{"product_id":"draytek-v2960-high-performance-ssl-vpn-router-firewall","title":"DrayTek v2960 High-Performance SSL VPN Router\/Firewall","description":"DrayTek v2960 High-Performance SSL VPN Router\/Firewall\u003cbr\u003e\u003cbr\u003e\n\nVPN\u003cbr\u003e\n\nAs a VPN endpoint\/concentrator, the Vigor 2960 will support up to 200 simultaneous teleworker or LAN-to-LAN VPNs with a VPN throughput of up to 500Mb\/s dependant on protocol, thanks to its hardware-based VPN co-processor. VPN security includes certificate, MOTP or token\/PSK based access and key-hash authentication to ensure maximum security.\u003cbr\u003e\u003cbr\u003e\n\nSSL VPN\u003cbr\u003e\n\nFor ease of remote access, the Vigor 2960 can provide up to 50 simultaneous SSL VPN tunnels or web-proxy links. SSL Web-Proxy makes remote access to your network possible from virtually anywhere without the inconvenience or compatibility issues of installing a VPN client. As SSL is a standard Internet protocol (used for web sites) SSL VPNs are also resilient to difficulties in creating tunnels through guest networks (web cafes, hotels etc.) where traditional IPSec\/PPTP tunnels can often have difficulties. SSL encryption is strong too, using 128bit DES\/3DES or AES. Using MoTP, your teleworker passwords are strong and realtime; a password is generated in real-time by your mobile phone (iphone, Android etc.) which can be used once only, and only at the time its generated. \u003cbr\u003e\u003cbr\u003e\n\nVigor 2960 Series Specification:-\u003cbr\u003e\n\n•Physical Interfaces: •LAN: 4-port Gigabit (10\/100\/1000 Base-T)\u003cbr\u003e\n•WAN: 2-port Gigabit (10\/100\/1000 Base-T) Ethernet\u003cbr\u003e\n•USB: 2 USB 2.0 Ports (for flash storage and 3G)\u003cbr\u003e\n Note : USB Function due in later firmware\u003cbr\u003e\n•WAN Protocols : PPPoE, PPTP, DHCP Ciet, Static IP\u003cbr\u003e\n•Load Balancing : Policy based or automatic\u003cbr\u003e\n•WAN Failover : Switch to other connection when primary WAN lost\u003cbr\u003e\u003cbr\u003e\n\n•VPN support: •Protocols : PPTP, IPSec, L2P, L2TP over IPSec\u003cbr\u003e\n•Up to 100 simultaneous tunnels (LAN-to-LAN or Teleworker-to-LAN)\u003cbr\u003e\n•Dial-in and Dial-out supported\u003cbr\u003e\n•VPN Trunking - allows alternative failover route or multiple\n tunnels to the same destination to increase capacity\/throughput\u003cbr\u003e\n•LDAP\/Active Directory : Teleworker VPNs can be auththenticated by a LDAP\/AD server\u003cbr\u003e\n•NAT-Traversal (NAT-T): VPN over routes without VPN Passthrough\u003cbr\u003e\n•PKI Certificates: Use X.509 Digital Signatures\u003cbr\u003e\n•IKE Authentication: Pre-shared key (PSK), Phase 1 agressive\/standard, Phase 2 selectable lifetimes\u003cbr\u003e\n•Encryption: •Hardware-based AES (128, 192, 256 bits)\u003cbr\u003e\n•Hardware-based DES\/3DES (56 \u0026amp; 168 bits)\u003cbr\u003e\n•Hardware-based MD5 \u0026amp; SHA-1\u003cbr\u003e\n•MPPE (40 or 128 bits)\u003cbr\u003e\u003cbr\u003e\n\n•Radius Client: Authentication for PPTP remote dial-in teleworkers\u003cbr\u003e\n•DHCP over IPSec\u003cbr\u003e\n•GRE over IPSec\u003cbr\u003e\n•Dead-Peer-Detection (DPD))\u003cbr\u003e\n•Smart-VPN Softare utility: For teleworkers\u003cbr\u003e\n•No extra licencing or additional VPN client costs.\u003cbr\u003e\n•Ineroperability : Compatible with other 3rd party VPN devices\u003cbr\u003e\u003cbr\u003e\n\n•Firewall: •Stateful Packet Inspection (SPI)\u003cbr\u003e\n•Content Security Management (CSM)\u003cbr\u003e\n•Multi-NAT: Set one-to-one mappings between your private and public IP addresses\u003cbr\u003e\n•Port Redirection \u0026amp; Open Ports\u003cbr\u003e\n•Policy-based IP Packet Filter. Fully configurable policies based on IP address, MAC address (source or destination), DiffServ attribute, direction, bandwidth, remote site\u003cbr\u003e\n•DoS\/DDoS Protection\u003cbr\u003e\n•IP Address Anti-spoofing\u003cbr\u003e\n•Object-Based