Dual WAN SSL VPN Router
Vigor2930 Series
| Vigor 2930 Series Router Firewall
|
|
![]() |
|
|
|
|
|
Vigor2930 Series |
Vigor2930 |
Vigor2930n |
Vigor2930vn |
|
Ethernet WAN (main WAN) |
|
|
|
|
Ethernet WAN (2nd WAN) |
|
|
|
|
802.11n WLAN |
|
|
|
|
VoIP (2xFXS, 1xPSTN) |
|
|
|
| Overview (Vigor2930 Series) |
The Vigor 2930 is a high-performance dual-WAN firewall. The two dedicated ethernet WAN ports can provide load balancing, WAN failover or bandwidth aggregation (increasing total bandwidth onto the Internet). Versions with SIP-Compliant VoIP (Voice-over-IP) and ISDN support are also available. High Speed total WAN througput of up to 70Mb/s is available, and IPSec VPN throughput of up to 40Mb/s. Extensive QoS support and comprehensive Web Content filtering features help you make the most efficient use of your bandwidth. The Vigor 2930 is in an all-new DrayTek housing design with all LEDs and sockets provided conveniently on the front. This makes desk usage, wall mouting or rack-mounting (optional bracket required) all equally covenient. |
| Last Updated on Wednesday, 10 August 2011 20:38 |
| Wirelass LAN (Vigor2930 Series) |
Wireless LAN ('n' models only)The Vigor2930 Series ('n' models) features the latest 802.11n wireless LAN specification and has been certified by the WiFi alliance for cross compatibility and WiFi compliance (including WPA/WPA2 and WMM). 802.11n provides a total wireless bandwidth of up to 300Mb/s using new methods such as packet aggregation and channel bonding. Throughput depends on your own environment (factors such as obstructions, number of hosts and distance all make a significant difference), but actual transfer speeds of 100Mb/s are achievable (based on our real world tests). In addition, 802.11n provides greater coverage and resilience to interference compared to previous wireless standards thanks to the MIMO technology and the Vigor's triple-antennae diversity arrangement. This offset arrangement of aerials provides offset paths between hosts so that interference can be overcome. Wireless Security is comprehensive too; the Vigor 2930 Series provides several independent levels of security including encryption (up to WPA2), authentication (802.11x) and methods such as MAC address locking and DHCP fixing to restrict access to authorised users only. The Web interface lets you see how many and which clients are currently connected as well as their current bandwidth usage. An 'instant' block lets you disconnect a wireless user temporarily in case of query. The Wireless VLAN facility allows you to isolate wireless clients from each other or from the 'wired' LAN. Your laptop PC's built-in wireless may not support 802.11n wireless, in which case you will need to add a new wireless LAN interface such as the DrayTek N61 USB adaptor. Click on 'accessories' for details. For specialist coverage applications, optional aerials can be used with the Vigor 2930 to potentially increase the range of wireless coverage (depending on enviroment) or provide directional coverage in order that your wireless transmission is focussed and concentrated into one direction only, for example into a room or across open space.
Important Note : Wireless performance (speed and range) always depends on your specific environment and will vary considerably. Factors affecting performance include wireless traffic, other networks nearby, site construction, walls, ceilings and other electronic equipment nearby. Speeds quoted are the maximum wireless capacity, including RX/TX capacity, protocol overheads and all clients/hosts connected. |
| Last Updated on Wednesday, 10 August 2011 20:41 |
VoIP
| VoIP (Vigor2930 Series) |
Voice-over-IP Features ('V' model only)The Voice-over-IP (VoIP) facilities on the Vigor 2930 'V' models within the series are extensive. Standard SIP compliance, with up to 12 simultaneous registrars (e.g. DrayTEL etc.) is supported, plus multiple codec support and many supplemental services enabling you to make thorough use of your Internet connection for Voice calls. Short codes (speed dials) and VoIP LCR ('Least Cost Routing') are also supported./p>
Vigor 2930VS Schematic From left : Two analogue VoIP ports, two ISDN Sockets (One S0, oneswitchable S0/NT), dual Ethernet WAN ports and four LAN Ethernet ports. |
| Last Updated on Wednesday, 10 August 2011 20:42 |
| SSL VPN (Vigor2930 Series) |
