DrayTek is introducing a new generation of business routers in the form of the Vigor 2867BE and Vigor 2928BE, bringing Wi-Fi 7 and multi-gigabit networking into a part of the market where DrayTek has built an enormous installed base.
For UK businesses, IT providers and network installers, however, the important question isn’t simply whether Wi-Fi 7 is faster than Wi-Fi 6. It is: when does replacing an existing DrayTek router actually make sense? That is a much more interesting question.
A business might still be running a Vigor 2860 installed when FTTC was considered fast broadband. Another might have a Vigor 2862 that continues to work perfectly well but is approaching the later stages of its support lifecycle. Others will have moved to the Vigor 2865ax or Vigor 2927ax and now find that Gigabit Ethernet has become the limiting factor as 2Gbps, 5Gbps and even faster FTTP services become available.
The Vigor 2867BE and 2928BE therefore represent more than another incremental router update. They mark DrayTek’s move from the Gigabit and Wi-Fi 6 generation towards 10 Gigabit networking, Wi-Fi 7, DrayOS 5, stronger identity-based security and significantly more capable local network infrastructure. For some businesses, upgrading immediately would be unnecessary. For others, particularly organisations replacing older DrayTek hardware or deploying multi-gigabit FTTP, the difference is substantial.
Vigor 2867BE and Vigor 2928BE at a glance
The easiest way to understand the two routers is to look at the role each occupies.
The Vigor 2867BE is the natural progression of DrayTek’s long-running 286x family. It combines an integrated VDSL2/ADSL modem with Ethernet WAN connectivity, making it particularly useful for businesses that still require DSL support while wanting a migration path towards FTTP and multi-gigabit Ethernet.
The Vigor 2928BE removes the DSL emphasis and concentrates on high-performance Ethernet and fibre WAN connectivity. That makes it particularly interesting for modern FTTP installations, offices with multiple internet circuits and businesses deploying faster internal networks. Both introduce 10GbE-class connectivity and Wi-Fi 7.
| Feature | Vigor 2867BE | Vigor 2928BE |
|---|---|---|
| Primary role | DSL + Ethernet multi-WAN business router | High-performance Ethernet/fibre dual-WAN router |
| Integrated DSL | Yes | No |
| VDSL2 35b | Yes, up to 300Mbps theoretical sync | No |
| 10GbE RJ45 | Yes | Yes |
| 10G SFP+ | Yes | Yes |
| 2.5GbE LAN | Yes | Yes |
| Wi-Fi | Wi-Fi 7 / 802.11be | Wi-Fi 7 / 802.11be |
| 2.4GHz maximum link rate | Up to 1,376Mbps | Up to 1,376Mbps |
| 5GHz maximum link rate | Up to 5,764Mbps | Up to 5,764Mbps |
| Wi-Fi architecture | 4×4 MU-MIMO | 4×4 MU-MIMO |
| VPN tunnels | Up to 50 | Up to 50 |
| Published IPsec throughput | Up to 540Mbps | Up to 540Mbps |
| Recommended network size | Around 50 hosts | Around 50 hosts |
| NAT sessions | Up to 100,000 | Up to 60,000 |
| VLANs | Up to 8 | Up to 8 |
| VigorAP management | Yes | Yes |
| VigorSwitch management | Yes | Yes |
| DrayOS 5 | Yes | Yes |
| VigorShield security services | Yes | Yes |
These figures immediately reveal something important. The biggest improvement isn’t necessarily the WAN routing performance. It is the network architecture surrounding the router. 10GbE, 10G SFP+, 2.5GbE and Wi-Fi 7 fundamentally change what can happen on the LAN.
A quick spec caution. DrayTek’s current global specifications describe the 2867BE and 2928BE as dual-band 2.4/5GHz Wi-Fi 7, not the tri-band 2.4/5/6GHz arrangement seen on some Wi-Fi 7 hardware. Check the final UK launch specification before assuming every high-end tri-band Wi-Fi 7 feature is present simply because “Wi-Fi 7” appears on the box.
