• Ready to connect to NTD (Network Termination Device) of NBN (Aust) and UFB (NZ)

  • Cat.6 4G LTE modem with dual nano SIM slots (SIM slot 2 for Failover) for FDD & TDD 4G LTE WAN

  • Support 4G LTE bands: B1/B3/B7/B8/B20/B28/B32/B38/B40; great coverage in Australia and New Zealand, Cat.6 4G LTE with 300Mbps download and 50Mbps upload speeds

  • 1 x 2.5 Gigabit WAN port, Wi-Fi WAN and 2 x USB ports for 4G Mobile Fail-Over
  • 1 x configurable 2.5 GbE WAN/LAN port (P1)
  • Support dual-WAN Load Balance and Failover, with per-WAN Weight for Primary and Failover members
  • 3 x Gigabit LAN ports with 50,000 NAT sessions
  • NAT throughput with Hardware Acceleration over 2.3 Gbps
  • IPsec VPN throughput up to 390 Mbps (AES 256 bits)
  • Object-based SPI Firewall, Content Security Management (CSM), URL/IP Reputation and Port Knocking
  • IAM (Identity and Access Management) to enhance security management and user experience
  • IPv6 & IPv4

  • 802.11ax (Wi-Fi 6, AX3000) Wi-Fi up to 574 + 2402Mbps speed

  • 16 x VPN tunnels, including IPsec, OpenVPN, and WireGuard, with EasyVPN features that simplify VPN setup for effortless connectivity

  • 1 x USB ports for 4G Backup, FTP server, network printer or thermometer

  • Virtual AP Controller for the deployment of up to 20 wireless VigorAPs
  • Wireless Mesh up to 7 VigorAPs

  • Virtual Switch Controller to manage up to 5 VigorSwitches

  • Supports VigorACS 3 Central Management Software for remote management

  • 2 years back to base warranty

2.5GbE Dual-WAN High-Speed Security Router with 4G Cellular

The Vigor2136ax-4G delivers reliable, ultra-fast connectivity with built-in 4G LTE support. Featuring embedded dual SIM slots (one active at a time), it provides seamless network redundancy to ensure uninterrupted cellular access. An integrated 2.5GbE WAN port handles high-speed wired performance, while Wi-Fi 6 (802.11ax) guarantees stable wireless connections, even in dense device environments.

Designed for mission-critical reliability, the router supports Ethernet WAN or Wi-Fi WAN alongside 4G LTE. Dual-WAN load balancing and automated failover, complete with configurable per-WAN weight control, keep your business connected without interruption.

The Vigor2136ax-4G also offers a robust suite of enterprise security and networking tools, including Route Policy, App-based QoS, IP/URL Filtering, SPI Firewall, Port Knocking, Tag-based VLAN, up to 16 VPN tunnels, and advanced traffic management. This makes it an ideal, all-in-one networking solution for offices, retail stores, and branch sites.

Key Features

[DISPLAY OFF] —– MOBILE VIEW

Multi-Gigabit Router

Faster Wired Connections

  • 4K video streaming
  • Online Gaming
  • Large file transfers
  • Network-attached storage (NAS) devices etc

Beyond Gigabit

With internet speeds of up to 2.5 Gbps, users can fully utilize the available bandwidth.

4G Router with High Speed Mobile Connectivity

  • Equipped with an integrated 4G LTE Cat.6 modem, the router supports carrier aggregation to deliver high-speed mobile broadband connectivity for reliable internet access and VPN services.
  • The dual-SIM slot design allows the use of two mobile network providers. If the primary mobile network becomes unavailable, the router can automatically switch to the secondary SIM to maintain continuous cellular connectivity.
  • With two external 4G cellular antennas, users can flexibly position the antennas to achieve optimal signal reception, even in challenging installation environments.

Effortless and Secure VPN Access with EasyVPN

Setting up a VPN can often be complex, involving protocol selection, manual configurations, and troubleshooting, especially for non-technical users. While Vigor routers support advanced VPN protocols such as IPsec, WireGuard, and OpenVPN, traditional setup methods can be time-consuming and daunting.

EasyVPN simplifies this process by offering a streamlined, hassle-free solution for secure remote connectivity. With EasyVPN, users can quickly establish encrypted connections without the need to:

  • Manually generate WireGuard keys
  • Import OpenVPN configuration files
  • Upload certificates

By automating these steps, EasyVPN delivers a fast, secure, and intuitive VPN experience, perfect for businesses and users who want robust protection without the technical complexity.

