| Overview |
- Ready to connect to NTD (Network Termination Device) of NBN (Aust) and UFB (NZ)
- 1 x VDSL2 35b/ADSL2+ WAN port
- 35b Supervectoring VDSL2
- 1 x configurable 2.5 GbE WAN/LAN port (P1)
- 3 x Gigabit LAN ports with 50,000 NAT sessions
- NAT throughput with Hardware Acceleration over 2.3 Gbps
- IPsec VPN throughput up to 390 Mbps (AES 256 bits)
- Object-based SPI Firewall, Content Security Management (CSM), URL/IP Reputation and Port Knocking
- IAM (Identity and Access Management) to enhance security management and user experience
- IPv6 & IPv4
- 802.11ax (Wi-Fi 6, AX3000) Wi-Fi up to 574 + 2402Mbps speed (ax model)
- 16 x VPN tunnels, including IPsec, OpenVPN, and WireGuard, with EasyVPN features that simplify VPN setup for effortless connectivity
- 2 x USB ports for 4G Backup, FTP server, network printer or thermometer
- Virtual AP Controller for the deployment of up to 20 wireless VigorAPs
- Wireless Mesh (ax model) up to 7 VigorAPs
- Virtual Switch Controller to manage up to 5 VigorSwitches
- Supports VigorACS 3 Central Management Software for remote management
- 2 years back to base warranty
|
| Vigor2767 Series – High-Performance VDSL2 & 2.5GbE WAN Wi-Fi 6 VPN Security Routers |
The Vigor2767 series supports VDSL2 35b (Supervectoring) connections, and one of its four Gigabit Ethernet LAN ports can be configured as a 2.5GbE WAN/LAN interface, enabling connectivity to any Ethernet-based broadband service.
With both integrated xDSL and a high-speed 2.5GbE Ethernet WAN port, the Vigor2767 series is compatible with all major internet technologies, including FTTP, FTTC, FTTB/N, HFC, Satellite, and Fixed Wireless services deployed by nbn™ in Australia and UFB in New Zealand.
Designed for both domestic and SMB environments, the router incorporates advanced security and networking features such as an object-oriented SPI Firewall, Content Security Management (CSM), URL/IP Reputation filtering, Port Knocking, support for up to 16 VPN tunnels, and dual USB ports for 4G LTE mobile broadband backup, printer sharing, or network storage.
The Vigor2767ax model features 802.11ax (Wi-Fi 6, AX3000) wireless technology, delivering combined speeds of up to 2976 Mbps (574 Mbps on 2.4 GHz and 2402 Mbps on 5 GHz). Business-grade wireless enhancements, including AirTime Fairness, Router-Assisted Roaming, and Band Steering, ensure reliable connectivity for bandwidth-intensive applications such as HD video streaming, online gaming, and VoIP. |
2.5 GbE 1 x 2.5GbE LAN/WAN Switchable |
| VDSL2 35b Download speed up to 300 Mbps |
| 16 x VPN tunnels IPsec throughput up to 300 Mbps |
| AX 3000 Delivers link rate up to 3 Gbps (ax model only) |
|
|
|
| Interface |
 |
| (ax model) |
| WLAN/WPS Button (ax model) |
| | | Fixed WAN Port: 1 x RJ-11 (For VDSL 35b/ADSL2+ WAN) |
| | LAN/WAN Switchable Port: 1 x 2.5GbE RJ-45 |
| | Fixed LAN Port: 3 x GbE RJ-45 |
| | | | | Wi-Fi Antennas (ax model) |
| | |
|
| NAT & Routing Performance |
| With hardware acceleration, Vigor2767 Series delivers up to 2.3 Gbps aggregate NAT throughput, meeting the demands of business-critical applications while keeping VoIP traffic as the top priority. Additionally, a single 1GbE client can reach up to 950 Mbps, and VDSL2 35b provides up to 300 Mbps to LAN. |
 |
Faster Wired Connections- 4K video streaming
- Online Gaming
- Large file transfers
- Network-attached storage (NAS) devices etc
Beyond Gigabit With internet speeds of up to 2.5 Gbps, users can fully utilize the available bandwidth. |
 |
|
| Effortless and Secure VPN Access with EasyVPN |
 |
Setting up a VPN can often be complex, involving protocol selection, manual configurations, and troubleshooting, especially for non-technical users. While Vigor routers support advanced VPN protocols such as IPsec, WireGuard, and OpenVPN, traditional setup methods can be time-consuming and daunting.