Why DrayTek needed to move beyond Gigabit Ethernet
Gigabit Ethernet enjoyed an extraordinarily long useful life. For years it was almost impossible for an SME broadband connection to challenge it. That has changed.
UK FTTP services are increasingly available at speeds above 1Gbps, while business leased lines and specialist fibre services can go considerably further. At the same time, the LAN itself is getting faster. Modern Wi-Fi access points commonly use 2.5GbE uplinks. NAS appliances increasingly offer 2.5GbE, 5GbE or 10GbE. Workstations handling video, CAD, large datasets and backups can easily exploit multi-gigabit networking.
A Gigabit router sitting in the middle of this environment becomes an artificial bottleneck. That is one of the biggest differences between the new generation and routers such as the Vigor 2865ax and 2927ax.
Vigor 2927ax versus Vigor 2928BE
The outgoing Vigor 2927ax illustrates the change particularly well. It remains a capable SME router, providing two Gigabit Ethernet WAN interfaces, up to approximately 950Mbps hardware-accelerated throughput per WAN and around 1.8Gbps combined NAT throughput. Its AX3000 Wi-Fi 6 implementation offers up to 574Mbps on 2.4GHz and up to 2,400Mbps on 5GHz, along with OFDMA, MU-MIMO, beamforming, 1024-QAM and up to 160MHz channels.
For a business with a 500Mbps or 900Mbps FTTP circuit, none of that suddenly becomes obsolete because a newer router exists. But imagine upgrading that business to a 2Gbps, 5Gbps or eventually 10Gbps internet service. The Gigabit WAN interfaces immediately become the constraint.
The Vigor 2928BE changes the physical architecture. It provides 10GbE and SFP+ connectivity alongside 2.5GbE and Gigabit Ethernet. That means the router is no longer designed around the assumption that approximately 1Gbps is the practical ceiling of an SME internet connection. That is arguably the most important generational change.
Vigor 2865ax versus Vigor 2867BE
A similar transition exists between the Vigor 2865ax and Vigor 2867BE. The 2865ax combines VDSL2/ADSL, a Gigabit Ethernet WAN, five Gigabit LAN ports, AX3000 Wi-Fi 6, up to 950Mbps Ethernet WAN NAT throughput, 32 VPN tunnels, hardware-accelerated IPsec of up to 800Mbps on supported configurations, eight LAN subnets/VLANs and DrayTek AP and switch management. For many existing installations that remains perfectly adequate.
The Vigor 2867BE retains the crucial DSL capability but moves the platform into a different networking generation. Alongside VDSL2 35b and ADSL2+, it provides access to 10GbE RJ45, 10G SFP+, 2.5GbE, Wi-Fi 7, up to 100,000 sessions, 50 VPN tunnels, DrayOS 5, IAM, VigorShield threat intelligence, Port Knocking and improved local network management.
The business that still needs DSL but is preparing for FTTP
Not every UK site has FTTP, and not every organisation can simply design its network around what Openreach might install next year. Some businesses still depend upon VDSL. Others operate multiple sites where one location has FTTP while another remains on FTTC.
That is exactly where the 2867 concept continues to make sense. A business can deploy the router today using its integrated VDSL modem, but build the internal network around faster Ethernet infrastructure. When FTTP eventually arrives, the WAN connection can move to Ethernet without replacing the entire router again. That is considerably more sensible than designing a new LAN around the limitations of the current broadband connection.
What does Wi-Fi 7 actually add?
Wi-Fi 7 is based around IEEE 802.11be, sometimes referred to as Extremely High Throughput, or EHT. The headline speeds attract most of the attention, but businesses should be more interested in efficiency, latency and spectrum utilisation. Several technologies contribute.
