Replacing a DrayTek: when your business outgrows the Vigor, and what comes next

Updated August 2026 · Written by the Firewall Buddy team. No DrayTek-bashing here — Vigors are good at what they're for; this is about what comes after.

First, some credit where due

The DrayTek Vigor is close to default UK small-business kit — 2865s and 2927s sit in thousands of British offices, and for good reason: dependable ADSL/VDSL handling, workable VPN, sensible price. Plenty of businesses reading this page were right to buy one. This guide is about the moment a business outgrows it — which usually announces itself as one of four things: a cyber-insurance or Cyber Essentials questionnaire the Vigor can't honestly tick; a move to FTTP or a leased line; more home workers than its VPN comfortably carries; or an incident that made proper logging suddenly interesting.

What a Netgate adds that a Vigor can't

The jump isn't speed for speed's sake — it's capability class. pfSense Plus brings intrusion detection and prevention (Suricata) watching traffic rather than just filtering it; pfBlockerNG consuming live threat feeds to block known-bad destinations network-wide; proper VLAN policy so guest Wi-Fi, card terminals and CCTV genuinely can't touch business systems; modern remote access with WireGuard alongside OpenVPN and IPsec; and logging and rule documentation that satisfy an assessor rather than embarrass you. None of it carries a subscription.

Sizing is simple at this end of the market: most DrayTek replacements are a 2100 MAX (£366 inc. VAT, up to ~25 staff) or a 4200 MAX (£546, full-gigabit lines and room for IDS everywhere). Our sizing guide covers the edge cases.

The neat trick: your DrayTek doesn't have to die

On FTTC/VDSL, the tidiest design keeps the Vigor as a modem in bridge mode: it does the DSL line negotiation it's genuinely good at, while the Netgate behind it does PPPoE, firewalling, VPN and everything security-related. You get enterprise-grade protection without touching the phone line side. On FTTP the Netgate connects straight to the ONT and the DrayTek retires with honour. Either way there's no ISP drama — we handle the PPPoE credentials and VLAN tagging (including BT's VLAN 101) as part of setup.

How the swap actually goes

A DrayTek replacement is our standard migration in miniature: we take your port forwards, DHCP reservations, VPNs and Wi-Fi arrangement, rebuild them on the Netgate in parallel, then swap in an agreed evening window — typically 15–30 minutes offline, Vigor still cabled as the instant rollback. From £399 inc. VAT including 30 days of aftercare, or £149 for a simple single-site setup without config migration. If you tell us your Vigor model and what it does today, we'll quote it straight: send the details.

Still not sure? Let us help — free

Two-minute quiz, or email us a quick description of your network and we'll give you an honest recommendation — even if it's the cheaper model.

Take the quiz → Ask us

Frequently asked questions

Can I keep my DrayTek as the modem when I move to pfSense?+
Usually, yes — and it's often the neatest design. On FTTC/VDSL lines a Vigor makes an excellent modem in bridge mode with the Netgate doing PPPoE and all the firewalling behind it. On FTTP you generally connect the Netgate straight to the ONT and the DrayTek retires completely.
Is a DrayTek Vigor actually a firewall?+
It has firewall features — NAT, SPI, basic content filtering — and for a small office with simple needs that's genuinely fine. What it lacks is the next tier: intrusion detection and prevention, managed threat-feed blocking, rich VLAN policy, serious logging, and the config documentation that schemes like Cyber Essentials and cyber-insurance questionnaires increasingly expect.
What does replacing a DrayTek with a Netgate cost?+
For most DrayTek-sized networks: a Netgate 2100 MAX at £366 inc. VAT or 4200 MAX at £546, plus optional professional setup from £149 — or our migration service from £399 which re-creates your port forwards, VPNs and Wi-Fi handoff and includes an out-of-hours cutover with rollback.
We have several sites with DrayTek-to-DrayTek VPNs — can you move those?+
Yes. We rebuild site-to-site tunnels as IPsec or WireGuard between Netgate units (or between a Netgate and a remaining DrayTek during a phased move), test them in parallel, and switch sites over one at a time so nothing is big-bang.