EasyVPN simplifies this process by offering a streamlined, hassle-free solution for secure remote connectivity. With EasyVPN, users can quickly establish encrypted connections without the need to:- Manually generate WireGuard keys
- Import OpenVPN configuration files
- Upload certificates
By automating these steps, EasyVPN delivers a fast, secure, and intuitive VPN experience—perfect for businesses and users who want robust protection without the technical complexity. |
|
| Stealth Security Protection with Port Knocking |
DrayTek’s Port Knocking technology adds an advanced stealth security layer by keeping critical network services completely invisible to unauthorised users. Instead of exposing management ports or VPN services to the public internet, Port Knocking requires a predefined “knock” sequence before access is granted, ensuring that only trusted users can discover and use these services.
By integrating three powerful functions, Port Knocking provides robust protection against port scanning, brute-force attacks, and unauthorised access. Port Redirection- Conceal real service ports from the public internet
- Redirect unauthorised requests to non-existent services to prevent detection
 Secure Router Management AccessAllow router management access only after a successful knock sequence or through a secure internal serverCompletely eliminate direct exposure of the management interface to the open internet VPN Service Control (WAN Binding)- Keep VPN services invisible until the correct knock sequence is received
- Bind VPN availability to specific WAN interfaces and authorised IP addresses
How It Works- By default, all protected ports remain closed and undetectable
- After the correct knock sequence is received, selected ports open temporarily for authorised access
- Once the configured time window expires, services automatically return to hidden mode
With DrayTek Port Knocking, your network operates in stealth mode, invisible to attackers yet instantly accessible to authorised administrators and remote users. It is the ideal solution for organisations that demand high-level security without compromising accessibility. |
|
Vigor2767ax 2.5GbE Router with AX3000 (Wi-Fi 6) capacity |
 |
| Vigor2767ax is a 2×2 dual-band Wi-Fi router that provides 160MHz bandwidth and 1024-QAM modulation to increase wireless data speed greatly. The theoretical speed is up to 3,000Mbps, of which 574Mbps is in the 2.4GHz band and 2,402Mbps in the 5GHz band, making it 2.5 times faster than an 802.11ac 2×2 dual-band router. Equipped with business-grade features, including URL Reputation, Route Policy, App-based QoS, and lots more, Vigor2767ax is perfect for professional smart homes/SOHO users who want to take full control of their network. |
OFDMA (Orthogonal Frequency Division Multiple Access) is a core feature of the Wi-Fi 6 certification program. As part of the Wi-Fi 6 standard, OFDMA leverages advanced scheduling mechanisms to optimise performance in congested and complex network environments.
With Wi-Fi 6 gaining widespread adoption across manufacturers and the broader industry, it is increasingly important to evaluate and document the tangible benefits of effective OFDMA implementation, as well as establish reliable methods to measure and quantify its real-world performance impact. |
|
|
| MU-MIMO works like multiple trucks delivering goods at the same time. Instead of serving one device after another, it allows the router to transmit data to multiple devices simultaneously, improving overall network capacity and delivering higher speeds for each user. |
 |
|
| BSS Colouring is a technique that enhances the coexistence of overlapping Basic Service Sets (BSSs) and enables better spatial reuse within a single channel. Simply put, BSS Colouring helps reduce the co-channel interference commonly seen in legacy Wi-Fi networks. |
 |
|
| TWT (Target Wake Time) |
| Devices negotiate with the AP for a Target Wake Time (TWT), or join a TWT broadcast session, and transmit only when the TWT arrives—reducing power consumption and increasing network efficiency. |
 |
|
| WPA3 (Wi-Fi Protected Access 3) |
| WPA3 enhances Wi-Fi security by addressing vulnerabilities in previous standards (WEP, WPA and WPA2) and introducing stronger authentication, improved encryption, and better protection against brute-force and man-in-the-middle attacks. |
DrayTek’s Wi-Fi 6 encryption:- WEP (64 / 128-bit)
- WPA / WPA2 / WPA3 / OWE
|
The table below compares the security design of Wi-Fi protocols WEP, WPA, WPA2 and WPA3. | | WEP | WPA | WPA2 | WPA3 | | Encryption | RC4 | TKIP / RC4 | AES-CCMP | AES-CCMP / AES-GCMP | | Session Key | 64/128-bit | 128-bit | 128-bit | 128/256-bit | | Authentication | Open / Shared key | Pre-shared key | Pre-shared key | AES-CCMP / AES-GCMP | | Level of Security | Very low | Low | Moderate | High |
|
|
| URL Reputation |
URL Reputation is a cloud-based threat intelligence service that adds an extra layer of security to protect LAN clients during their online activities.