SSL VPNsVPNs (Virtual Private Networks) enable you to link two remote computers or networks securely using the public Internet. An encrypted tunnel is created to carry your private data between the two sites. Tunnels making use of PPTP, L2TP, AES and IPSec protocols have been available on Vigor routers for many years and provide a simple to set up solution for your site-to-site or teleworker VPNs. SSL VPNs provide a new method for teleworker to central site VPN, providing great convenience, low TCO and simplicity where other methods may not be possible. The benefits of SSL VPNsOne potential drawback of using the above methods for a Teleworker-to-central site VPN is that they need compatiable protocol stacks at each end (e.g. an IPSec client or hardware) and most importantly those protocols need to be freely passed by your local host network. This isn't normally a problem where you own the computers and the network in use and you can install any client, software or hardware you choose, as well as allowing any traffic types you like. Where it can become a problem is where you are using someone else's computer or network where either you cannot use the O/S VPN client, or the host network blocks VPN protocols or makes them unreliable. This is most commonly a problem when using WiFi hotspots or other public Internet access methods (hotels, conference centres etc.). You may already have heard of SSL previously, and you have almost certainly used it. SSL (Secure Sockets Layer) is the protocol used by all web browsers for accessing 'secure' web sites. You will have used secure web sites whenver you have used your credit card online or accessed your banking web sites, for example. SSL is supported by all web browsers, and as it is so commonly used, all hotspots and other public Internet will always allow SSL to pass properly. By using the SSL protocol for your telework VPN tunnel you therefore have some important benefits:
Another advantage of web based SSL VPN is that your host Vigor router presents the user with his/her login page to the network within their browser and then can provide access only to the web based applications or local servers which you allow as opposed to a regular VPN which connects the user to the network directly for access to any resource which is accessible locally. No TCP/UDP ports have to be opened on your host router; if the user cannot login to the VPN, they won't get access. As mentioned previously, an SSL VPN uses your standard web browser; this means that for your web based applications running at your office (webmail, Intranet, Thin Clients etc.) SSL VPNs work really well for this access method, which is called 'SSL Web Proxy' mode. A very common application for SSL VPN is remote desktop. By using the Windows 'Remote Desktop Web Connection', your office desktop will be accessible from your web browser whereever you are and whoever's computer you're using. In addition, by using Vigor web proxy, you can browse external web sites via the tunnel, thus bypassing any local web site blocking policy (content filtering or local polcies). If you are familiar with 'port redirection' or 'open ports setup' on Vigor routers, SSL Proxy to your internal web services is very similar in concept to this except that the data passes through a secured tunnel, hence increasing security and privacy.
MOTP (Mobile One-time Passwords)As an alternative to a fixed password for remote teleworkers, you can make use of DrayTek's Mobile One-Time Password (MOTP) system to add Two-layer authentication. A One-time password is generated dynamically each time you want to connect, works once only and expires immediately. For DrayTek MOTP, the authentication device is your mobile phone; MOTP applets are available for Symbian mobile phones (e.g. Nokia), most phones supporting Java and the Apple iPhone™.
| ||||||||||||||||||||||
| Last Updated on Wednesday, 10 August 2011 20:44 |
| VPN Trunking (Vigor2930 Series) |
VPN TrunkingVPN Trunking is the facility to create more than one VPN tunnel to the same remote location in order to provide either increased bandwidth between the two sites (load balancing) or resilience (failover) in the event that one tunnel/connection is interrupted. The Vigor 2930 supports both Failover and Load Balancing modes for VPN Trunks. The Vigor 2930 already supports load balancing to the Internet using its dual-WAN ports. What VPN trunking does is enables a tunnel to be created down each WAN connection to the same remote location creating a single virtual tunnel, as far as the traffic and LAN devices/clients are concerned.
In the diagram above, you can see a single virtual tunnel as far as the LAN at each end is concerned. Within the router, two WAN connections are being used with each router, across which the VPN tunnel can be spread, increasing total capacity and/or redundancy (for failover). |
| Last Updated on Wednesday, 10 August 2011 20:46 |
| Specification (Vigor2930 Series) |
Vigor2930 Series Specification
|
| Last Updated on Wednesday, 10 August 2011 20:47 |
| Screenshots (Vigor2930 Series) |
|
| Last Updated on Wednesday, 10 August 2011 20:48 |
| Accessories (Vigor2930 Series) |
Rack Mounting Kit
The RM1 Rackmount Bracket enabled you to fit any Vigor 2920 series router into a standard 19" rack or cabinet. The bracket takes up one rack slot (1U). The front mounted sockets remain fully accessible. For wireless models, we then recommend extension aerials (or aerial extensions) as aerials will not perform well if sited inside your metal cabinet. Directional and Higher-Gain Aerials
Omnidirectional and Unidirectional aerials are available for increased coverage or other specialist requirements. For full specifications, click here. Wireless LAN Adaptors |
| Last Updated on Wednesday, 10 August 2011 20:49 |