Stealth Security Protection with Port Knocking

DrayTek’s Port Knocking technology adds an advanced stealth security layer by keeping critical network services completely invisible to unauthorised users. Instead of exposing management ports or VPN services to the public internet, Port Knocking requires a predefined “knock” sequence before access is granted, ensuring that only trusted users can discover and use these services.

By integrating three powerful functions, Port Knocking provides robust protection against port scanning, brute-force attacks, and unauthorised access.

Port Redirection

  • Conceal real service ports from the public internet
  • Redirect unauthorised requests to non-existent services to prevent detection

Secure Router Management Access

  • Allow router management access only after a successful knock sequence or through a secure internal server
  • Completely eliminate direct exposure of the management interface to the open internet

VPN Service Control (WAN Binding)

  • Keep VPN services invisible until the correct knock sequence is received
  • Bind VPN availability to specific WAN interfaces and authorised IP addresses

How It Works

  • By default, all protected ports remain closed and undetectable
  • After the correct knock sequence is received, selected ports open temporarily for authorised access
  • Once the configured time window expires, services automatically return to hidden mode

With DrayTek Port Knocking, your network operates in stealth mode, invisible to attackers yet instantly accessible to authorised administrators and remote users. It is the ideal solution for organisations that demand high-level security without compromising accessibility.

Secure network with VPN

Vigor2136 supports the most secure VPN protocols:

Hardware NAT & Routing

With hardware acceleration enabled, the Vigor2136 Series’ NAT throughput can reach 2.3Gbps while still meeting the requirements of QoS. Business-critical apps can be prioritised over other apps.

LAN (2.5GbE) to WAN 1

With Hardware NAT & Routing

2.3 Gbps

LAN (1GbE) to WAN 1

Without Hardware NAT & Routing

950 Mbps

LAN (2.5GbE) to WAN 1

With Hardware NAT & Routing

2.3 Gbps

LAN (1GbE) to WAN 1

Without Hardware NAT & Routing

950 Mbps

Vigor2136ax-4G: 2.5GbE Dual-WAN Router with AX3000 Wi-Fi 6

The Vigor2136ax-4G is a 2×2 dual-band Wi-Fi 6 dual-WAN router featuring 160MHz channel bandwidth and 1024-QAM modulation for significantly boosted wireless speeds. It achieves theoretical throughput of up to 3,000 Mbps, delivering up to 574 Mbps on the 2.4GHz band and 2,402 Mbps on the 5GHz band, making it up to 2.5 times faster than standard 802.11ac 2×2 dual-band routers. For uninterrupted uptime, it supports dual-WAN load balancing and failover with configurable per-WAN weight controls for primary and failover connections.

Packed with business-grade features, including URL Reputation, Route Policy, App-based QoS, and advanced management tools, the Vigor2136ax-4G is the ideal solution for prosumers, smart homes, and SOHO users who want to take full control of their network.

OFDMA (Orthogonal Frequency Division Multiple Access).
With OFDMA modulation scheme, each channel is made up of 256 subcarriers spaced 78.125 kHz apart, compared to 64 subcarriers spaced 312.5 kHz apart with OFDM. With up to 4 times data efficiency and more advanced channel sharing technologies, a device can be allotted bandwidth based on the assessed needs for the highest airtime efficiency possible. For example, users on streaming or VoIP services can be allocated more bandwidth and time, while services such as email or website browsing can be assigned less bandwidth that are still sufficient for the tasks, thus improving user experience in high-density environments.

MU-MIMO 

BSS Colouring Instead of CSMA/CA which allows only one device to transmit at a time, 802.11ax uses BSS Colouring to manage collision avoidance. Each Wi-Fi device is assigned a Basic Service Set (BSS), a 6-bit colour field, while adjacent devices are allocated with different colours. Before transmitting, the device checks the BSS and backs off only when the BSS is of the same colour as its own. In this way, the spectral efficiency is maximized as APs and Wi-Fi clients can transmit simultaneously even if they are on the same channel.

TWT (Target wake time)
Devices negotiate with the AP for a Target Wake Time (TWT), or joint a TWT broadcast session, and transmit data only when the TWT arrives, thereby reducing power consumption and increase network efficiency.