With a total of 82 content categories, including 10 security-focused ones, it provides comprehensive and up-to-date protection for both home and business networks.
These categories cover a wide range of areas—from malware, spyware, and adware, to parental controls, business productivity, and social networking—helping to create a safer online environment, enhance employee productivity, and support efficient bandwidth management.
|
 |
| IP Reputation |
Every internet communication involves source and destination IP addresses. Cybercriminals often exploit known malicious IPs to launch attacks using various techniques, including:- Botnets
- TOR nodes and anonymous proxies
- Command-and-Control (C2) servers
- Phishing servers
- Distributed Denial of Service (DDoS) attacks
|
 |
| IP Reputation helps identify and block traffic from these high-risk IP addresses, adding an essential layer of network protection against cyber threats. |
Blocking communication with malicious IP addresses is critical for network security. However, relying on static blocklists is no longer effective, as they lack the real-time, predictive intelligence needed to combat evolving threats. The IP Reputation Service addresses this challenge by delivering dynamic, real-time scoring and classification of IP addresses. It enables the automatic blocking of:- High-risk traffic
- Suspicious proxies
- Malware distributors
- IPs associated with recent malicious activity
The system evaluates IPs based on multiple factors, including infection history, protocol behaviour, and attack frequency. Each IP is assigned a reputation score, which determines whether it should be trusted, monitored, or blocked, ensuring proactive and intelligent network protection. |
You can purchase a URL Reputation B card for your Vigor2767 series
|
|
| IAM (Identity and Access Management) |
| The Vigor2767 Series, powered by the new DrayOS 5, is fully Zero Trust ready! |
| IAM (Identity and Access Management) is a cybersecurity system that controls user access by managing digital identities, authentication, and authorisation, to ensure correct access to network resources such as applications and devices. |
 |
With processes including identifying, authenticating, authorising users or groups, and assigning appropriate levels of access, IAM enhances both security management and the user experience and plays an important role in cloud-based services.
The IAM solution from Vigor2767 is Zero Trust Ready, and allows you to grant and categorize user privileges, create and manage access policies, and define large-scale group policies that integrate multiple filtering rules and traffic-shaping settings. |
| |
| Users & Groups |
- User accounts and user groups allow flexible access level control.
- Existing external authentication server is supported.
- User and MFA protection can be easily configured.
|
 |
| Access Policies |
System administrators can create access policies for the local users in this tab. The access policies can be configured based on:- MAC address filter list
- The allowed / blocked user list
- The login sessions lifetime
Access policies can be combined to create a robust security framework for your system. |
 |
| Conditional Access Policy |
Conditional access policies can be configured to request users to provide multiple forms of authentication before granting appropriate access to a resource.- Specify a period for the user to re-authenticate
- Restrict access to specific source IP addresses or ranges of IP addresses
- Specify VLAN-based access level in your conditional policies
- Set up time schedules when users are allowed to log in
|
 |
| Resources Tab |
| Configure local resources such as IP and MAC addresses for workstations, network printers, PBX systems, NVR systems, servers, etc. |
| |
| Backup and Restore |
| Backup or restore router settings such as Users and Groups, Access and Group Policies, etc. A password protection can be applied before backup or restore. |
 |
|
| Seamless Wi-Fi Roaming |
 |
| Fast & Smooth Handover |
| Seamlessly switch between access points with intelligent roaming support. Supports both Over-the-DS (via wired backbone) and Over-the-Air handoffs, ensuring reliable connectivity for video calls, voice communications, and real-time applications. |
| Smarter Assisted Roaming |
Configurable signal thresholds and AP steering guide devices to stronger access points and help balance network loads. Enjoy stable, consistent performance across all devices everywhere. |
| Always Optimized for Business |
| From offices to campuses, seamless roaming delivers uninterrupted mobility. Built to provide reliable coverage for the demands of modern workplaces. |
| Mesh Wi-Fi (Vigor2767ax only) |
| Vigor2767ax supports up to 7 APs, which can form one or more Wireless Groups. Each group can form Mesh links automatically based on the optimum signal level among the APs and devices. |
 |
 |
 |
| Key Features |
2.5 GbE Provides higher performance to Wi-Fi 6 AP and other Ethernet devices
35b Supervectoring Modem Integrated VDSL modem with 35b Supervectoring compatibility and VDSL2/ADSL2+ fallback.
