Vigor 3900
- Professional Router/Firewall
- Five Gigabit WAN ports (4 x Ethernet & 1 SFP)
- Up to 50 WAN ports with optional Switch
- WAN Load Balancing & WAN Failover
- High-Availability (Hardware failover)
- Up to 500 simultaneous IPSec/PPTP/L2TP Tunnels
- Up to 100 SSL VPN Tunnels
- 3 Gigabit LAN ports (2 x Ethernet & 1 x SFP)
- IPv4 & IPv6 Dual-Stack
- Two USB Ports for 3G/4G/LTE USB Modem or thermometer
- Temperature Monitoring (optional Thermometer)
- 802.1q Tagged and port-based VLANs
- QoS Assurance on different traffic types
- Mobile One-Time Passwords for Teleworker VPNs
- VPN Trunking (aggregated/failover links)
- Up to 50 WAN/LAN-side IP subnets
- Internet Content Filtering (by keyword, data type or category)
- Central Management of up to 30 DrayTek VigorAPs - New!
- Central Switch Management - New!
- Optional VigorCare Available
- Professional Router/Firewall
- Five Gigabit WAN ports (4 x Ethernet & 1 SFP)
- Up to 50 WAN ports with optional Switch
- WAN Load Balancing & WAN Failover
- High-Availability (Hardware failover)
- Up to 500 simultaneous IPSec/PPTP/L2TP Tunnels
- Up to 100 SSL VPN Tunnels
- 3 Gigabit LAN ports (2 x Ethernet & 1 x SFP)
- IPv4 & IPv6 Dual-Stack
- Two USB Ports for 3G/4G/LTE USB Modem or thermometer
- Temperature Monitoring (optional Thermometer)
- 802.1q Tagged and port-based VLANs
- QoS Assurance on different traffic types
- Mobile One-Time Passwords for Teleworker VPNs
- VPN Trunking (aggregated/failover links)
- Up to 50 WAN/LAN-side IP subnets
- Internet Content Filtering (by keyword, data type or category)
- Central Management of up to 30 DrayTek VigorAPs - New!
- Central Switch Management - New!
- Optional VigorCare Available
High Performance Multi-WAN VPN Appliance
The Vigor 3900 is a high-performance quad-Gigabit WAN router for high-performance applications including remote access, firewalling, load-balancing and failover. Its WAN throughput runs at up to 1Gb/s, adequate for the most demanding SME applications. The WAN ports on the Vigor 3900 can provide load balancing or WAN failover. Based on a new DrayTek OS platform, the Vigor 3900 combines high performance and capacity with DrayTek's traditional ease of use and comprehensive features set.
For multi-tenant or departmental flexibility, the Vigor3900 will support multiple LAN IP subnets, together with VLAN capabilities and user management, providing access to WAN resources only to the appropriate users or departments, as well as maintaining infrastructure effciency.
Four WAN ports for load-balancing or failover
Four Gigabit Ethernet WAN ports and one SFP slot (for fibre modules or an additional Ethernet module) provide 5 independent WAN ports for either load-balancing or failover applications. Gigabit Ethernet and SFP LAN Interfaces provide high speed connectivity to your LAN.
Fibre is of particular use for longer distance deliveries, beyond the range of standard Ethernet, or where copper connections cannot be used. WAN Load-balancing weight or traffic-type rules can be set or on an automatic basis to spread WAN traffic evenly across all interfaces on a best-endeavour basis.

If you need more WAN connections, the Vigor 3900 supports VLAN tags on its WAN ports, allowing up to 50 WAN ports with optional Switch
VPN
As a VPN endpoint/concentrator, the Vigor 3900 will support up to 500 simultaneous teleworker or LAN-to-LAN VPNs, with a VPN throughput of up to 700Mb/s with IPsec VPN tunnels, thanks to its hardware-based VPN co-processor.
VPN security includes certificate, MOTP or token/PSK based access and key-hash authentication to ensure maximum security.
SSL VPN

DrayTek's SSL VPN uses standard TLS encryption (the same protocol used for HTTPS web sites) and therefore can pass unimpeded through most networks and public Internet access/WiFi.