WPA3 (Wi-Fi Protected Access 3) enhances the security of Wi-Fi networks by addressing vulnerabilities in previous standards (WEP, WPA and WPS2) and introduces new features including stronger authentication, better encryption, and improved protection against attacks such as brute-force password guessing and man-in-the-middle exploits.

DrayTek’s Wi-Fi 6 encryption:

  • WEP (64 / 128-bit)
  • WPA / WPA2 / WPA3 / OWE

The comparison table below compares security design of Wi-Fi security protocols WEP, WPA, WPA2 and WPA3.

WEPWPAWPA2WPA3
EncryptionRC4TKIP / RC4AES-CCMPAES-CCMP /
AES-GCMP
Session Key64/128 bit128 bit128 bit128/256 bit
AuthenticationOpen system,
shared key
Pre-shared keyPre-shared keyAES-CCMP /
AES-GCMP
Level of SecurityVery lowlowModerateHigh

[DISPLAY OFF] —– MOBILE VIEW

WEPWPAWPA2WPA3
EncryptionRC4TKIP /
RC4
AES-
CCMP
AES-
CCMP /
AES-
GCMP
Session Key64/128
bit
128
bit
128 bit128/256

bit

AuthenticationOpen
system,
shared
key
Pre-
shared
key
Pre-
shared
key
AES-
CCMP /
AES-
GCMP
Level of
Security
Very
low
lowModerateHigh
EncryptionWEP:
RC4
WPA:
TKIP / RC4
WPA2:
AES-CCMP
WPA3:
AES-CCMP /
AES-GCMP
Session KeyWEP:
64/128 bit
WPA:
128 bit
WPA2:
128 bit
WPA3:
128/256 bit
AuthenticationWEP:
Open system,
shared key
WPA:
Pre-shared key
WPA2:
Pre-shared key
WPA3:
AES-CCMP /
AES-GCMP
Level of SecurityWEP:
Very low
WPA:
low
WPA2:
Moderate
WPA3:
High

URL Reputation

URL Reputation is a cloud-based threat intelligence service that adds an extra layer of security to protect LAN clients during their online activities.

With a total of 82 content categories, including 10 security-focused ones, it provides comprehensive and up-to-date protection for both home and business networks.

These categories cover a wide range of areas—from malware, spyware, and adware, to parental controls, business productivity, and social networking—helping to create a safer online environment, enhance employee productivity, and support efficient bandwidth management.

IP Reputation

Every internet communication involves source and destination IP addresses. Cybercriminals often exploit known malicious IPs to launch attacks using various techniques, including:

  • Botnets
  • TOR nodes and anonymous proxies
  • Command-and-Control (C2) servers
  • Phishing servers
  • Distributed Denial of Service (DDoS) attacks

IP Reputation helps identify and block traffic from these high-risk IP addresses, adding an essential layer of network protection against cyber threats.

Blocking communication with malicious IP addresses is critical for network security. However, relying on static blocklists is no longer effective, as they lack the real-time, predictive intelligence needed to combat evolving threats. The IP Reputation Service addresses this challenge by delivering dynamic, real-time scoring and classification of IP addresses. It enables the automatic blocking of:

  • High-risk traffic
  • Suspicious proxies
  • Malware distributors
  • IPs associated with recent malicious activity

The system evaluates IPs based on multiple factors, including infection history, protocol behaviour, and attack frequency. Each IP is assigned a reputation score, which determines whether it should be trusted, monitored, or blocked, ensuring proactive and intelligent network protection.

You can purchase a URL Reputation B card for your Vigor2136 series

IAM (Identity and Access Management) 

Vigor2136 Series with the new DrayOS5 is Zero Trust ready!

IAM (Identity and Access Management) is a cybersecurity system that controls user access by managing digital identities, authentication, and authorisation, to ensure correct access to network resources such as applications and devices.

With processes including identifying, authenticating, authorising users or groups, and assigning appropriate levels of access, IAM enhances both security management and the user experience and plays an important role in cloud-based services.

The IAM solution from Vigor2136 is Zero Trust Ready, and allows you to grant and categorize user privileges, create and manage access policies, and define large-scale group policies that integrate multiple filtering rules and traffic-shaping settings.

