Vigor 3900

$ 1,045.00

Quad-WAN Load Balancing Router & VPN Gateway

  • 4 Gigabit Ethernet WAN ports + 1 SFP Fiber WAN
  • 2 Gigabit Ethernet LAN ports + 1 SFP Fiber LAN
  • 2 USB port for 3G/4G Backup (or Load Balancing), printer, or temperature sensor
  • 500 simultaneous VPN tunnel, including up to 100 SSL VPN
  • Outbound & Inbound Load Balancing
  • Support High Availability (hardware redundancy)
  • Support PPPoE server with quota policy and MAC address filter
  • Flexible Firewall, Content Filtering, and Bandwidth Management policies
  • Central Management for Vigor Router, VigorAP, and Vigor Switch
  • Compliant with VigorACS2
  • Support DrayDDNS (Since f/w v1.4.0)


Vigor3900 is a high-performance multi-WAN Load Balancing Firewall Router as well as a VPN concentrator for up to 500 concurrent users. It offers enterprise-level functions including Routing, Firewall and content filtering, PPPoE server, bandwidth management, QoS, Inbound Load Balancing, Web Portal, and High Availability.

WAN Load Balancing

Vigor3900 offers WAN throughput up to 1 Gbps, there are 4 Gigabit Ethernet WAN ports and 1 SFP slot for either load balance or failover applications, up to 2 3G/4G USB modems can be attached to the USB ports to add additional cellular connectivity. Up to 7 physical WAN connections can be active simultaneously to provide a high-performance as well as high-availability network.

While acting as an authoritative DNS server, VIgor3900 can also perform inbound load balancing to distribute the incoming connection requests across multiple WAN links to the server behind Vigor3900.

High Capacity VPN

As a VPN concentrator, Vigor3900 allows up to 500 concurrent VPN connection, including LAN-to-LAN and Teleworker-to-LAN VPN. All the industry standard tunneling protocols are supported, including PPTP, L2TP, IPsec, IKEv2, and GRE. DrayTek SSL VPN is also provided. Vigor3900 also features VPN trunking, which allows you to establish multiple VPN tunnels to one remote network but through different WAN links. The two trunking tunnels can be used for load balancing application to increase the VPN throughput, or to be used in failover mode to provide a backup access.

User Management

Vigor3900 provides an integrated solution for local user management. Besides being a VPN gateway for remote dial-in users, it can also be a PPPoE server to authenticate LAN clients and track data usage of each client; and also a web portal server for authenticating guests and displaying information. Vigor3900 supports user authentication based on local user profiles or external authentication servers, including RADIUS and LDAP/Active Directory. Furthermore, Vigor3900 allows user-based management rules, content filtering policies and bandwidth management policies can all be to be applied to a certain user profile, user group, or even certain LDAP profile. This ensures the security of local network while providing Internet services to plenty of users.

High Availability (Hardware Redundancy)

Vigor3900 offers High Availability to prevent a single point of failure. The feature is based on the Common Address Redundancy Protocol (CARP). The network administrator can add a redundant Vigor3900 to the network as a standby router, in the events of failure of the main Vigor3900, the backup one can take over the traffic automatically, and reduce the downtime of the network.


