About

Learn what makes this product unique and why it’s right for you.

The Vigor2928 is a Dual-WAN VPN router equipped with three 10G interfaces, supporting both Ethernet and fiber connections. As DrayTek’s first router with a 10G Ethernet WAN, it delivers high-performance WAN connectivity for bandwidth-intensive networks.

The Vigor2928 supports advanced features, including load balancing, VPN, QoS, IP/URL filtering, and a hotspot portal with built-in IAM to enhance network security. It also functions as a virtual controller for the centralized management of VigorAPs and VigorSwitches.



KEY FEATURES

  • Ready to connect to NTD (Network Termination Device) of NBN (Aust) and UFB (NZ)
  • Multi-WAN for Failover, Load Balancing and High Availability mode
  • 1 x fixed GbE WAN port (P1)
  • 1 x 10GbE WAN/LAN port (P3)
  • 1 x fixed SFP+ WAN port (P2)
  • 1 x 10GbE SFP+ LAN slot (P4)
  • For P2~P4, any two of these three ports can be used simultaneously, and P3 can also beconfigured as a high-speed LAN port when not serving as the WAN
  • 1 x fixed 2.5GbE LAN port (P5)
  • 3 x fixed GbE LAN ports (P6~P8)
  • 2 x USB 2.0 ports for connection to two 4G LTE USB modems, FTP server, network printer and thermometer
  • Up to 8 subnets and 60,000 NAT sessions
  • 50 x VPN tunnels, including IPsec, OpenVPN, and WireGuard, with EasyVPN features that simplify VPN setup for effortless connectivity
  • IPsec VPN throughput up to 540 Mbps (AES 256 bits)
  • WireGuard VPN throughput up to 85 Mbps
  • Object-based SPI Firewall, Content Security Management (CSM), URL/IP Reputation and Port Knocking
  • IAM (Identity and Access Management) to enhance security management and user experience
  • IPv6 & IPv4
  • Virtual AP Controller for the deployment of up to 20 wireless VigorAPs
  • Virtual Switch Controller to manage up to 10 VigorSwitches
  • Supports VigorACS 3 Central Management Software for remote management
  • 2 years back to base warranty



SPECIFICATION

Performance
NAT Session 60,000
Max. NAT (Mbps) 9300
WAN
Ethernet (1 GbE) 1
Ethernet (10 GbE) 1
SFP (10G) 1
Ethernet – Switchable
* When this field is filled, the port count above includes both switchable and fixed ports.
Cellular (via USB) 2
Internet Connection
IPv4 PPPoE, DHCP, Static IP
IPv6 PPP, DHCPv6, Static IPv6, TSPC, 6rd, 6in4 Static Tunnel
802.1p/q Multi-VLAN Tagging
Failover
Load Balancing IP-based, Session-based
Connection Detection ARP, Ping
WAN Data Budget
Dynamic DNS
DrayDDNS
LAN
Fixed LAN (RJ-45, GbE) 3
Fixed LAN (RJ-45, 2.5GbE) 1
LAN Subnet 8
VLAN 802.1q Tag-based VLAN
Max. Number of VLAN 8
DHCP Server Multiple IP Subnet, Custom DHCP Options, Bind-IP-to-MAC
Wired 802.1x Authentication
Port Mirroring
Local DNS Server
Conditional DNS Forwarding
Hotspot Web Portal (Profile No.) 4
Hotspot Authentication Click-Through, Social Login, SMS PIN, RADIUS, External Portal Server
Other Ports
USB 2
USB Type 2.0
USB Application User Management, File Explorer, FTP File Sharing, Device Status, Printer Server, Temperature Sensor, USB WAN
SMB File Sharing
(Requires external storage)
Networking
Routing IPv4 Static Routing, IPv6 Static Routing, Policy Route, Inter-VLAN Route,
RIP v1/v2, OSPF(V2/V3), BGP
Policy-based Routing Protocol, IP Address, Port
DNS Security (DNSSEC)
IGMP IGMP v2/v3, IGMP Proxy, IGMP Snooping & Fast Leave
Local RADIUS server
Bandwidth Management
Traffic Shaping Policy
IP-based Bandwidth Limit
IP-based Session Limit
QoS (Quality of Service) IP Address, Port, Application
APP QoS
Default Policy
VoIP Prioritization
NAT
Port Forwarding
DMZ Host
Port Trigger
ALG (Application Layer Gateway) SIP, RTSP, FTP, H.323
UPnP
Management
Local Service HTTP, HTTPS, Telnet, SSHv2, FTP, TR-069
Config Backup/Restore
Firmware Upgrade WUI, TFTP, TR-069
Role-based Privilege
Access Control Access List, Brute Force Protection
Notification Alert SMS, E-mail
SNMP v1, v2c, v3
Syslog
Virtual AP Controller (Device up to) 20
Virtual Switch Controller 10
Managed by VigorACS Since f/w v5.4.0
Security
URL/IP Reputation
Firewall Filter IP, Content, Traffic
Port Knocking *
Defense Setup ARP Spoofing, IP Spoofing
MAC Filtering Profile
IPv6 Address Security
IAM
Users & Groups
Access Policies
Group Policies
Conditional Access Policy
Resources
Account Status
Backup and Restore
VPN
Site-to-Site VPN
Teleworker VPN
EasyVPN
Protocols IPsec, IKEv1/IKEv2, IKEv2-EAP, IPsec-XAuth, OpenVPN, WireGuard
Max. VPN Tunnels 50
IPsec VPN Throughput
(AES 256 bits)
540 Mbps (single-directional)
WireGuard VPN Throughput 85 Mbps (single-directional)
User Authentication Local, RADIUS, TACACS+, mOTP, TOTP
IKE Authentication Pre-Shared Key, X.509
IPsec Authentication SHA-1, SHA-256
Encryption DES, 3DES, AES
Translate Local Network
(Site-to-Site VPN)
Single-Armed VPN
NAT-Traversal (NAT-T)
VPN Matcher
VPN Connection Status
Backup & Restore
Monitoring
Log Center
WAN
ARP Table
Route Table
DHCP Table
IPv6 TSPC Status
IPv6 Neighbor Table
LLDP Neighbors
DNS Cache Table
Remote DSL Status
SFP Information
PPPoE Pass-Through
Session Table
Running Service
Physical
Power Supply Vigor2928: DC 12V @ 1.15A
Max. Power Consumption Vigor2928: 18 watts
Dimension 241mm x 165mm x 43mm
Weight Vigor2928: 590.6g
Operating Temperature 0 to 45°C
Storage Temperature -25 to 70°C
Operating Humidity (non-condensing) 10 to 90%