Multi-Link Operation
One of Wi-Fi 7’s most important technologies is Multi-Link Operation, normally abbreviated to MLO. Traditional Wi-Fi clients generally establish their active connection through one wireless link. Wi-Fi 7 introduces the ability for compatible equipment to make more intelligent use of multiple wireless links, potentially improving throughput, latency, resilience, congestion handling and traffic distribution.
Think of it less as simply widening a road and more as giving traffic access to multiple routes. For applications such as video conferencing, cloud desktops and large file transfers, reducing contention and latency can matter just as much as increasing headline bandwidth.
There is an important qualification with these particular models. DrayTek’s current global specifications list the Vigor 2867BE and 2928BE as using 2.4GHz and 5GHz Wi-Fi, rather than the tri-band 2.4/5/6GHz arrangement seen on some Wi-Fi 7 products. Businesses should therefore examine the final UK specification carefully rather than assuming every feature associated with high-end tri-band Wi-Fi 7 hardware is present.
Multiple Resource Units
Wi-Fi 6 introduced OFDMA, which allows a wireless channel to be divided into smaller Resource Units. Rather than giving an entire channel to one client at a time, an access point can allocate pieces of the channel more efficiently. Wi-Fi 7 develops this further with Multiple Resource Units, or MRU, where a compatible client can be allocated multiple resource units rather than being restricted to one.
For busy offices this can improve spectrum utilisation. That matters because modern Wi-Fi problems increasingly aren’t caused by one laptop requiring enormous bandwidth. They are caused by lots of devices wanting relatively small pieces of bandwidth simultaneously: phones, laptops, Teams rooms, printers, VoIP handsets, cameras, tablets, IoT devices, digital signage, building-management equipment, wireless scanners and guest devices. Improving how efficiently those devices share spectrum can have more practical value than another impressive laboratory speed test.
Zero-Wait DFS
The new routers also incorporate Zero-Wait DFS. DFS exists because portions of the 5GHz Wi-Fi spectrum are shared with radar systems, and wireless equipment operating on DFS channels must detect radar and vacate affected spectrum when required. Traditional implementations can introduce delays while the access point performs Channel Availability Checks before using another DFS channel.
DrayTek uses a dedicated radio function to monitor potential channels so that an alternative can already be cleared for use. If radar is detected, the router can move users to a prepared channel more quickly. In a domestic environment that might be a minor convenience. In an office carrying voice, video meetings and cloud applications over Wi-Fi, reducing interruptions is much more valuable.
The difference between link rate and actual internet speed
Wi-Fi specifications frequently create confusion because wireless link rates are not the same thing as internet throughput. The Vigor 2867BE and 2928BE have published maximum wireless link rates of approximately 1,376Mbps on 2.4GHz and 5,764Mbps on 5GHz. Those numbers should not be interpreted as a promise that a laptop will download from the internet at 5.7Gbps.
Wireless throughput depends upon client capabilities, channel width, interference, signal strength, distance, walls and building materials, neighbouring networks, protocol overhead, the number of connected devices, WAN speed and Ethernet infrastructure.
This is also why 10GbE and 2.5GbE matter. There is little point installing increasingly fast wireless infrastructure if every connection behind it is forced through Gigabit Ethernet.
The forgotten upgrade: the LAN
Businesses frequently upgrade broadband while ignoring the internal network. Imagine a company buys a 2Gbps FTTP service. Its router has a Gigabit WAN port. Its switches are Gigabit. Its wireless access points have Gigabit uplinks. Its NAS is connected at Gigabit. The business technically owns a 2Gbps internet service, but much of the network can never individually use more than approximately half of it.
The new DrayTek architecture allows businesses to start removing these bottlenecks. A sensible modern network might therefore look like: multi-gigabit FTTP into a Vigor 2928BE, a 10GbE backbone, a multi-gigabit PoE switch and Wi-Fi 7/6E/6 access points, with NAS appliances, servers and high-performance workstations connected at 2.5GbE or 10GbE where appropriate. That is a much more significant upgrade than merely replacing Wi-Fi 6 with Wi-Fi 7.