  • WAN:
    4 Gigabit Ethernet
    1 SFP slot
  • LAN:
    2 Gigabit Ethernet
    1 SFP slot
  • 2 USB ports
  • 1 console port
  • Factory Reset Button
  • Power On/Off Switch
  • Max. Power Consumption: 20 watts
  • Operating: 0 ~ 45°C
  • Storage: -10°C ~ 70°C
  • Operating: 10% ~ 90%
Dimension (mm)
  • 443(L) x 285(W) x 45(H)
Ethernet Connection (IPv4)
  • PPPoE Client
  • DHCP Client
  • Static IP
  • 802.1Q VLAN Tagging
    (Up to 50 profiles)
  • Triple-Play Applications
Ethernet Connection (IPv6)
  • PPP
  • DHCPv6 Client
  • Static IPv6
Load Balance
  • IP-based Load Balancing
  • Session-based Load Balancing
  • Custom Weight
  • Inbound Load Balancing
  • Failover by Link Failure
Connectivity Detection
  • ARP
  • Ping Probe
High Availability
  • Active-Standby Method
  • Hot-Standby Method
LAN Managment
  • Up to 64 VLAN
DHCP Server
  • Up to 50 IP Subnet
  • DHCP Server
  • PPPoE Server
  • Bind-IP-to-MAC (DHCP Reservation)
DNS Control
  • Local Name Server
Hotspot Portal
  • Authentication: Local User Profile, Guest Profile, RADIUS, LDAP, SMS PIN
  • Landing Page: URL Redirection, Bulletin Board
  • Mobile Device Blocking
  • Custom Portal Page
  • Walled Garden
Static Route
  • 200 IPv4 Static Routes
  • 200 IPv6 Static Routes
Dynamic Routing
  • RIPv1, v2
  • OSPF
  • BGP
Policy Routing
  • 120 Route Policy
  • Criteria: Protocol, Source IP, Destination IP, Destination Domain Name, Destination Country, Destination Port
  • Failover options
  • Scheduled Enable/Disable
  • Up to 500 concurrent  tunnels
  • Max.100 concurrent SSL VPN
  • PPTP, L2TP, IPsec, L2TP over IPsec, SSL, GRE, IKEv2, OpenVPN (Since f/w v1.4.0)
  • LAN-to-LAN VPN
  • Teleworker-to-LAN VPN
  • MPPE 40/128 bit
  • Hardware-based AES/DES/3DES
  • MD5, SHA1, SHA2-256
  • Pre-Shared Key, Digital Signature (X.509)
  • mOTP
  • Hub-and-Spoke Topology support
  • DHCP over IPsec
  • VPN Redundancy for Load Balancing or Failover
  • One-to-One Port Redirection
  • Range-to-Range Port Redirection
  • Range-to-One Port Redirection
  • Server Load Balance
  • DMZ Host
  • ALG: SIP, H.323
  • VPN Pass-Through: PPTP, L2TP, IPsec
  • UPnP 500 sessions
Firewall Filter
  • IP Filter
  • IPv6 Filter
  • Country Filter
  • MAC Address Filter
  • Object-based Configuration
  • Scheduled Enable/Disable
Content Filtering
  • Application Filter
  • URL Keyword Filtering
  • Category Filtering (subscription required)
  • DNS Keyword Filtering
  • Web Features Filtering
  • QQ Filter
  • IP-Based Policy
  • User-Based Policy
  • Scheduled Enable/Disable
Attack Protection
  • DoS Defense
Bandwidth Management
Bandwidth Policy
  • Session Limit
  • Bandwidth Limit
  • IP-Based Policy
  • User-Based Policy
  • Scheduled Enable/Disable
Quality of Service
  • Layer 3 QoS (TOS/DSCP)
  • 4-Level Priority with user-defined classification
  • Bandwidth Borrowing
  • Guaranteed bandwidth for VoIP traffic
Network Features
  • Dynamic DNS
  • DNS Security
  • GVRP
  • IGMP Proxy
  • SMB File Sharing
  • FTP Server
User Authentication
  • Local User Database
  • RADIUS Server
  • Active Directory/LDAP
  • Web Interface: HTTP, HTTPS
  • Command-Line Interface: Telnet, SSH
  • TR-069 via VigorACS
  • Configuration File Export & Import
F/W Upgrade
  •  TFTP, HTTP, FTP, TR-069
Admin Access Control
  • 2-level Administration Privilege
  • Access from the Internet
  • Access List
  • Brute Force Protection
  • Login Page Greeting
  • Dashboard
  • Syslog
  • SMS/E-mail Alert
  • TR-069 via VigorACS
  • SNMP v2, v2c, v3
  • Port Mirroring
Central Management
  • Wireless Controller for up to 50 VigorAP
  • 20 Vigor Switch
  • 16 Vigor Router (CVM)



Release Date 2018-09-21
Release Note PDF
Firmware Files Vigor3900_v1.4.1
Checksum View from FTP
Support Language Multiple
Download from FTP


User’s Guide Version : 2.7
Quick Start Guide
Datasheet Download


CE Download