An SSL VPN tunnel can be created from any client device - Windows, MacOS, iOS (iPhone/iPad) and Android phones and tablets. The freely available DrayTek Smart VPN Client app
makes it easy on any of those platforms. Once connected, you can access the remote resources and, commonly, create remote desktop sessions to the remote device.You can read more about SSL VPNs and MoTP here.
High Availability
For even greater resilience, the Vigor 3900 provides High Availability (HA).
The CARP protocol (equivalent to VRRP or HSRP) lets you set up a master and secondary Vigor 3900 whereby in the event of the master unit failing, the secondary unit can seamlessly and automatically switch over. This can remove the possibility of a single point of failure within your routers. Additionally, multiple active Vigor 3900's can provide reciprocal routing backup to other active Vigor 3900s.
Read more about DrayTek High Available here.
VPN - Linking remote offices, HQ, teleworkers and mobile staff
A feature central to DrayTek routers is its VPN (Virtual Private Networking) capabilities. A VPN enables you to link remote offices and branch offices back to HQ, or home-based/mobile teleworkers back to your office. Once connected, they have access to your office/remote resources through a secure encrypted tunnel allowing remote desktop, file sharing and seamless access to other resources and devices.
The Vigor 3900 allows you to have up to 500 simultaneous VPN tunnels to remote offices or teleworkers. It supports all common industry standard protocols, encryption types and authentication methods (see specification tab for full support list). Teleworkers can authenticate directly with your LDAP server if preferred.

The Vigor 3900 supports VPN trunking; this allows you to create tunnels down muliple WAN connections to a remote site in order to increase bandwidth. VPN trunking also provides failover (backup) of your VPN route down a secondary WAN connection. You can learn more about DrayTek VPN here. Teleworkers can also use 2FA (Two factor authentication) such as MOTP.
DrayTek SSL VPN - Link teleworkers and remote networks with TLS encryption

The Vigor 3900 supports up to 100 DrayTek SSL VPN tunnel connections. These are encrypted tunnels linking your teleworkers or remote DrayTek Vigor routers back to your main office using SSL/TLS technology - the same encryption that you use for secure web sites such as your bank.
Site to site VPN tunnels can connect branch offices to a main office, with DrayTek SSL VPN encryption securing the connection between the two offices, a TLS encrypted HTTPS tunnel which can be more secure than PPTP, and easier to configure than an IPsec VPN tunnel.
Teleworkers can easily create a secure DrayTek SSL VPN tunnel to the DrayTek Vigor 3900 using the DrayTek Smart VPN Client app.
DrayTek Smart VPN Client is free and supports Windows OS, macOS, Apple iOS (iPad, iPhone) and Android. You can learn more about the DrayTek Smart VPN Client here.
DrayTek SSL VPN is simple to configure, providing a more secure alternative to the now obsolete Point to Point Tunneling Protocol (PPTP VPN); which has known weaknesses and is now considered to be insecure. Setup is similar to a PPTP VPN tunnel in that it authenticates with an SSL VPN Username and Password.
You can learn more about DrayTek SSL VPNs here.
VPN Trunking
VPN Trunking is the facility to create more than one VPN tunnel, over a second Wan CONNECTION, to the same remote location in order to provide either increased bandwidth between the two sites (load balancing) or resilience (failover) in the event that one tunnel/connection is interrupted. The Vigor 3900 supports both Failover and Load Balancing modes for VPN Trunks.
The Vigor 3900 already supports load balancing to the Internet using its quad-WAN ports. What VPN trunking does is enables a single virtual tunnel to be created across both WAN connections to the same remote location creating a single virtual tunnel, recombining the tunnel at the other end. As far as the traffic and LAN devices/clients are concerned, there is just a single tunnel, with increased bandwidth.

In the diagram above, you can see a single virtual tunnel as far as the LAN at each end is concerned. Within the router, two WAN connections are being used with each router, across which the VPN tunnel can be spread, increasing total capacity and/or redundancy (for failover).
Vigor 3900 Specification
| Product Code | EAN | Description |
|---|---|---|
| V3900-K | 4716779074017 | Vigor 3900 (UK/IE) |
Technical Specification (UK Hardware Spec.)