Note :
  • All specifications are subject to change without notice.
  • The throughput figures are maximum, based on DrayTek internal testing with optimal conditions. The actual performance may vary depending on the different network conditions and applications activated.
Learn what makes this product unique and why it’s right for you.

The Vigor2928 is a Dual-WAN VPN router equipped with three 10G interfaces, supporting both Ethernet and fiber connections. As DrayTek’s first router with a 10G Ethernet WAN, it delivers high-performance WAN connectivity for bandwidth-intensive networks.

The Vigor2928 supports advanced features, including load balancing, VPN, QoS, IP/URL filtering, and a hotspot portal with built-in IAM to enhance network security. It also functions as a virtual controller for the centralized management of VigorAPs and VigorSwitches.



KEY FEATURES

  • Ready to connect to NTD (Network Termination Device) of NBN (Aust) and UFB (NZ)
  • Multi-WAN for Failover, Load Balancing and High Availability mode
  • 1 x fixed GbE WAN port (P1)
  • 1 x 10GbE WAN/LAN port (P3)
  • 1 x fixed SFP+ WAN port (P2)
  • 1 x 10GbE SFP+ LAN slot (P4)
  • For P2~P4, any two of these three ports can be used simultaneously, and P3 can also beconfigured as a high-speed LAN port when not serving as the WAN
  • 1 x fixed 2.5GbE LAN port (P5)
  • 3 x fixed GbE LAN ports (P6~P8)
  • 2 x USB 2.0 ports for connection to two 4G LTE USB modems, FTP server, network printer and thermometer
  • Up to 8 subnets and 60,000 NAT sessions
  • 50 x VPN tunnels, including IPsec, OpenVPN, and WireGuard, with EasyVPN features that simplify VPN setup for effortless connectivity
  • IPsec VPN throughput up to 540 Mbps (AES 256 bits)
  • WireGuard VPN throughput up to 85 Mbps
  • Object-based SPI Firewall, Content Security Management (CSM), URL/IP Reputation and Port Knocking
  • IAM (Identity and Access Management) to enhance security management and user experience
  • IPv6 & IPv4
  • Virtual AP Controller for the deployment of up to 20 wireless VigorAPs
  • Virtual Switch Controller to manage up to 10 VigorSwitches
  • Supports VigorACS 3 Central Management Software for remote management
  • 2 years back to base warranty