Users & Groups
  •  User accounts and user groups allow flexible access level control.
  •  Existing external authentication server is supported.
  •  User and MFA protection can be easily configured.
Access Policies

System administrators can create access policies for the local users in this tab. The access policies can be configured based on:

  • MAC address filter list
  • The allowed / blocked user list
  • The login sessions lifetime

Access policies can be combined to create a robust security framework for your system.

Group Policies

Group policies can be configured for predefined local resources such as employees, workstations, network printers, and local servers. Network Firewall and traffic shaping policies can be configured to enhance network security and optimise traffic flows.

Conditional Access Policy

Conditional access policies can be configured to request users to provide multiple forms of authentication before granting appropriate access to a resource.

  • Specify a period for the user to re-authenticate
  • Restrict access to specific source IP addresses or ranges of IP addresses
  • Specify VLAN-based access level in your conditional policies
  • Set up time schedules when users are allowed to log-in
Resources Tab

Configure local resources such as IP and Mac addresses for workstations, network printers, PBX systems, NVR systems, servers, etc.

Backup and Restore

Backup or restore router settings such as Users and Groups, Access and Group Policies, etc. A Password protection can be applied before backup or restore.

Seamless Wi-Fi Roaming

Fast & Smooth Handover

Seamlessly switch between access points with intelligent roaming support. Supports both Over-the-DS (via wired backbone) and Over-the-Air handoffs, ensuring reliable connectivity for video calls, voice communications, and real-time applications.

Smarter Assisted Roaming

Configurable signal thresholds and AP steering guide devices to stronger access points and help balance network loads.
Enjoy stable, consistent performance across all devices everywhere.

Always Optimized for Business

From offices to campuses, seamless roaming delivers uninterrupted mobility. Built to provide reliable coverage for the demands of modern workplaces.

Mesh Wi-Fi

Vigor2136ax-4G supports up to 7 APs, which can form one or more Wireless Groups. Each group can form Mesh links automatically based on the optimum signal level among the APs and devices.

Hotspot Web Portal

Market your business while offering free Wi-Fi

Wi-Fi Marketing

Redirect hotspot guests to the company homepage, online surveys, or display a promotion message.

Grow Customer Mailing List

Require guests to leave contact info or social media accounts before they can use the Internet services.

Various Authentication Types

Various login methods are supported to meet your business needs, including Facebook Login, Google Login, SMS PIN, and RADIUS.

3rd-Party Service Compliant

Supports external captive portal authentication so you can keep using the Wi-Fi marketing solution you prefer.

Data Quota Management

Bandwidth management is integrated into the Hotspot features to control the bandwidth and session usage of the Hotspot guests.

LAN Management

The LAN Management platform allows easy and flexible configuration for Vigor devices on the LAN side, supporting up to 20 VigorAPs (including a root AP) and 5 VigorSwitches.

Automatic Device Discovery

Just connect new devices such as Vigor Switches or APs to the LAN port, Vigor2136 will auto-configure the new devices into the network.

Provisioning

New devices such as Vigor Switch/AP can be configured into the network automatically.

Monitoring

A summarized view of the network at the same page allows fast monitoring of all devices in the network.

System Maintenance

Tasks such as factory reset, backup and restore of configuration settings, or remote reboot can be performed from the Vigor routers, without needing to log in to the devices’ management pages.

Management Solution

On-Device Network Management with DrayTek Virtual Controller

The DrayTek Virtual Controller is a built-in management platform available on supported routers and firewalls.
It delivers centralised network control without cloud dependency, helping reduce data exposure risks while
enhancing security and privacy.

Wireless Management

  • Mesh Controller – Easily build and manage wireless mesh networks with auto-routing and self-healing capabilities.
  • AP Management (APM) – Automatically discover, configure, and monitor connected VigorAPs, making it simple to deploy multiple APs with unified settings.

Switch Management

  • Central Switch Manager (SWM) – Detect and manage supported VigorSwitches, push configurations, monitor device status, and apply VLAN or QoS policies, all from a single local interface.

