Draytek Vigor 3220 Quad-WAN security Firewall router


The Vigor3220 Quad-WAN security Firewall router is an enterprise level router suitable for any medium-sized business (SMB) that need to provide up to 100 VPN tunnels.

The Vigor3220 router supports 4 x Gigabit Ethernet WAN interfaces and the USB port 2 (USB2) for 3G/4G mobile dongles.

The Vigor3220 can connect to the Internet through any of these interfaces, or with a combination of interfaces for Load Balance and/or Failover functions. It supports business features including an object-oriented SPI (Stateful Packet Inspection) firewall, IPv6, 100 VPN tunnels, 50 SSL VPN tunnels, tag-based VLAN, multiple subnets, etc.

The dedicated DMZ port can be used to connect servers or computers that need to be exposed to the Internet without compromising internal LAN security.

The Centralised network management features provide a convenient console for the network administrator. These features include Central VPN Management, Central Switch Management, and Central AP Management.

The Vigor3220 series router can be rack mounted, using the supplied mounting brackets, into a standard 19” rack or cabinet.


  1. Ethernet WAN
    • IPv4
      • DHCP Client, Static IP, PPPoE, PPTP, L2TP, 802.1q Multi-VLAN Tagging
    • IPv6
      • Tunnel Mode: TSPC, AICCU, 6rd, Static 6in4
      • Dual Stack: PPP, DHCPv6 Client, Static IPv6
    • WAN Connection Failover
    • WAN Budget
    • Load Balance/Route Policy
  2. Ethernet LAN
    • IPv4/IPv6 DHCP Server
    • Static Routing/RIP
    • Multiple Subnets
    • Port/Tag-based VLAN
  3. USB
    • 3.5G/4G LTE(PPP, DHCP) as WAN5/ WAN6
    • Printer Server/File Sharing


  1. System Maintenance
    • HTTP/HTTPS with 2-level Management (Admin/User)
    • Logging via Syslog
    • SNMP Management MIB-II (v2/v3)
    • CLI (Command Line Interface, Telnet/SSH)
    • Administration Access Control
    • Web-based Diagnostic Functionality
    • Firmware Upgrade via TFTP/FTP/HTTP/TR-069
    • CWMP Support (TR-069/TR-104)
    • LAN Port Monitoring
  2. Network Management
    • Bandwidth Management by Session/Bandwidth
    • User Management by Time/Data Quota
    • LAN DNS and DNS Proxy/Cache
    • Dynamic DNS
    • IGMP Snooping/Proxy v2 and v3
    • QoS (DSCP/Class-based/4-level Priority)
    • Guarantee Bandwidth for VoIP
    • Support Smart Monitor (Up to 200 nodes)
    • Central AP Management
    • Central VPN Management
    • Switch Management


  1. Multi-NAT, DMZ Host, Port-redirection and Open Port
  2. Object-based Firewall, Object IPv6, Group IPv6
  3. MAC Address Filter
  4. SPI (Stateful Packet Inspection) (Flow Track)
  5. DoS/DDoS Prevention
  6. IP Address Anti-spoofing
  7. E-mail Alert and Logging via Syslog
  8. Bind IP to MAC Address
  9. Time Schedule Control
  10. Content Security (IM/P2P, URL, Keywords, Cookies, etc.)


  1. Up to 100 VPN Tunnels
  2. Protocol: PPTP, IPsec, L2TP, L2TP over IPsec
  3. Encryption: MPPE and Hardware-based AES/DES/3DES
  4. Authentication: MD5, SHA-1
  5. IKE Authentication: Pre-shared Key and Digital Signature (X.509)
  6. LAN-to-LAN, Teleworker-to-LAN
  7. DHCP over IPsec
  8. IPsec NAT-traversal (NAT-T)
  9. Dead Peer Detection (DPD)
  10. VPN Pass-through
  11. VPN Wizard
  12. mOTP
  13. Supports 50 SSL VPN Tunnels
  14. VPN Trunk: VPN Backup and Load Balance

Hardware Interface

  1. 4 x 10/100/1000Base-Tx WAN Port, RJ-45
  2. 1 x 10/100/1000Base-Tx LAN Switch, RJ-45
  3. 1 x 10/100/1000Base-Tx DMZ Port, RJ-45
  4. 2 x USB Host (USB1 is 2.0 and USB2 is 3.0)
  5. 1 x Console Port, RJ-45
  6. 1 x Factory Reset Button