Vigor 2867BE connectivity
The 2867BE is particularly flexible. DrayTek lists:
- integrated VDSL2/ADSL2+
- VDSL2 Profile 35b support
- fixed Gigabit Ethernet WAN
- switchable 10GbE WAN/LAN
- 10G SFP+ connectivity
- 2.5GbE LAN
- three Gigabit Ethernet LAN ports
- two USB 2.0 interfaces
There are some interface limitations concerning which high-speed ports can operate simultaneously, so anyone designing a complex multi-WAN installation should check the port configuration against the exact deployment. Nevertheless, compared with the Gigabit-centric architecture of earlier 286x routers, this is a substantial leap.
Vigor 2928BE connectivity
The 2928BE dispenses with DSL and concentrates on high-speed Ethernet and fibre. Its interfaces include:
- fixed Gigabit Ethernet WAN
- 10G SFP+
- switchable 10GbE RJ45 WAN/LAN
- additional 10G SFP+ connectivity
- 2.5GbE LAN
- three Gigabit Ethernet LAN interfaces
- two USB interfaces
This makes it the more natural choice where DSL simply isn’t required: FTTP-connected offices, leased-line installations, dual-ISP businesses, high-bandwidth creative studios, engineering companies, multi-site organisations, businesses using large local NAS systems and offices deploying multi-gigabit Wi-Fi.
Multi-WAN isn’t just about speed
DrayTek has always been strong in multi-WAN networking. Combining connections can increase aggregate capacity, but resilience is often the more important benefit. Consider a business with a primary FTTP connection, a secondary broadband service and potentially cellular connectivity through supported external equipment. The router can detect connectivity failures and move traffic accordingly.
Policy routing can also determine which connection specific traffic uses. VoIP can use the lowest-latency WAN, guest traffic can use a secondary connection, business-critical cloud traffic can use the primary circuit, backups can be pushed through another WAN and VPN traffic can follow defined routing policies. That makes multi-WAN a business continuity feature rather than simply a bandwidth feature.
VPN remains important
The fashionable assumption is that everything has moved to the cloud and traditional VPNs no longer matter. Reality is messier. Businesses still need secure connections for branch offices, remote engineers, CCTV, industrial equipment, building management systems, NAS access, local servers, maintenance contractors, remote desktop systems and machine networks.
Both new router families support up to 50 VPN tunnels and protocols including IPsec, WireGuard and OpenVPN. DrayTek publishes IPsec throughput of up to approximately 540Mbps for the new models in its current global specifications. This is one area where buyers should compare requirements carefully rather than assuming every figure increases simply because the router generation is newer. A company moving large quantities of encrypted traffic between multi-gigabit sites may need a different class of security appliance, but 500Mbps-class encrypted site-to-site connectivity is still considerably more than many SME branch networks require.
EasyVPN
DrayTek is also trying to simplify one of the more tedious elements of business networking: provisioning remote users. EasyVPN is intended to reduce the manual work involved in creating VPN configurations. Instead of expecting users or administrators to manually generate keys, distribute certificates and configure protocols, profiles can be prepared and imported more easily. That matters when supporting remote workers who aren’t networking engineers. Security systems are only useful when people can actually deploy and maintain them.
DrayOS 5 changes the security conversation
The new hardware also arrives alongside DrayOS 5, and this is arguably as important as Wi-Fi 7. Traditional SME router security largely revolved around a simple model: the LAN is trusted and the internet is untrusted. That model is increasingly inadequate. Businesses now have employees, contractors, guest devices, BYOD, IoT equipment, CCTV, cloud applications, remote workers, smart-building systems, printers, VoIP and externally managed equipment on their networks. Simply being connected to the LAN shouldn’t automatically mean that a device can access everything.