Bandwidth Management Prevent one device using all the bandwidth by bandwidth limit policy, session limit policy, and QoS settings.
DrayDDNS The free DDNS service for you to access the router by a fixed hostname of your choice. Learn more.
VPN (Virtual Private Network) Build a secure and private tunnel from the LAN of Vigor2767 Series to the remote offices and teleworkers over the Internet. Learn more
EasyVPN Secure VPN in Seconds: No Keys, No Configs, Just Login.
Port Knocking Add a stealth security layer to protect ports from unauthorized access.
Firewall & Content Filter Filter web pages by URL keyword or web category to block access to insecure or inappropriate contents.
URL/IP Reputation Improve network security by classifying URLs and IPs to control web access and protect against online threats. Learn more
IAM A solution that manages digital identities, authentication, and access control to ensure the right users or groups have appropriate access to critical resources.
Hotspot Web Portal Market your business and communicate with the guests while offering hospitality WLAN. Learn more.
Wi-Fi 6 (ax model only) Feature OFDMA and MU-MIMO technology to improve Wi-Fi efficiency and deliver higher wireless speed
Mesh (Wireless model only) Easily link to other VigorAP to expand the wireless network. Learn more.
Virtual AP/Switch controller All-in-one management platform for Vigor2767 to maintain and monitor the VigorAPs and VigorSwitches.
|
| Unified Mesh & AP Management |
| Configure local resources such as IP and MAC addresses for workstations, network printers, PBX systems, NVR systems, servers, etc. |
 |
| Mesh Mode |
| Automatically forms a self-healing wireless mesh network, with the Vigor2767ax as the Root AP and up to 7 Node APs, delivering easy, scalable, and reliable Wi-Fi coverage. |
| AP Management Mode |
| For networks with more than 8 APs, the Virtual Controller switches to AP Management mode, allowing centralised control of up to 20 APs directly through the router’s interface. |
| Seamless Mesh Role Assignment |
| When powered on, devices automatically discover each other and assign roles as Root or Node Aps, no manual setup required. This streamlined process enables rapid mesh network formation with optimised coverage and self-healing reliability. |
 | | ▶ Watch: Mesh Role Auto Assignment Demo | |
| Central Switch Manager (SWM) |
The Central Switch Manager (SWM) provides a comprehensive solution for simplifying network administration. It automatically detects and manages all compatible VigorSwitches from a single, centralised interface, eliminating the need to configure each device individually. Administrators can efficiently push configurations to multiple switches and monitor their real-time status to ensure network stability.
SWM also streamlines advanced management tasks, allowing easy implementation of VLAN segmentation and Quality of Service (QoS) policies. This consolidated approach reduces maintenance time and boosts the overall efficiency and reliability of your network infrastructure
|
| SWM |
 |
The Vigor2767 Series can function as a master controller, managing and monitoring up to 5 switches. It also provides full visibility into powered devices (PDs) connected behind the switches, such as IP cameras and access points.
|
| Device Management |
 |
Monitor the status, firmware version, and uptime of all managed switches in real time.
|
| Port Profile |
 |
Create multiple port profiles to easily configure PoE, VLAN, QoS, and other settings across selected switches.