Firewall\u003cbr\u003e\n•Notification: Email alerts and logs to syslog\u003cbr\u003e\n•Bind IP to MAC address\u003cbr\u003e\n•User-Controlled Rules: Interrogates LDAP server to permit access or enforce policies\u003cbr\u003e\u003cbr\u003e\n\n•System Management: \u003cbr\u003e\n•Web-Based User Interface: Integrated server for router management (via HTTP or HTTPS)\u003cbr\u003e\n•Telnet\/SSH : Command line control and configuration\u003cbr\u003e\n•Configuration Backup\/Restore\u003cbr\u003e\n•Built-in diagnostics, dial-out triger, routing table, ARP table, DHCP Table, NAT Sessions Table, data flow monitor, traffic graph, ping diagnostics, traceroute\u003cbr\u003e\n•Firmware Upgrade by HTTP, TFTP \u0026amp; FTP\u003cbr\u003e\n•Syslog Logging\u003cbr\u003e\n•SNMP Management: v1\/v2, MIB II\u003cbr\u003e\n•Vigor ACS-SI Centralised Management: TR-069 compatible for ACS platform\u003cbr\u003e\n•Compatible with Smart Monitor Traffic Analyser : Windows software for up to 100 users\u003cbr\u003e\u003cbr\u003e\n\n•Bandwidth Management: •Traffic Shaping: Dynamic bandwidth management with IP traffic shaping\u003cbr\u003e\n•Bandwidth Reservation: Connection or client based\u003cbr\u003e\n•Packet Size Control\u003cbr\u003e\n•DiffServ Codepoint Classifying\u003cbr\u003e\n•4 Priority Levels (Inbound\/Outbound)\u003cbr\u003e\n•Individual IP Bandwidth Session Limits per user\/group\u003cbr\u003e\n•Bandwidth Borrowing\u003cbr\u003e\n•User-defined class-based rules\u003cbr\u003e\u003cbr\u003e\n\n•Web Content Filtering \u0026amp; CSM: •URL Keyword Blocking: Blacklist or Whitelist\u003cbr\u003e\n•Content Type Blocking: Java applet, cookies, Active-X\u003cbr\u003e\n•Block P2P Applications (inc. Kazza, WinMX, Bittorrent)\u003cbr\u003e\n•Block Instant messaging\u003cbr\u003e\n•Block access of web sites by direct IP address (thus URLs only)\u003cbr\u003e\n•Block HTTP download of compressed, executable or multimedia files\u003cbr\u003e\n•Web Content Filter: GlobalView filtering of 64 web site categories (e.g. adult, gambling sites etc.). subscription required (free trial included)\u003cbr\u003e\n•Time Scheduling: Blocking rules can be activated based on time schedules\u003cbr\u003e\u003cbr\u003e\n\n•Routing Functions:\u003cbr\u003e •IPv4 \u0026amp; IPv6 Dual-Stack\u003cbr\u003e\n•DNS Cache\/Proxy\u003cbr\u003e\n•DHCP Client, Server \u0026amp; Relay\u003cbr\u003e\n•DHCP Options: 1,3,6,51,53,54,58,59,60,61,66,125\u003cbr\u003e\n•IGMP v1\/v2 \u0026amp; Proxy\/Snooping\u003cbr\u003e\n•uPnP: 500 Sessions\u003cbr\u003e\n•NAT: 80,000 Sessions\u003cbr\u003e\n•NTP Client with DST Adjustments\u003cbr\u003e\n•Static routing\u003cbr\u003e\n•Policy-based routing\u003cbr\u003e\n•Dynamic DNS : Updates DDNS servers with public IP address\u003cbr\u003e\n•Port-Based VLAN\u003cbr\u003e\n•Tag-Based VLAN: 802.1q\u003cbr\u003e\n•Client\/Call Scheduling : Real-time clock, with NTP updating schedules access or connectivity\u003cbr\u003e\n•Wake-on-LAN : Passed from WAN to preset LAN device\u003cbr\u003e\u003cbr\u003e\n\n•Operating Requirements: •Rack Mountable (Mount brackets included)\u003cbr\u003e\n•Temperature Operating : 0°C ~ 45°C\u003cbr\u003e\n•Storage : -10°C ~ 70°C\u003cbr\u003e\n•Humidity 10% ~ 90% (non-condensing)\u003cbr\u003e\n•Power Consumption: 19W Max\u003cbr\u003e\n•Dimensions: L273 * W166 * H44 (mm) (1U Height))\u003cbr\u003e\n•Operating Power: 220-240VAC (internal PSU)\u003cbr\u003e\n•Warranty : 2 Years Manufacturer's RTB included\n\n\n\n\n","brand":"DrayTek","offers":[{"title":"Default Title","offer_id":57413389484364,"sku":"DRA-V2960","price":402.92,"currency_code":"GBP","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/1053\/6891\/2204\/files\/DrayTek-v2960.jpg?v=1777543203","url":"https:\/\/www.stoneaudio.co.uk\/products\/draytek-v2960-high-performance-ssl-vpn-router-firewall","provider":"Stone Audio","version":"1.0","type":"link"}