Wireless Management Solution

Mesh (ax model)

Up to 7 APs

  • DrayTek Wireless app-support
  • Discovery
  • Auto-Provisioning
  • Monitoring
  • Centralized Hierarchy View

Virtual AP Controller

Up to 9 VigorAPs

  • Auto-Discovery
  • Auto-Provisioning
  • Monitoring
  • Centralized View
  • Alarm
  • Reboot VigorAP Remotely
  • Wi-Fi Client Load Balancing

Device Management

View and Configure VigorAPs

  • Device List
  • Mesh Status
  • AP Adoption

Switch Management Solution

SWM (Switch Management)

The Vigor2136 Series can operate as a master controller to centrally manage and monitor up to 5 switches. It also provides visibility into connected PD devices behind the switches, such as IP cameras and access points.

Device Management

Easily monitor switch status, firmware versions, and uptime across all managed devices from a single interface.

Port Profile

Create and apply multiple port profiles to configure PoE, VLAN, QoS, and other settings across selected switches with ease.

Maintenance

Easily perform configuration backup and restore, remote reboots, or full factory resets.

Software Management

VigorACS 3

  • Zero Touch Deployment & Provisioning
  • Auto VPN
  • Interface Quality & SLA
  • VoIP Optimization & Monitoring
  • Application Visibility
  • Application Based SD-WAN Policy
  • Customized Hotspot Page with Multilingual
  • Hotspot Clients Analytics
  • ACS Server Load Balancing / Failover

Vigor2136ax Review

In-the-Box

Vigor2136ax-4G

Cellular Antenna x 2

Wi-Fi Antenna x 2

RJ-45 Cable
(Ethernet)

Power Adaptor

Quick Start Guide

Note :

The throughput figures are maximum, based on DrayTek internal testing with optimal conditions. The actual performance may vary depending on the different network conditions and applications activated.

Models

ModelVigor2136Vigor2136axVigor2136ax-4G
Product
Gigabit WAN1 x 2.5 GbE1 x 2.5 GbE1 x 2.5 GbE
Selectable Gigabit WAN/LAN1 x 2.5 GbE1 x 2.5 GbE1 x 2.5 GbE
4G LTE2 x USB 2.02 x USB 2.02 x nano SIM slots (SIM slot 2 for Failover)
1 x USB 2.0
Wireless WAN
Gigabit LAN333
VPN Tunnels161616
Wireless LAN
WiFi 6, AX3000WiFi 6, AX3000
Wi-Fi Antenna
2.7dBi for 5GHz
2.6dBi for 2.4GHz
2.7dBi for 5GHz
2.6dBi for 2.4GHz
VoIP (2xFXS)

Vigor2136

Vigor2136
  • Gigabit WAN: 1×2.5GbE
  • Selectable Gigabit WAN/LAN:
    1×2.5GbE
  • 3G/4G LTE: 2 x USB 2.0
  • Gigabit LAN: 3
  • VPN Tunnels: 16
  • Wireless LAN: n/a
  • Wi-Fi Antenna: n/a
  • VoIP (2xFXS): n/a

Vigor2136ax

Vigor2136ax
  • Gigabit WAN: 1×2.5GbE
  • Selectable Gigabit WAN/LAN:
    1×2.5GbE
  • 3G/4G LTE: 2 x USB 2.0
  • Gigabit LAN: 3
  • VPN Tunnels: 16
  • Wireless LAN:
    WiFi 6, AX3000
  • Wi-Fi Antenna:
    2.7dBi for 5GHz
    2.6dBi for 2.4GHz
  • VoIP (2xFXS): n/a

Vigor2136ax-4G

Vigor2136ax-4G
  • Gigabit WAN: 1×2.5GbE
  • Selectable Gigabit WAN/LAN:
    1×2.5GbE
  • 3G/4G LTE:
    2 x nano SIM slots
    (SIM slot 2 for Failover)
    1 x USB 2.0
  • Gigabit LAN: 3
  • VPN Tunnels: 16
  • Wireless LAN:
    WiFi 6, AX3000
  • Wi-Fi Antenna:
    2.7dBi for 5GHz
    2.6dBi for 2.4GHz
  • VoIP (2xFXS): n/a

Specifications

Interface (gDisplayOff)

Interface
WAN Port1 x 2.5 GbE
Selectable Gigabit WAN/LAN1 x 2.5 GbE
LAN Port3 x Gigabit Ethernet
SIM Slot2 x nano SIM slots (SIM slot 2 for Failover)
USB Port1 x USB 2.0 for 4G/LTE USB modem, storage, printer or thermometer
Wi-Fi Antenna2x External Dipole, Gain: 2.7 dBi for 5GHz, 2.6 dBi for 2.4GHz (ax model)
2.4G WLAN802.11ax 2×2 MIMO, up to 574Mbps Link Rate (ax model)
5G WLAN802.11ax 2×2 MU-MIMO, up to 2402Mbps Link Rate (ax model)