Identity and Access Management
DrayTek is introducing stronger Identity and Access Management capabilities, allowing network policies to be built around users, devices and roles. A finance employee might require access to accounting systems. A guest should only need internet access. A CCTV camera should communicate with its recorder and perhaps selected cloud services. An IoT sensor might only require DNS, NTP and access to one remote platform. A contractor may require temporary access to one particular server. Combined with VLAN segmentation and firewall rules, IAM can help businesses move away from large flat trusted networks.
Zero Trust without the marketing nonsense
“Zero Trust” has become one of those phrases capable of meaning almost anything. The useful principle is actually very simple: don’t grant access merely because something happens to be inside your network. Identify it, authenticate it, decide what it needs, and give it that access and nothing more.
For an SME this doesn’t necessarily require an enormous enterprise security platform. Creating separate VLANs for staff, guests, CCTV and IoT equipment already provides a much better foundation, and the new DrayTek platform builds further controls around that principle.
URL and IP reputation
VigorShield adds cloud-assisted threat intelligence including URL and IP reputation services. Static firewall rules remain important, but they have an obvious limitation: internet threats constantly change, and an IP address that was harmless yesterday might host malicious infrastructure tomorrow. Reputation services allow the router to use continuously updated information when evaluating destinations and remote hosts, helping to identify or block communication associated with botnets, command-and-control infrastructure, malicious servers, suspicious proxies, phishing infrastructure and known hostile IP addresses. It shouldn’t replace endpoint security, proper patching or sensible firewall design. It adds another layer.
Port Knocking
One of the more interesting security additions is Port Knocking. Publicly exposed services are routinely scanned by automated systems, and even an obscure TCP port will eventually be found. Changing port 443 to 10443 isn’t meaningful security. Port Knocking takes a different approach: the required service remains closed until the remote user sends a predefined sequence, and only then does the router temporarily expose the service to that authorised connection. This can reduce the visibility of management interfaces, VPN services, remote administration ports and specialist services. It isn’t a substitute for strong authentication, but it reduces unnecessary exposure to automated scanning.
VLANs matter more than Wi-Fi speed for IoT
For IoT deployments, one of the most useful features of business-class routers remains network segmentation. Putting every device onto the same LAN is convenient. It is also poor security design. Consider a small manufacturing company with office PCs, VoIP phones, CCTV cameras, environmental sensors, printers, machinery, guest Wi-Fi and building controls. There is little reason those devices should all communicate freely. Instead:
- VLAN 10 – Corporate
- VLAN 20 – Voice
- VLAN 30 – CCTV
- VLAN 40 – IoT
- VLAN 50 – Guest Wi-Fi
Firewall policies can then determine exactly what communication is permitted between them. This is one reason business routers such as the Vigor range remain relevant even when an ISP provides a perfectly functional free router. The difference isn’t merely Wi-Fi coverage. It is network control.
Central management of DrayTek access points
Both router families can operate as a Virtual Controller for compatible VigorAP wireless access points. DrayTek specifies support for mesh networks with the router acting as Root AP and up to seven node APs. For larger deployments, AP Management mode can manage up to 20 access points. That means a small business doesn’t necessarily need a separate wireless controller. SSIDs, access points and wireless configuration can be managed centrally through the router.
Switch management
The router can also manage supported VigorSwitch hardware, with DrayTek specifying management of up to ten switches. Administrators can monitor switch status, firmware, uptime, connected devices, VLAN configuration, QoS and PoE-related settings on compatible hardware. Configuration backup, reboot and other maintenance operations can also be handled centrally. For a small organisation without a dedicated network management platform, this can significantly simplify administration.
When mesh makes sense
Mesh Wi-Fi is convenient, but it is worth understanding what it actually does. A traditional access point uses Ethernet for its backhaul connection. A wireless mesh node can communicate back to another access point wirelessly, which makes mesh useful where running Ethernet is difficult.
