Call us: +61 2 9838 8899
FAX: +61 2 9838 8818


Penta-WAN Gigabit Router with 1 x Gigabit LANs & 64 x VPN tunnels


  • NBN (National Broadband Network – Australia) Ready to connect to NTD (Network Termination Device)
  • 4 x Gigabit WAN ports & 1 x USB ports for 3.5G / 4G Mobile with Load Balance and Fail-Over
  • 1 x Gigabit LAN ports with 100,000 NAT sessions and IPv6
  • Object-based SPI Firewall, Content Security Management (CSM) and QoS
  • 64 x VPN tunnels with VPN load balance and redundancy & 10 x SSL VPNs
  • Up-to 40Mbps site-to-site IPsec VPN throughput
  • 1 x USB port for 3.5G / 4G modem, USB disk storage & network printer
  • Support Smart Monitor Traffic Analyzer (up to 100-nodes)
  • Support TR-069 for VigorACS SI Central Management
  • 2 years back to base warranty


  • Overview
  • Features of the Vigor3200 series Multi-Subnet security routers will satisfy the network requirements of small to medium business networks. Its Multi-Subnet interface with Multi-VLAN function allows users to easily divide network into different sections based on applications, such as VoIP, web or ftp server or user groups, such as Sales, Technical Support or HR dept. Each usage/application or user group can get its dedicated bandwidth and administrator can have security control between user groups for preventing possible data leakage.

    Multi-WAN with Bandwidth Management

    All these 4xGbps WAN ports support current xDSL/Cable/Satellite broadband and the USB port also allows connection to the 3.5G Mobile Broadband. The WAN ports can be configured to increase data throughput, backup each other (Failover mode), or share the traffic (Load Balance). If you have your own Web server, FTP server and mail server, the 4 WAN ports will provide additional bandwidth for customers. In addition, the 1xGbps LAN port switch compatible with PoE switch (e.g. VigorSwitch P2260) and Gigabit switch (e.g. VigorSwitch G2080/G2240) can support large data transfer and connect to multiple client devices (PC/servers) in small to medium LAN networks.

    Vigor3200 series embedded with tag-based multi-subnet function can maximize the investment of your obtained bandwidth. For example, you can allocate your 100Mbps broadband connection(s) to timing critical applications such as VoIP, web or ftp severs and business essential departments such as Sales and Technical Support team. You additional low monthly fee DSL or cable line can be used by mail server or HR team which don’t need fast data/voice packet transmission for daily operation. SMB can get highly cost-effective and secure network as adopting Vigor3200 series.

    USB Port for 3.5G or FTP/Printer Server

    The capability of the USB port to connect to 3.5G mobile broadband means that the router can be used in anywhere with 3.5G coverage, such as moving vehicles, temporary events, offices where xDSL or Cable are not available, etc.
    Apart from supporting printer servers, the USB port also allows the connection of a USB disk or hard drive for FTP file transfer through the Internet or local networks. The network administrator can set username/password and directory/file access privilege for individual users.

    DMZ Port for providing servers with extra protection

    The DMZ port of Vigor3200 series can provide additional layer protection to servers, such as Web server, which need to expose resources from untrusted network: e.g. Internet but also have uncompromising internal LAN security requirements.

    Through the user-friendly WUI of Vigor3200 series, admin can activate DMZ by NAT or Physical mode to the chosen server. That would makes external attacks only have access to the external-facing equipment in the DMZ, not entire LAN to insert extra layer of protection to SMB’s internal network.

    Combination of VLAN, Tagging and QoS

    With all this connectivity, your LAN and WAN increases in complexity, but the comprehensive VLAN and QoS enables your efficient utilization of your bandwidth on your LAN and WAN side. The 802.1q VLAN is supported on both the LAN and WAN ports. By applying 802.1q VLAN tagging, the marked packets will be transmitted together and split further along in your network topology, as required, or merely dropped/ignored if they fall outside a device’s VLAN settings. The Quality of Service (QoS) allows you to give specific traffic types or clients different levels of priority when it comes to transmitting data so that the most appropriate amount of total bandwidth is reserved for the most important data. The VLAN groups and QoS (802.1p & TOS/DSCP Methods) can be combined with QoS rules for transmission to the Internet. After you set up VLAN groups for your office network, you can define firewall rules together with VLAN groups to let remote VPN links to only access the specific LAN ports. The Vigor3200 series are with four LAN subnets which are very useful for multi-tenanted applications or where there is necessity of department segmentation. The VLAN setup can be applied to the four LAN subnets for isolated connection. For example, you are running a public web server on your network. The VLAN segmentation with different subnets will give a fully isolated connection to the said public web server.