[DISPLAY OFF] —– MOBILE VIEW

Interface
WAN Port:
1 x 2.5GbE
Selectable Gigabit
WAN/LAN:
1 x 2.5GbE
LAN Port:
3 x Gigabit Ethernet
SIM Slot:
2 x nano SIM slots
(SIM slot 2 for Failover)
USB Port:
1x USB 2.0 for
4G/LTE USB modem, storage,
printer or thermometer
Wi-Fi Antenna:
2 x External Dipole
Gain: 2.7 dBi for 5GHz, 2.6 dBi for
2.4GHz (ax model)
2.4G WLAN:
802.11ax 2×2 MIMO,
up to 574Mbps Link Rate
(ax model)
5G WLAN:
802.11ax 2×2 MU-MIMO,
up to 2402Mbps Link Rate
(ax model)

Performance (gDisplayOff)

Performance
NAT Throughput w/ Hardware Acceleration2300 Mbps
IPsec VPN Performance390 Mbps (AES 256 bits)
Wireguard VPN Throughput90 Mbps
Max. Number of NAT Sessions50,000
Max. Concurrent VPN Tunnels (including OpenVPN/
SSL-VPN/Wireguard)
16

[DISPLAY OFF] —– MOBILE VIEW

Performance
NAT Throughput w/
Hardware Acceleration:
2300 Mbps
IPsec VPN Performance:
390 Mbps (AES 256 bits)
Wireguard VPN Throughput:
90 Mbps
Max. Number of NAT
Sessions:
50,000
Max. Concurrent VPN
Tunnels (including OpenVPN/
SSL-VPN/Wireguard)
:
16

4G LTE (gDisplayOff)

4G
LTE CategoryCAT.6
LTE Antenna (External Dipole)2
Max. Rx Link Rate300 Mbps
Max. Tx Link Rate50 Mbps
FDD Band1 (2100MHz), 20 (800MHz), 28 (700MHz), 3 (1800MHz), 7 (2600MHz), 8 (900MHz)
TDD Band38 (2600MHz), 40 (2300MHz)
WCDMA (3G) Band1, 8
4G
LTE Category :
CAT.6
LTE Antenna
(External Dipole) :
2
Max. Rx Link Rate:
300 Mbps
Max. Tx Link Rate:
50 Mbps
FDD Band :
1 (2100MHz), 20 (800MHz),
28 (700MHz), 3 (1800MHz),
7 (2600MHz), 8 (900MHz)
TDD Band :
38 (2600MHz), 40 (2300MHz)
WCDMA (3G) Band :
1, 8

Internet Connection (gDisplayOff)

Internet Connection
IPv4PPPoE, DHCP, Static IP
IPv6PPP, DHCPv6, Static IPv6, TSPC, 6rd, 6in4 Static Tunnel
802.1p/q Multi-VLAN Tagging
Multi-VLAN/PVC
4G/LTE WAN with USB modem
WAN Failover
Connection DetectionARP, Ping
WAN Data Budget
Dynamic DNS
DrayDDNS

[DISPLAY OFF] —– MOBILE VIEW

Internet Connection
IPv4:
PPPoE, DHCP, Static IP
IPv6:
PPP, DHCPv6, Static IPv6, TSPC,
6rd, 6in4 Static Tunnel
802.1p/q Multi-VLAN
Tagging
Multi-VLAN/PVC
4G/LTE WAN with
USB modem
WAN Failover
Connection Detection:
ARP, Ping
WAN Data Budget
Dynamic DNS
DrayDDNS

LAN Management (gDisplayOff)

LAN Management
VLAN802.1q Tag-based, Port-based
Max. Number of VLAN8
Number of LAN Subnet4
DHCP ServerMultiple IP Subnet, Custom DHCP Options, Bind-IP-to-MAC
Wired 802.1x Authentication
Port Mirroring
Local DNS Server
Conditional DNS Forwarding
Hotspot Web Portal2
Hotspot AuthenticationClick-Through, External Portal Server