|
| Maintenance |
 |
Create multiple port profiles to easily configure PoE, VLAN, QoS, and other settings across selected switches.
|
| Software Management |
VigorACS 3 |
 |
- Zero Touch Deployment & Provisioning
- Auto VPN
- Interface Quality & SLA
- VoIP Optimization & Monitoring
- Application Visibility
- Application Based SD-WAN Policy
- Customized Hotspot Page with Multilingual
- Hotspot Clients Analytics
- ACS Server Load Balancing / Failover
|
|
| In-the-box |
 Vigor2767 Series |  2 x Antennas(ax models) |  RJ-45 Cable (Ethernet) |  RJ-11 to RJ-11 Cable (Annex A) |  Power Adaptor |  Quick Start Guide | Note: The throughput figures are maximum, based on DrayTek internal testing with optimal conditions. The actual performance may vary depending on the different network conditions and applications activated. |
| Models |
| Vigor2767ax |
| VDSL2 35b Single WAN routers with
1 x Configurable 2.5GbE WAN/LAN port,
3 x GbE LAN ports, SPI Firewall,
Port Knocking, 802.11ax Wi-Fi 6 (ax model),
and 16 x VPN tunnels including
IPsec, OpenVPN, and WireGuard |
|
 |
- Ready to connect to NTD (Network Termination Device) of NBN (Aust) and UFB (NZ)
- 1 x VDSL2 35b/ADSL2+ WAN port
- 35b Supervectoring VDSL2
- 1 x configurable 2.5 GbE WAN/LAN port (P1)
- 3 x Gigabit LAN ports with 50,000 NAT sessions
- NAT throughput with Hardware Acceleration over 2.3 Gbps
- IPsec VPN throughput up to 390 Mbps (AES 256 bits)
- Object-based SPI Firewall, Content Security Management (CSM), URL/IP Reputation and Port Knocking
- IAM (Identity and Access Management) to enhance security management and user experience
- IPv6 & IPv4
- 802.11ax (Wi-Fi 6, AX3000) Wi-Fi up to 574 + 2402Mbps speed (ax model)
- 16 x VPN tunnels, including IPsec, OpenVPN, and WireGuard, with EasyVPN features that simplify VPN setup for effortless connectivity
- 2 x USB ports for 4G Backup, FTP server, network printer or thermometer
- Virtual AP Controller for the deployment of up to 20 wireless VigorAPs
- Wireless Mesh up to 7 VigorAPs
- Virtual Switch Controller to manage up to 5 VigorSwitches
- Supports VigorACS 3 Central Management Software for remote management
- 2 years back to base warranty
| |
|
| Vigor2767 |
| VDSL2 35b Single WAN routers with 1 x Configurable 2.5GbE WAN/LAN port, 3 x GbE LAN ports, SPI Firewall, Port Knocking, and 16 x VPN tunnels including IPsec, OpenVPN, and WireGuard |
|
 |
- Ready to connect to NTD (Network Termination Device) of NBN (Aust) and UFB (NZ)
- 1 x VDSL2 35b/ADSL2+ WAN port
- 35b Supervectoring VDSL2
- 1 x configurable 2.5 GbE WAN/LAN port (P1)
- 3 x Gigabit LAN ports with 50,000 NAT sessions
- NAT throughput with Hardware Acceleration over 2.3 Gbps
- IPsec VPN throughput up to 390 Mbps (AES 256 bits)
- Object-based SPI Firewall, Content Security Management (CSM), URL/IP Reputation and Port Knocking
- IAM (Identity and Access Management) to enhance security management and user experience
- IPv6 & IPv4
- 16 x VPN tunnels, including IPsec, OpenVPN, and WireGuard, with EasyVPN features that simplify VPN setup for effortless connectivity
- 2 x USB ports for 4G Backup, FTP server, network printer or thermometer
- Virtual AP Controller for the deployment of up to 20 wireless VigorAPs
- Virtual Switch Controller to manage up to 5 VigorSwitches
- Supports VigorACS 3 Central Management Software for remote management
- 2 years back to base warranty
| |
|
| Video |
 |
|
| Config Demo |
 |
Click below for the Config Demo Page: |
| |
| |
|
 |
|
 |
| |