-
Physical Interfaces
- WAN Ports:
- WAN1 : RJ-45 Gigabit Ethernet (1000Mb/s)
- WAN2 : RJ-45 Gigabit Ethernet (1000Mb/s)
- WAN3 : RJ-45 Gigabit Ethernet (1000Mb/s)
- WAN4 : RJ-45 Gigabit Ethernet (1000Mb/s)
- WAN5 : SFP Gigabit Slot for Fibre or other module (1000Mb/s)
- LAN Ports:
- 2 X RJ-45 Gigabit Ethernet (1000Mb/s)
- 1 X SFP Gigabit Slot for Fibre or other module (1000Mb/s)
- Console Port (RJ-45 physical, RS-232 electrical)
- WAN Ports:
-
Performance
- Firewall: Up to 1000Mb/s
- IPSec VPN: Up to 700Mb/s
- SSL VPN: Up to 100Mb/s
- NAT Sessions : 120,000
-
VPN Services
- Remote Dial In Teleworker Protocols:
- PPTP
- IPSec
- L2TP
- L2TP over IPSec
- SSL VPN
- LAN to LAN VPN Tunnel Protocols:
- PPTP
- IPSec
- SSL VPN
- GRE (LAN to LAN Tunnel) - New!
- Up to 500 simultaneous tunnels (LAN-to-LAN or Teleworker-to-LAN)
- PPTP Acceleration (90Mbps with encryption, 400Mbps without encryption)
- Dial-in and Dial-out supported
- VPN Trunking: allows alternative failover route or multiple tunnels to the same destination to increase capacity/throughput
- Multiple SA (Security Association) IPsec VPN support: send multiple Local and Remote subnets through one VPN tunnel - New!
- Teleworker - Remote Dial-In VPN Features:
- LDAP/Active Directory: Teleworker VPNs can be authenticated by a LDAP/AD server
- XAuth authentication support for IPsec Remote Dial-In Teleworker VPN tunnels - New!
- Radius Client: Authentication for Remote Dial-In Teleworkers
- Scheduled Remote Dial-In VPN - configure times that specified Teleworkers are allowed to Dial In - New!
- DrayTek Smart-VPN Software utility
- IPsec IKE Protocols:
- IKEv1
- IKEv2 - New!
- IPsec IKE Authentication:
- Pre-shared key (PSK)
- PKI Certificate (RSA): Use X.509 Digital Signatures
- Phase 1 Main Mode or Aggressive Mode
- Phase 2 selectable lifetimes
- Encryption:
- Hardware-based AES (128, 192, 256 bits)
- Hardware-based DES/3DES (56 & 168 bits)
- Hardware-based MD5, SHA-1 & SHA-256
- MPPE (40 or 128 bits)
- IKE Phase 1 DiffieHelman Groups 1,2,5 & 14
- IKE Phase 2 DiffieHelman Groups 1,2,5 & 14 (will match phase 1 selection)
- DHCP over IPSec
- GRE over IPSec
- Dead-Peer-Detection (DPD)
- NAT-Traversal (NAT-T): VPN over routes without VPN Passthrough
- No extra licencing or additional VPN client costs.
- Interoperability : Compatible with other 3rd party VPN devices
- Remote Dial In Teleworker Protocols:
-
Firewall
- Stateful Packet Inspection (SPI)
- Content Security Management (CSM)
- Multi-NAT: Set one-to-one mappings between your private and public IP addresses
- NAT Port Forward Features:
- Port Redirection - 256 entries with 16 port ranges per entry
- DMZ Host
- Server Load Balance & Inbound Load Balance
- SIP Application Layer Gateway (ALG)
- H.323 Application Layer Gateway (ALG)
- Policy-based IP Packet Filter. Fully configurable policies based on IP address, MAC address (source or destination), DiffServ attribute, direction, bandwidth, remote site
- DoS/DDoS Protection
- IP Address Anti-spoofing
- Object-Based Firewall
- Notification: Email alerts and logs to syslog
- Bind IP to MAC address
- User-Controlled Rules: Interrogates LDAP server to permit access or enforce policies
- DNSSEC support - New!