[DISPLAY OFF] —– MOBILE VIEW

LAN Management
VLAN:
802.1q Tag-based, Port-based
Max. Number of VLAN:
8
Number of LAN Subnet:
4
DHCP Server:
Multiple IP Subnet,
Custom DHCP Options,
Bind-IP-to-MAC
Wired 802.1x
Authentication
Port Mirroring
* Future Support
Local DNS Server
Conditional DNS
Forwarding
Hotspot Web Portal2
Hotspot Authentication:
Click-Through,
External Portal Server

Networking (gDisplayOff)

Networking
RoutingIPv4 Static Routing, IPv6 Static Routing, Policy Route, Inter-VLAN Routing, RIP v1/v2, BGP, OSPF(V2/V3)
Policy-based RoutingProtocol, IP Address, Port
DNS Security (DNSSEC)
MulticastIGMP v2/v3, IGMP Proxy, IGMP Snooping & Fast Leave
Local RADIUS server
SMB File Sharing (Requires external storage)

[DISPLAY OFF] —– MOBILE VIEW

Networking
Routing:
IPv4 Static Routing,
IPv6 Static Routing,
Policy Route, Inter-VLAN Routing,
RIP v1/v2, BGP, OSPF(V2/V3)
Policy-based Routing:
Protocol, IP Address, Port
DNS Security
(DNSSEC)
IGMP:
IGMP v2/v3, IGMP Proxy,
IGMP Snooping & Fast Leave
Local RADIUS server:
SMB File Sharing:
(Requires external storage)

VPN (gDisplayOff)

VPN
LAN-to-LAN
Teleworker-to-LAN
ProtocolsIPsec, IKEv2, IKEv2-EAP, IPsec XAuth, OpenVPN, Wireguard
User AuthenticationLocal, RADIUS, TACACS+, mOTP, TOTP
IKE AuthenticationPre-Shared Key, X.509
IPsec AuthenticationSHA1, SHA256
EncryptionDES, 3DES, AES128, AES192, AES256
Single-Armed VPN
NAT-Traversal (NAT-T)
VPN Connection Status
Backup & Restore

[DISPLAY OFF] —– MOBILE VIEW

VPN
LAN-to-LAN
Teleworker-to-LAN
Protocols:
IPsec, IKEv2, IKEv2-EAP,
IPsec-XAuth, OpenVPN, Wireguard
User Authentication:
Local, RADIUS, TACACS+,
mOTP, TOTP
IKE Authentication:
Pre-Shared Key, X.509
IPsec Authentication:
SHA1, SHA256
Encryption:
DES, 3DES, AES128, AES192, AES256
Single-Armed VPN
NAT-Traversal (NAT-T)
VPN Connection
Status
Backup & Restore

Security (gDisplayOff)

Security
URL/IP Reputation
Firewall FilterIP, Content, Traffic
Port Knocking
Defense SetupARP Spoofing, IP Spoofing
MAC Filtering Profile
IPv6 Address Security

[DISPLAY OFF] —– MOBILE VIEW

Security
URL/IP Reputation
Firewall Filter:
IP, Content, Traffic
Port Knocking
Defense Setup:
ARP Spoofing, IP Spoofing
MAC Filtering Profile
IPv6 Address
Security

IAM (gDisplayOff)

IAM
Users & Groups
Access Policies
Group Policies
Conditional Access Policy
Resources
Account Status*
Backup and Restore

[DISPLAY OFF] —– MOBILE VIEW

IAM
Users & Groups
Access Policies
Group Policies
Conditional Access
Policy
Resources
Account Status
Backup and Restore

Bandwidth Management (gDisplayOff)

Bandwidth Management
Traffic Shaping Policy
IP-based Bandwidth Limit
IP-based Session Limit*
QoS (Quality of Service)IP Address, Port, Application
APP QoS
Default Policy
VoIP Prioritization

[DISPLAY OFF] —– MOBILE VIEW

Bandwidth Management
Traffic Shaping
Policy
IP-based Bandwidth
Limit
QoS (Quality of Service):
IP Address, Port, Application
APP QoS
Default Policy
VoIP Prioritization

Wireless LAN (ax model) (gDisplayOff)