However, if Ethernet can reasonably be installed, wired backhaul remains preferable for business networks. It provides predictable capacity and avoids consuming wireless airtime carrying traffic between access points. Mesh is therefore excellent for listed buildings, temporary offices, difficult extensions, warehouses where cabling is impractical and rapid deployment. But it shouldn’t automatically replace proper Ethernet infrastructure.
Which older Vigor routers should you replace?
This is where sensible engineering should beat marketing. The right answer depends far more on support lifecycle, WAN capacity and security requirements than on the age of the model number.
Should a Vigor 2860 be replaced?
Yes. At this stage a Vigor 2860 belongs to a previous networking generation. DrayTek lists the 2860 series as discontinued from December 2017 with firmware maintenance ending in December 2022. That is a much stronger reason to replace it than Wi-Fi performance. Network infrastructure sitting at the internet boundary should receive security maintenance. If you’re still running a 2860 or 2860ac in a business environment, the Vigor 2867BE represents an enormous technological jump: modern security, multi-gigabit Ethernet, Wi-Fi 7, modern VPN options and much greater network-management capability.
What about the Vigor 2862?
This is more nuanced. The Vigor 2862 series reached end of sale in May 2022, but DrayTek currently lists firmware maintenance through May 2028. So a properly maintained 2862 isn’t suddenly unsafe simply because the 2867 exists. There are still good reasons to consider upgrading, particularly faster FTTP, multi-gigabit LAN requirements, Wi-Fi 7, modern security architecture, greater VPN requirements, more devices, 10GbE, 2.5GbE and newer management features. For a 70Mbps FTTC-connected office with ten users, upgrading purely for speed could achieve almost nothing. For the same company moving to 2Gbps FTTP and installing a 2.5/10GbE LAN, it is a completely different calculation.
What about the Vigor 2925?
The 2925 generation is already firmly in upgrade territory. DrayTek lists Vigor 2925 hardware as discontinued with firmware maintenance expired. Businesses still operating these routers should therefore consider replacement based primarily on lifecycle and security rather than simply performance. The 2928BE would represent a major upgrade for a site that still requires the familiar DrayTek dual-WAN architecture.
What about the Vigor 2926?
The Vigor 2926 reached end of sale in April 2022, and DrayTek currently lists firmware maintenance through 1 April 2027. That makes 2026 a sensible point for organisations to begin planning replacements. There is no need to panic and rip working equipment from racks tomorrow morning. But if a business normally operates routers for five or more years, installing another old-generation replacement now would make little sense. The 2928 generation provides a much longer technological runway.
Should you replace a Vigor 2865ax?
Not necessarily. The 2865ax already provides Wi-Fi 6, a Gigabit Ethernet WAN, VDSL, VLANs, VPN, approximately Gigabit-class routing, central AP management and strong business networking functionality. If your internet connection is 500Mbps and the router comfortably handles your users, replacing it simply because Wi-Fi 7 exists is difficult to justify.
The 2867BE becomes compelling when you’re moving towards multi-gigabit FTTP, 2.5GbE or 10GbE switching, high-speed NAS access, Wi-Fi 7 clients, more sophisticated network segmentation, DrayOS 5 security capabilities, greater device density or newer management requirements. In other words, don’t replace the 2865ax because the model number is older. Replace it when the network has outgrown its architecture.
Should you replace a Vigor 2927ax?
Exactly the same principle applies. The 2927ax remains a strong Gigabit-class business router. Its limitation becomes apparent when internet and LAN speeds move significantly beyond Gigabit Ethernet. For a company with dual 500Mbps connections, the 2927ax may continue to be perfectly suitable. For a company installing 2Gbps or 5Gbps FTTP, a 10GbE-capable router starts making considerably more sense.