    Firewall and Security

    The Vigor3200 series offer you robust firewall options with both IP-layer and content-based protection. The DoS/DDoS prevention and URL/Web content filter strengthen the security outside and inside the network. The enterprise-level CSM (Content Security Management) enables users to control and manage IM (Instant Messenger) and P2P (Peer-to-Peer) applications more efficiently. The CSM hence prevents inappropriate content from distracting employees and impeding productivity. Furthermore, the CSM can keep office networks threat-free and available.

    The “User Management” implemented on your router firmware can allow you to prevent any computer from accessing your Internet connection without a username or password. You can also allocate time budgets to your employees within office network.

    Comprehensive VPN

    Up to 64 simultaneous hardware based VPN tunnels are supported providing a throughput up to 40Mbps. Each of these can be configured to use any of the common VPN protocols: PPTP, IPSec, L2TP, L2TP over IPSec, etc., and with any of the most up-to-date encryption (MPPE, AES/DES/3DES), Authentication (MD5, SHA-1), Pre-shared Key, Digital Signature (X.509). These tunnels can be used for LAN-to-LAN or remote dial-in.

    The Vigor3200 series support up to 64 concurrent VPN tunnels for LAN-to-LAN and remote access. There are up 10 concurrent tunnels of SSL Web Proxy and SSL Applications on Vigor3200 series for teleworkers. Along with Ethernet WAN ports, the VPN trunking (VPN load-balancing and VPN backup) are available on Vigor3200 series.

    Working with Smart Monitor Traffic Analyzer

    Vigor3200 supports 100-Node DrayTek Smart Monitor Traffic Analyser which enables you to analyze in great depth your Internet traffic, as a professional aid to improving efficiency and detecting potential problems.

    Easy Network Management

    Configuring Vigor3200 router is easy with the web based configuration pages, plus the CLI/Telnet/SSH methods. Tools allowing network administrators to manage and maintain the networks with ease include:

    • Diagnostic Tables that show network connection status
    • SNMP for network traffic monitoring
    • Two levels of Access Control to prevent unauthorized access to the router
    • TR-069 for service providers to manage user devices remotely

    Active Directory / LDAP for authentication

    DrayTek makes authentication for VPN Remote Access with ease by Vigor3200 Series. Network administrator doesn’t have to create new Remote Dial-in User Profiles for authentication mechanism but applies existed user accounts saved in the external server (e.g. Active Directory/LDAP). This enhancement significantly saves the time of IT Dept while establishing the secure remote access network for tele-workers.

    More features are available to support business networks’ operations, such as Call Scheduling, RADIUS support, UP&P, VLAN, QoS, Packet Forward Acceleration, etc.