Wireless LAN (ax model)
2.4GHz WLAN802.11ax 2×2 MIMO
5GHz WLAN802.11ax 3×3 MU-MIMO
Antennas3
Antenna Spec2 x External Detachable + 1 x 5GHz Internal PIFA
2.4GHz Antenna Gain2.6dBi
5GHz Antenna Gain2.7dBi
2.4GHz Max. Link Rate574Mbps
5GHz Max. Link Rate2402Mbps
Max. Number of SSIDs per band8
Security ModeOWE, WEP, WPA, WPA2, Mixed (WPA+WPA2), WPA3, Mixed (WPA2+WPA3)
AuthenticationPre-Shared Key, 802.1x
WiFi 6
OFDMA
RoamingAssisted Roaming
WPSPIN, PBC
WDSRepeater
Access ControlAccess List, Client Isolation, Hide SSID, Wi-Fi Scheduling
AirTime Fairness
Band Steering
WMM
Mesh (5GHz only)Root

[DISPLAY OFF] —– MOBILE VIEW

Wireless LAN (ax model)
2.4GHz WLAN:
802.11ax 2×2 MIMO
5GHz WLAN:
802.11ax 3×3 MU-MIMO
Antennas3
Antenna Type:
2 x External Detachable +
1 x 5GHz Internal PIFA
2.4GHz Gain:
2.6dBi
5GHz Gain:
2.7dBi
2.4GHz Max. Link Rate:
574Mbps
5GHz Max. Link Rate:
2402Mbps
Max. Number of
SSIDs per band
8
Security Mode:
OWE, WEP, WPA, WPA2,
Mixed (WPA+WPA2), WPA3
Mixed (WPA2+WPA3)
Authentication:
Pre-Shared Key, 802.1x
WiFi 6
OFDMA
Roaming:
Assisted Roaming
WPS:
PIN, PBC
WDS:
Repeater
Access Control:
Access List, Client Isolation,
Hide SSID, Wi-Fi Scheduling
AirTime Fairness
Band Steering
WMM
Mesh (5GHz only):
Root

Management (gDisplayOff)

Management
Local ServiceHTTP, HTTPS, Telnet, SSHv2, FTP, TR-069
Port Knocking for Local Service
Config File Export & Import
Firmware UpgradeWUI, TFTP, TR-069
Access ControlAccess List, Brute Force Protection
Notification AlertSMS, E-mail
SNMPv1, v2c, v3
Syslog
Virtual AP Controller (Device up to)20
Mesh (Number of manageable APs)7
Virtual Switch Controller5
Managed by VigorACSSince f/w v5.3.5

[DISPLAY OFF] —– MOBILE VIEW

Management
Local Service:
HTTP, HTTPS, Telnet, SSH v2, FTP,
TR-069
Port Knocking
for Local Service
Config File
Export & Import
Firmware Upgrade:
WUI, TFTP, TR-069
Access Control:
Access List, Brute Force Protection
Notification Alert:
SMS, E-mail
SNMP:
v1, v2c, v3
Syslog
Virtual AP Controller
(Device up to):
20 x VigorAPs
Mesh
(Number of manageable APs):
7 x VigorAPs (ax model)
Virtual Switch Controller:
5 x VigorSwitches
Managed by
VigorACS
Since f/w v5.3.5

Physical (gDisplayOff)

Physical
Power SupplyDC 12V @ 1.7A
Max. Power Consumption20.5 watts
Dimension207mm x 131mm x 42mm
Weight???g
Operating Temperature0 to 45°C
Storage Temperature-25 to 70°C
Operating Humidity (non-condensing)10 to 90%

[DISPLAY OFF] —– MOBILE VIEW

Physical
Power Supply:
DC 12V @ 0.9A (Vigor2136)
DC 12V @ 1.5A (Vigor2136ax)
Max. Power Consumption:
10 watts (Vigor2136)
18 watts (Vigor2136ax)
Dimension:
207mm x 131mm x 42mm
Weight:
452g (Vigor2136)
508g (Vigor2136ax)
Operating Temperature:
0 to 45°C
Storage Temperature:
-25 to 70°C
Operating Humidity
(non-condensing):
10 to 90%

Note :

  • All specifications are subject to change without notice.
  • The throughput figures are maximum, based on DrayTek internal testing with optimal conditions. The actual performance may vary depending on the different network conditions and applications activated.

Reviews

DrayTek Vigor2135ax Review Published in APC Magazine Issue 523 – Sep 2023