Practical DrayTek upgrade guide
| Existing router | Position in 2026 | Suggested approach |
|---|---|---|
| Vigor 2820 / 2830 | Very old, support expired | Replace |
| Vigor 2850 | Very old, support expired | Replace |
| Vigor 2860 / 2860ac | Firmware maintenance expired | Replace |
| Vigor 2862 / 2862ac | EoS, maintenance currently to May 2028 | Plan replacement according to requirements |
| Vigor 2865ax | Modern Wi-Fi 6/Gigabit platform | Keep unless multi-gigabit or new features justify upgrade |
| Vigor 2920 / 2925 | Old generation, maintenance expired | Replace |
| Vigor 2926 / 2926ac | Maintenance currently to April 2027 | Replacement planning advisable |
| Vigor 2927ax | Modern Gigabit/Wi-Fi 6 platform | Keep unless network requirements have moved beyond Gigabit |
| New DSL/multi-WAN installation | Current requirement | Consider Vigor 2867BE |
| New FTTP/dual-WAN installation | Current requirement | Consider Vigor 2928BE |
Applications in practice
Professional office
Imagine a 30-person accountancy or legal office. Historically it may have used a Vigor 2862, FTTC, a Gigabit switch and several VigorAPs. The business now has 2Gbps FTTP, cloud document systems, Teams, VoIP, cloud backups, hybrid workers, CCTV and guest Wi-Fi. The broadband connection is no longer the only consideration. The network needs segmentation, predictable wireless performance and multi-gigabit switching, so a Vigor 2928BE connected to suitable multi-gigabit switching becomes a much more logical architecture.
Engineering or creative business
A CAD, architectural, video or engineering business can generate enormous local traffic. Employees may routinely transfer multi-gigabyte project files between workstations and NAS systems. Here 10GbE matters even if the internet connection is only 1Gbps, because LAN traffic doesn’t need to go to the internet. Moving a 50GB project between a workstation and NAS can benefit enormously from multi-gigabit Ethernet. This is where looking only at WAN speed misses half the purpose of the new routers.
Retail and hospitality
A hospitality site might operate a staff network, guest Wi-Fi, EPOS, CCTV, digital signage, IoT environmental sensors, VoIP and payment systems. Segmentation is therefore extremely important. Guest devices should not share a trusted network with payment systems, CCTV shouldn’t necessarily communicate with office PCs, and IoT devices should be restricted to the services they actually require. VLANs, IAM, firewall rules and central AP management can make the router an important part of the site’s security architecture.
IoT and smart buildings
IoT deployments often contain large numbers of low-bandwidth devices. That sounds like an environment where Wi-Fi performance doesn’t matter, but density does. A building might contain hundreds of sensors, controllers, cameras, displays, handheld devices, environmental monitors and building systems. The important requirements become efficient airtime utilisation, VLAN segmentation, device isolation, traffic policies, reliable DHCP, predictable DNS, resilient WAN connectivity and remote management. Wi-Fi 7’s efficiency improvements can therefore matter even where individual IoT devices consume very little bandwidth.
Multi-site business
DrayTek remains particularly attractive to SMEs with several offices. A business could operate routers at head office, a warehouse, a retail branch and a remote office, with site-to-site VPN connecting the networks, WAN failover providing resilience and VLANs maintaining consistent segmentation. VigorACS can provide wider remote management, allowing a relatively small IT team or MSP to manage multiple sites without deploying enterprise networking hardware everywhere.
Don’t forget the switch
There is an important purchasing trap here. Buying a 10GbE router doesn’t magically create a 10GbE network. If everything downstream connects through an old Gigabit switch, most devices remain limited to Gigabit speeds. Businesses considering the 2867BE or 2928BE should therefore look at the network as a whole and ask:
- What speed is the internet connection?
- What speed is the router WAN port?
- What speed is the router LAN uplink?
- What speed are the switches?
- What speed are the access point uplinks?
- What speed are the important clients and servers?
A network is ultimately constrained by the bottlenecks between those components.