  • Features
      1. Multi-WAN (Ethernet / 3.5G)
        • Outbound Policy-based Load-balance
        • WAN Connection Failover
      2. WAN Protocol
        • DHCP Client
        • Static IP
        • PPPoE
        • PPTP
        • BPA
        • L2TP
      3. VPN
        • Up to 64 VPN Tunnels
        • Protocol : PPTP, IPsec, L2TP, L2TP over IPsec
        • Encryption : MPPE and Hardware-based AES/DES/3DES
        • Authentication : Hardware-based MD5, SHA-1
        • IKE Authentication : Pre-shared Key and Digital Signature (X.509)
        • LAN-to-LAN, Teleworker-to-LAN
        • DHCP over IPsec
        • IPsec NAT-traversal (NAT-T)
        • Dead Peer Detection (DPD)
        • VPN Pass-through
        • VPN Wizard
        • SSL VPN
      4. Firewall
        • Multi-NAT, DMZ Host, Port-redirection and Open Port
        • Object-based Firewall
        • MAC Address Filter
        • SPI (Stateful Packet Inspection) (Flow Track)
        • DoS / DDoS Prevention
        • IP Address Anti-spoofing
        • E-mail Alert and Logging via Syslog
        • Bind IP to MAC Address
        • Time Schedule Control
      5. USB
        • 3.5G (HSDPA)/4G (LTE) as WAN
        • Printer Sharing
        • File System:
          • Support FAT32 File System
          • Support FTP Function for File Sharing
      6. Bandwidth Management
        • QoS
          • Guarantee Bandwidth for VoIP
          • Class-based Bandwidth Guarantee by User-defined Traffic Categories
          • DiffServ Code Point Classifying
          • 4-level Priority for Each Direction (Inbound/Outbound)
          • Bandwidth Borrowed
        • Bandwidth / Session Limitation
        • Layer-2 (802.1p) and Layer-3 (TOS / DSCP) QoS Mapping
      7. Network Management
        • Web-Based User Interface (HTTP/HTTPS)
        • Quick Start Wizard
        • Dashboard
        • CLI (Command Line Interface, Telnet/SSH)
        • Administration Access Control
        • Configuration Backup/Restore
        • Built-in Diagnostic Function
        • Firmware Upgrade via TFTP/FTP/HTTP/TR-069
        • Logging via Syslog
        • SNMP Management MIB-II (v2/v3)
        • Management Session Time Out
        • 2-level management (Admin/User Mode)
        • TR-069 Management
        • TR-104 Management
      8. Content Security Management
        • IM/P2P Applications V3 (APP Enforcement)
        • GlobalView Web Content Filter (Powered by CYREN-90)
        • URL Content Filter
          • URL Keyword Blocking (Whitelist and Blacklist)
          • Java Applet, Cookies, Active X, Compressed, Executable, Multimedia File Blocking
          • Excepting Subnets
          • Time Schedule Control
      9. Network Features
        • Packet Forwarding Acceleration
        • DHCP Client/Relay/Server
        • DHCP Option
        • IGMP V2
        • Dynamic DNS
        • NTP Client
        • Call Scheduling
        • RADIUS Client
        • DNS Proxy
        • UPnP 30 sessions
        • Routing Protocol
          • Static Routing
          • RIP V2
        • Multiple Private LAN Subnets(Multi-Subnets)
        • VLAN Tagging (802.1q) on WAN
      10. Declaration of Conformity

  • Hardware Interface
  • Interface of Vigor3200
    Hardware Interface
    4 x 1000Based-Tx WAN, RJ-45
    1 x 100Base-TX DMZ Port, RJ-45
    1 x 1000Base-TX LAN Port, RJ-45
    1 x Factory Reset Button
    1 x USB Host 2.0 (for Printer / 3.5G USB Modem)
    Declaration of Conformity
    Temperature Operating : 0°C ~ 45°C
    Storage : -25°C ~ 70°C
    Humidity 10% ~ 90% (Non-condensing)
    Max. Power 10 Watt
    Dimension L240.96 * W165.07 * H43.96 ( mm )
    Power DC 15V /1.34A
  • Applications
  • Advance Business Network (Multi WAN / SSL VPN)

    Support up-to 10 SSL VPN tunnels

    Multi-WAN Load Balancing / Failover  LAN & WAN Status

    Multi subnet with VLAN tag – Multi-tenant applications along with FTTx

    VPN failover / backup by VPN trunk management

    Active Directory/LDAP Group Management for VPN remote dial-in authentication

    Working with Smart Monitor Traffic Analyzer

    The version 3.3.7 firmware of Vigor3200 supports 100-Node DrayTek Smart Monitor Traffic Analyzer which enables you to analyze in great depth your Internet traffic, as a professional aid to improving efficiency and detecting potential problems.

    Vigor3200 series with rackmount bracket

  • Downloads
  • Version Information

    Firmware Version 3.6.7
    Release Date 15/07/2014
    Support Language English

    Firmware Downloads

    Name Description Firmware For Standard


    Release Note Vigor3200_v3.6.7_release_note.pdf
    User’s Guide UG-Vigor3200-V1.61.pdf
    Quick Start Guide QS-Vigor3200-V1.0.pdf
    Datasheet Vigor3200-datasheet-110315.pdf

    Product Images

    Model JPG TIFF ZIP
    Vigor3200 Vigor3200

  • Web Demo
  • Open Link in New Tab