DrayTek Vigor2962
Business edge router and firewall; multi-WAN, VPN, port redirection, inter-LAN isolation
- Rebuilt and firmware-upgraded
- Custom API automation
- Login throttling reverse-engineered

We have rebuilt one from a factory reset, including a firmware upgrade and the inbound service mappings, and wrote our own API automation so that operations previously done by clicking through the web console became programmable. Along the way we established several behaviours the manual does not document: the SSH management interface enforces a cooldown after each successful login, a second login inside that window always fails, and every failure resets the timer, so retrying only extends the lockout. The web console login path has no such limit. Port redirection and the Open Ports table are separate, and changing one does not affect the other. Inter-LAN filtering is symmetric, so one-directional blocking is not possible, which directly constrains how multi-site isolation can be designed.
- Available interfaces
- Web console and CLI
- CLI login throttling
- A cooldown follows each successful login; a second login inside the window always fails
- The trap
- Every failure resets the timer, so retrying only extends the lockout, regardless of whether the password is correct
- Path without throttling
- The web console login path has no such limit and can be driven repeatedly
- Two separate tables
- Port redirection and the Open Ports table are independent; changing one does not affect the other
- Viewing from the CLI
- The redirection table requires an index to display; without one it returns nothing
- Filter behaviour
- Inter-LAN allow and block rules are symmetric
- Architectural consequence
- One-directional blocking is impossible, so isolation has to be handled at another layer
- API automation
- Written in house, turning operations that previously required clicking through the console into programmable calls
- Rebuild
- Full rebuild from a factory reset, including firmware upgrade and inbound service mappings
- DrayTekDrayTek Vigor2135Gigabit Ethernet WAN、3G/4G 備援、50k NAT連線數、同時最多2條VPN
- DrayTekDrayTek Vigor2136 系列2.5G Ethernet WAN、50k NAT連線數、同時最多16條VPN
- DrayTekDrayTek Vigor2927 系列2 Gigabit Ethernet WAN、60k NAT連線數、同時最多50條VPN
- DrayTekDrayTek Vigor2928 系列10GbE SFP+ WAN、1GbE WAN、60k NAT連線數、同時最多50條VPN
- DrayTekDrayTek Vigor3912 系列6 Ethernet WAN、2 10G SFP+ WAN、1000k NAT連線數、同時最多500條VPN、支援8GB DDR4 記憶體
- NusoftNusoft NGFW-710 next-generation firewall1U rackmount, 6 (Giga 埠) network interfaces, 1 TB disk
- NusoftNusoft NGFW-910 next-generation firewall1U rackmount, 6 (Giga 埠) network interfaces, 1 TB disk
- NusoftNusoft NGFW-1700A next-generation firewall1U rackmount, 6 (Giga 埠) + 4 SFP+ network interfaces, 1 TB disk