Don’t upgrade Wi-Fi without looking at cabling
The same applies to access points. A high-performance wireless access point connected through a Gigabit Ethernet port may eventually become constrained by its wired uplink. Modern Wi-Fi deployments increasingly make 2.5GbE Ethernet useful, and larger networks may use 10GbE between core switches while distributing 2.5GbE to access points. That is why the move towards multi-gigabit ports on routers is important: the router is becoming part of a wider multi-gigabit ecosystem.
Security may be the best reason to upgrade
Businesses often think about router replacement in terms of speed. That isn’t always the most important consideration. A router sits directly between the business and the internet, so running hardware that no longer receives guaranteed security maintenance should be treated differently from keeping an old printer or monitor. DrayTek states that after firmware maintenance expires, security updates are no longer guaranteed. For old Vigor hardware, that should become part of the organisation’s cyber-security and hardware lifecycle policy. An old router may still switch packets perfectly well. That doesn’t necessarily mean it should remain the security boundary of a modern business network.
A sensible five-year router strategy
Businesses shouldn’t replace routers every time a new Wi-Fi generation appears, and neither should they wait until hardware fails. A more sensible approach is to review routers against four factors:
- Support lifecycle – is the product still receiving firmware and security maintenance?
- WAN capacity – can it handle the internet services now available to the site?
- LAN capacity – can the internal network support modern switches, access points and servers without unnecessary bottlenecks?
- Security requirements – does the router support the segmentation, authentication, VPN and threat-protection features the organisation now requires?
When two or three of those answers become uncomfortable, replacement usually starts making sense.
Which should you choose: Vigor 2867BE or 2928BE?
The distinction is refreshingly straightforward. Choose the Vigor 2867BE where integrated DSL remains useful. That includes businesses currently using ADSL, VDSL/FTTC, mixed DSL and Ethernet WAN connectivity, or sites transitioning gradually towards FTTP.
Choose the Vigor 2928BE where the network is already based around Ethernet or fibre connectivity: FTTP, leased lines, dual Ethernet WAN, high-speed fibre and multi-gigabit business networks. If you don’t need DSL, there is little reason to buy it.
The bigger picture
The Vigor 2867BE and Vigor 2928BE aren’t interesting simply because DrayTek has put Wi-Fi 7 into another pair of routers. The important change is architectural. For more than a decade, SME networks have largely been built around Gigabit Ethernet. That assumption is finally disappearing.
Broadband is moving beyond 1Gbps. Wireless networking is moving beyond Gigabit speeds. NAS appliances are moving towards 2.5GbE and 10GbE. Access points increasingly require multi-gigabit uplinks. Cloud applications have made internet resilience more important. Hybrid working has made secure remote connectivity essential. IoT has increased the number and diversity of devices sitting inside business networks. And cyber security has made the old concept of one large trusted LAN increasingly difficult to defend.
The Vigor 2867BE and 2928BE are therefore best viewed as part of DrayTek’s transition from the Gigabit SME router era to the multi-gigabit business network era. If you’re running a Vigor 2865ax or 2927ax on a modest broadband connection today, there may be absolutely no reason to rush out and replace it. If you’re still running a 2860 or 2925, the lifecycle argument alone is becoming compelling. And if you’re designing a new network around multi-gigabit FTTP, 2.5GbE switching, 10GbE infrastructure and Wi-Fi 7, installing another Gigabit-centric router at the centre of it would be difficult to justify.
The takeaway. The best upgrade isn’t necessarily the newest router. It’s the router that removes the next bottleneck, improves the security architecture and gives the network enough headroom that you aren’t replacing it all over again when the next broadband upgrade arrives.
Sources: DrayTek Global and DrayTek UK product specifications, DrayTek UK product lifecycle information, IEEE 802.11 and the Wi-Fi Alliance. Specifications relate to pre-launch information and should be confirmed against the final UK launch specification.