SPECIFICATION

Performance
NAT Session 60,000
Max. NAT (Mbps) 9300
WAN
Ethernet (1 GbE) 1
Ethernet (10 GbE) 1
SFP (10G) 1
Ethernet – Switchable
* When this field is filled, the port count above includes both switchable and fixed ports.
Cellular (via USB) 2
Internet Connection
IPv4 PPPoE, DHCP, Static IP
IPv6 PPP, DHCPv6, Static IPv6, TSPC, 6rd, 6in4 Static Tunnel
802.1p/q Multi-VLAN Tagging
Failover
Load Balancing IP-based, Session-based
Connection Detection ARP, Ping
WAN Data Budget
Dynamic DNS
DrayDDNS
LAN
Fixed LAN (RJ-45, GbE) 3
Fixed LAN (RJ-45, 2.5GbE) 1
LAN Subnet 8
VLAN 802.1q Tag-based VLAN
Max. Number of VLAN 8
DHCP Server Multiple IP Subnet, Custom DHCP Options, Bind-IP-to-MAC
Wired 802.1x Authentication
Port Mirroring
Local DNS Server
Conditional DNS Forwarding
Hotspot Web Portal (Profile No.) 4
Hotspot Authentication Click-Through, Social Login, SMS PIN, RADIUS, External Portal Server
Other Ports
USB 2
USB Type 2.0
USB Application User Management, File Explorer, FTP File Sharing, Device Status, Printer Server, Temperature Sensor, USB WAN
SMB File Sharing
(Requires external storage)
Networking
Routing IPv4 Static Routing, IPv6 Static Routing, Policy Route, Inter-VLAN Route,
RIP v1/v2, OSPF(V2/V3), BGP
Policy-based Routing Protocol, IP Address, Port
DNS Security (DNSSEC)
IGMP IGMP v2/v3, IGMP Proxy, IGMP Snooping & Fast Leave
Local RADIUS server
Bandwidth Management
Traffic Shaping Policy
IP-based Bandwidth Limit
IP-based Session Limit
QoS (Quality of Service) IP Address, Port, Application
APP QoS
Default Policy
VoIP Prioritization
NAT
Port Forwarding
DMZ Host
Port Trigger
ALG (Application Layer Gateway) SIP, RTSP, FTP, H.323
UPnP
Management
Local Service HTTP, HTTPS, Telnet, SSHv2, FTP, TR-069
Config Backup/Restore
Firmware Upgrade WUI, TFTP, TR-069
Role-based Privilege
Access Control Access List, Brute Force Protection
Notification Alert SMS, E-mail
SNMP v1, v2c, v3
Syslog
Virtual AP Controller (Device up to) 20
Virtual Switch Controller 10
Managed by VigorACS Since f/w v5.4.0
Security
URL/IP Reputation
Firewall Filter IP, Content, Traffic
Port Knocking *
Defense Setup ARP Spoofing, IP Spoofing
MAC Filtering Profile
IPv6 Address Security
IAM
Users & Groups
Access Policies
Group Policies
Conditional Access Policy
Resources
Account Status
Backup and Restore
VPN
Site-to-Site VPN
Teleworker VPN
EasyVPN
Protocols IPsec, IKEv1/IKEv2, IKEv2-EAP, IPsec-XAuth, OpenVPN, WireGuard
Max. VPN Tunnels 50
IPsec VPN Throughput
(AES 256 bits)
540 Mbps (single-directional)
WireGuard VPN Throughput 85 Mbps (single-directional)
User Authentication Local, RADIUS, TACACS+, mOTP, TOTP
IKE Authentication Pre-Shared Key, X.509
IPsec Authentication SHA-1, SHA-256
Encryption DES, 3DES, AES
Translate Local Network
(Site-to-Site VPN)
Single-Armed VPN
NAT-Traversal (NAT-T)
VPN Matcher
VPN Connection Status
Backup & Restore
Monitoring
Log Center
WAN
ARP Table
Route Table
DHCP Table
IPv6 TSPC Status
IPv6 Neighbor Table
LLDP Neighbors
DNS Cache Table
Remote DSL Status
SFP Information
PPPoE Pass-Through
Session Table
Running Service
Physical
Power Supply Vigor2928: DC 12V @ 1.15A
Max. Power Consumption Vigor2928: 18 watts
Dimension 241mm x 165mm x 43mm
Weight Vigor2928: 590.6g
Operating Temperature 0 to 45°C
Storage Temperature -25 to 70°C
Operating Humidity (non-condensing) 10 to 90%



Note :
  • All specifications are subject to change without notice.
  • The throughput figures are maximum, based on DrayTek internal testing with optimal conditions. The actual performance may vary depending on the different network conditions and applications activated.

Draytek Vigor 2928 Multi-WAN Router with 1 x 10GbE WAN/LAN port, 1 x 10GbE SFP+ WAN slot, 1 x GbE WAN port, 1 x 10GbE SFP+ LAN slot, 1 x 2.5GbE LAN port, 3 x GbE LAN ports, SPI Firewall, and 50 x IPsec/OpenVPN/WireGuard VPN tunnels

Regular price
$690.00
Sale price
$690.00
Regular price

SKU: DV2928

Check Out These Related Products