally Managed by VigorACS
| UK Product Code | EAN | Product Name | Product Description |
|---|---|---|---|
| V2928-K | 4711637180244 | Vigor 2928 (UK/IE) | Vigor 2928 Multi-Gigabit Multi-WAN Wired FTTP Router |
These product codes are for UK/Irish products only. Please check with your local DrayTek office for the correct part nos. for your region if you are not in the UK/IE to ensure that you get the correct hardware and local support/warranty.
Technical Specification (UK Hardware Spec.)
Physical Interfaces
- WAN Port (P1): 1x Gigabit Ethernet (1G/100M/10M), RJ-45
- P2/P3/P4: 2 can be used out of 3 at once
- WAN Port (P2): 1x 10G/1G SFP+ Fiber Slot
- WAN/LAN Switchable (P3): 1x 10 Gigabit Ethernet (10G/2.5G/1G/100M/10M), RJ-45
- LAN Port (P4): 1x 10G/1G SFP+ Fiber Slot
- LAN Port (P5): 1x 2.5Gigabit Ethernet (2.5G/1G/100M/10M), RJ-45
- LAN Ports (P6-P8): 3x Gigabit Ethernet (1G/100M/10M), RJ-45
- 2x USB 2.0 Ports for LTE Modem, Thermometer or Printer
- Recessed Factory Reset button
Performance
- NAT Performance:
- Up to 9.3 Gb/s NAT Throughput
- 60,000 NAT Sessions
- VPN Performance:
- Up to 430 Mb/s IPsec VPN Performance
- Max. 50 Concurrent VPN Tunnels
WAN Interfaces
- WAN1: Gigabit Ethernet
- WAN2: 10 Gigabit SFP+ Slot for Fibre or another module
- WAN3/LAN Switchable Port: 10 Gigabit Ethernet
- WAN7: LTE USB Modem (not included)
- WAN8: LTE USB Modem (not included)
Internet Connection
- Load Balancing and Failover / Backup WAN
- 802.1p/q Multi-VLAN Tagging
- Multi-VLAN/PVC
- Connection Detection: ARP Detect, Ping Detect
- WAN Data Budget
- Dynamic DNS
- DrayDDNS – with automated Let’s Encrypt Certificates
- Full Feature-set Hardware Acceleration:
- Hardware Accelerated Quality of Service
- Multi-WAN Data Budget
- Bandwidth Limit
- IPv4 Connection Types: PPPoE, DHCP, Static IP
- IPv6 Connection Types:
- Ethernet: PPP, Static IPv6, DHCPv6, TSPC, 6in4, 6rd
Firewall & Content Filtering
- IP-based or User-based (IAM) Firewall Policy
- User-based Time Quota (IAM)
- DoS Attack Defence
- Spoofing Defence
- Content Filtering:
- Application Content Filter
- URL Content Filter
- Web Category Filter*
NAT Features
- NAT Port Forwarding/Redirection
- Open Ports
- DMZ Host
- Port Trigger
- UPnP
- ALG (Application Layer Gateway): SIP, RTSP, FTP, H.323
- NAT Traversal (NAT-T)
LAN Management
- 802.1q Tag-based, Port-based VLAN
- Up to 8 LAN Subnets (NAT or Routing mode selectable per LAN interface)
- Up to 8 VLANs
- DHCP Server:
- Multiple IP Subnet
- Custom DHCP Options
- Bind-IP-to-MAC
- DHCP Relay per LAN
- Wired 802.1x Port Authentication
- Port Mirroring
- Conditional DNS Forwarding
- Hotspot Web Portal
- Hotspot Authentication: Click-Through, External Portal Server, Social Login
Networking Features
- Policy-based Routing: Protocol, IP Address, Port, Domain/Hostname
- DNS Security (DNSSEC)
- Local RADIUS server
- SMB File Sharing (Requires external USB storage)
- Routing Features: IPv4 & IPv6 Static Routing, Inter-VLAN Routing, RIP v1/v2/ng, BGP, OSPF
VPN Features
- Up to 50 active VPN tunnels
- Up to 430Mb/s IPsec
- LAN-to-LAN - Dial-In VPN Server & Dial-Out VPN Client
- Teleworker-to-LAN – Dial-In VPN Server
- IKE Authentication: Pre-Shared Key and Digital Signature (X.509)
- Encryption: DES, 3DES, AES (128/192/256)
- Authentication: SHA-256, SHA-1
- Dead Peer Detection (DPD)
- IPsec NAT-Traversal (NAT-T)
- DHCP over IPsec
- VPN Protocols:
- IPsec IKEv1, IKEv2, IKEv2 EAP
- IPsec-XAuth
- OpenVPN
- WireGuard
- EasyVPN – New!
- User Authentication:
- Local
- RADIUS
- TACACS+
- TOTP - Time-based One Time Password, compatible with Google Authenticator
Bandwidth Management
- IP-based Bandwidth Limit
- IP-based Session Limit
- QoS (Quality of Service):
- Classify via TOS, DSCP, 802.1p, IP Address, Service Type
- 4 Priority Queues
- App QoS
- VoIP Prioritization
Management
- Local Service: HTTP, HTTPS, Telnet, SSH v2, FTP, TR-069
- Config File Export & Import
- Firmware Upgrade via TFTP, HTTP, TR-069
- 2-Level Administration Privilege
- Access Control Features: Access List, Brute Force Protection
- Syslog
- SMS, E-mail Notification Alert
- SNMP: v1, v2c, v3
- Compatible with DrayTek VigorACS Management Platform**
Router-based Central Management Features
- Virtual AP Controller: Up to 20 VigorAP wireless access points
- Virtual Switch Controller: Up to 5 VigorSwitch network switches
Operating Requirements
- PSU Power Requirements: 100-240VAC
- Power Consumption (Watts, maximum):
- Vigor 2928: 24W (12V @ 2A)
- Temperature Operating: 0 °C ~ 40 °C
- Storage: -25 °C ~ 70 °C
- Humidity 10% ~ 90% (non-condensing)
- Wall or Shelf Mountable
- Rack Mountable (Optional Vigor RM1 mounting bracket required)
Physical Specifications
- Dimensions:
- 241mm Width
- 165mm Depth
- 44mm Height
- Weight
- Vigor 2928: 711g
Box Contents
- Vigor 2928 router
- Quick Start Guide
- Screws & wall plugs for wall mounting
- RJ-45 Network Cable
- DC 12V Power Supply with UK Plug
ROHS, UKCA & CE Compliant
Warranty
- Standard: Two (2) Year, RTB
- Software security updates:
5 years after the EOL notification. Please note that this only applies to products sold in the UK - Optional VigorCare Extended Warranty
- VigorCare A3 3 Year Subscription: VCARE-A3
- VigorCare A5 5 Year Subscription: VCARE-A5
* - subscription required: Group B, URLR-B (includes free 30-day trial)
** - VigorACS subscription required