- LAN DNS Features:
- Control DNS resolution for A and CNAME records for configured hostnames
- Wildcard support
- Conditional Forwarding to specified DNS Server(s)
-
Web Content Filtering & CSM
- URL Keyword Blocking: Blacklist or Whitelist
- Content Type Blocking: Java applet, cookies, Active-X
- Application Enforcement (APPE): IM, P2P, Protocol, Tunnelling, Streaming, Remote Cotnrol, Wed HD
- Auto APPE Signature Upgrade
- Block P2P Applications (inc. Kazza, WinMX, Bittorrent)
- Block Instant messaging
- Block access of web sites by direct IP address (thus URLs only)
- Block HTTP download of compressed, executable or multimedia files
- Web Content Filter: GlobalView filtering of 64 web site categories (e.g. adult, gambling sites etc.). subscription required (free trial included)
- Time Scheduling: Blocking rules can be activated based on time schedules
-
User Management
- Manage account features through User Profiles - VPN, PPPoE, Web Portal, FTP, Samba
- Internal RADIUS Server
- External LDAP / Active Directory server authentication with SSL support
- External RADIUS server authentication
- PPPoE Server
- Guest Profiles with Guest Account Generator
- Web Portal Features:
- User Authentication for Internet access with Time Quotas
- SMS Authentication (requires SMS provider)
- Web Portal Login Page Customisation
- Login History
-
System Management
- Web-Based User Interface: Integrated server for router management (via HTTP or HTTPS)
- Telnet/SSH : Command line control and configuration
- Configuration Backup/Restore
- Built-in diagnostics, dial-out triger, routing table, ARP table, DHCP Table, NAT Sessions Table, data flow monitor, traffic graph, ping diagnostics, traceroute
- Firmware Upgrade by HTTP, TFTP & FTP
- Syslog Logging
- SNMP Management: v1/v2/v3, MIB II
- Mail Alert & Mail Notifications with SSL & StartTLS encryption support
- Vigor ACS-SI Centralised Management: TR-069 compatible for ACS platform
- Compatible with Smart Monitor Traffic Analyser : Windows software for up to 100 users
-
Central Management
- AP Management - Manage up to 30 compatible VigorAP access points - New!
- Switch Management - Manage up to 20 compatible VigorSwitch switches - New!
- VPN Management - Manage up to 16 DrayTek Vigor routers
-
Certificate Management
- Local Certificates for HTTPS, SSL & VPN
- Remote Certificates; Sign and manage certificates from other devices - New!
-
Bandwidth Management
- Traffic Shaping: Dynamic bandwidth management with IP traffic shaping
- Bandwidth Reservation: Connection or client based
- Packet Size Control
- DiffServ Codepoint Classifying
- 4 Priority Levels (Inbound/Outbound)
- Individual IP Bandwidth Session Limits per user/group
- Bandwidth Borrowing
- User-defined class-based rules
-
Routing Functions
- IPv4 & IPv6 Dual-Stack
- Up to 50 LAN Subnets / VLANs
- WAN Protocols: PPPoE, PPTP, DHCP Client, Static IP
- Load Balancing: Policy based or automatic
- WAN Failover: Switch to other connection when primary WAN lost
- DNS Cache/Proxy
- DHCP Client, Server & Relay
- DHCP Options: 1,3,6,51,53,54,58,59,60,61,66,125
- IGMP v1/v2 & Proxy/Snooping
- uPnP: 500 Sessions
- NAT: 120,000 Sessions
- NTP Client with DST Adjustments
- Static routing
- Policy-based routing with scheduling - New!
- BGP Routing protocol
- Dynamic DNS : Updates DDNS servers with public IP address
- Port-Based VLAN
- Tag-Based VLAN: 802.1q
- Client/Call Scheduling : Real-time clock, with NTP updating schedules access or connectivity
- Wake-on-LAN : Passed from WAN to preset LAN device
-
Operating Requirements
- Rack Mountable. 1U. (Mount brackets included)
- Temperature Operating : 0 °C ~ 45 °C
- Storage : -10 °C ~ 70 °C
- Humidity 10% ~ 90% ( non-condensing )
- Power Consumption: 20W max (typically 10-15W)
- Dimensions: 443 x 280 x 44 mm (LxWxH) - 1U
- Operating Power: 220-240VAC
- Warranty
- Two (2) Year Manufacturer's RTB
- Optional VigorCare Enhanced Warranty Available
- VigorCare D3 3 Year Subscription: VCARE-D3
- VigorCare D5 5 Year Subscription: VCARE-D5
