2.5GbE Dual-WAN High-Speed Security Router with 4G Cellular
The Vigor2136ax-4G delivers reliable, ultra-fast connectivity with built-in 4G LTE support. Featuring embedded dual SIM slots (one active at a time), it provides seamless network redundancy to ensure uninterrupted cellular access. An integrated 2.5GbE WAN port handles high-speed wired performance, while Wi-Fi 6 (802.11ax) guarantees stable wireless connections, even in dense device environments.
Designed for mission-critical reliability, the router supports Ethernet WAN or Wi-Fi WAN alongside 4G LTE. Dual-WAN load balancing and automated failover, complete with configurable per-WAN weight control, keep your business connected without interruption.
The Vigor2136ax-4G also offers a robust suite of enterprise security and networking tools, including Route Policy, App-based QoS, IP/URL Filtering, SPI Firewall, Port Knocking, Tag-based VLAN, up to 16 VPN tunnels, and advanced traffic management. This makes it an ideal, all-in-one networking solution for offices, retail stores, and branch sites.
Interface

Key Features
[DISPLAY OFF] —– MOBILE VIEW
Multi-Gigabit Router

Faster Wired Connections
- 4K video streaming
- Online Gaming
- Large file transfers
- Network-attached storage (NAS) devices etc
Beyond Gigabit
With internet speeds of up to 2.5 Gbps, users can fully utilize the available bandwidth.
4G Router with High Speed Mobile Connectivity
- Equipped with an integrated 4G LTE Cat.6 modem, the router supports carrier aggregation to deliver high-speed mobile broadband connectivity for reliable internet access and VPN services.
- The dual-SIM slot design allows the use of two mobile network providers. If the primary mobile network becomes unavailable, the router can automatically switch to the secondary SIM to maintain continuous cellular connectivity.
- With two external 4G cellular antennas, users can flexibly position the antennas to achieve optimal signal reception, even in challenging installation environments.

Effortless and Secure VPN Access with EasyVPN
Setting up a VPN can often be complex, involving protocol selection, manual configurations, and troubleshooting, especially for non-technical users. While Vigor routers support advanced VPN protocols such as IPsec, WireGuard, and OpenVPN, traditional setup methods can be time-consuming and daunting.
EasyVPN simplifies this process by offering a streamlined, hassle-free solution for secure remote connectivity. With EasyVPN, users can quickly establish encrypted connections without the need to:
- Manually generate WireGuard keys
- Import OpenVPN configuration files
- Upload certificates
By automating these steps, EasyVPN delivers a fast, secure, and intuitive VPN experience, perfect for businesses and users who want robust protection without the technical complexity.

Stealth Security Protection with Port Knocking
DrayTek’s Port Knocking technology adds an advanced stealth security layer by keeping critical network services completely invisible to unauthorised users. Instead of exposing management ports or VPN services to the public internet, Port Knocking requires a predefined “knock” sequence before access is granted, ensuring that only trusted users can discover and use these services.
By integrating three powerful functions, Port Knocking provides robust protection against port scanning, brute-force attacks, and unauthorised access.
Port Redirection
- Conceal real service ports from the public internet
- Redirect unauthorised requests to non-existent services to prevent detection

Secure Router Management Access
- Allow router management access only after a successful knock sequence or through a secure internal server
- Completely eliminate direct exposure of the management interface to the open internet
VPN Service Control (WAN Binding)
- Keep VPN services invisible until the correct knock sequence is received
- Bind VPN availability to specific WAN interfaces and authorised IP addresses
How It Works
- By default, all protected ports remain closed and undetectable
- After the correct knock sequence is received, selected ports open temporarily for authorised access
- Once the configured time window expires, services automatically return to hidden mode
With DrayTek Port Knocking, your network operates in stealth mode, invisible to attackers yet instantly accessible to authorised administrators and remote users. It is the ideal solution for organisations that demand high-level security without compromising accessibility.
Secure network with VPN
Vigor2136 supports the most secure VPN protocols:



Hardware NAT & Routing
With hardware acceleration enabled, the Vigor2136 Series’ NAT throughput can reach 2.3Gbps while still meeting the requirements of QoS. Business-critical apps can be prioritised over other apps.
LAN (2.5GbE) to WAN 1
2.3 Gbps
LAN (1GbE) to WAN 1
950 Mbps
LAN (2.5GbE) to WAN 1
2.3 Gbps
LAN (1GbE) to WAN 1
950 Mbps
Vigor2136ax-4G: 2.5GbE Dual-WAN Router with AX3000 Wi-Fi 6

The Vigor2136ax-4G is a 2×2 dual-band Wi-Fi 6 dual-WAN router featuring 160MHz channel bandwidth and 1024-QAM modulation for significantly boosted wireless speeds. It achieves theoretical throughput of up to 3,000 Mbps, delivering up to 574 Mbps on the 2.4GHz band and 2,402 Mbps on the 5GHz band, making it up to 2.5 times faster than standard 802.11ac 2×2 dual-band routers. For uninterrupted uptime, it supports dual-WAN load balancing and failover with configurable per-WAN weight controls for primary and failover connections.
Packed with business-grade features, including URL Reputation, Route Policy, App-based QoS, and advanced management tools, the Vigor2136ax-4G is the ideal solution for prosumers, smart homes, and SOHO users who want to take full control of their network.
OFDMA (Orthogonal Frequency Division Multiple Access).
With OFDMA modulation scheme, each channel is made up of 256 subcarriers spaced 78.125 kHz apart, compared to 64 subcarriers spaced 312.5 kHz apart with OFDM. With up to 4 times data efficiency and more advanced channel sharing technologies, a device can be allotted bandwidth based on the assessed needs for the highest airtime efficiency possible. For example, users on streaming or VoIP services can be allocated more bandwidth and time, while services such as email or website browsing can be assigned less bandwidth that are still sufficient for the tasks, thus improving user experience in high-density environments.

MU-MIMO

BSS Colouring Instead of CSMA/CA which allows only one device to transmit at a time, 802.11ax uses BSS Colouring to manage collision avoidance. Each Wi-Fi device is assigned a Basic Service Set (BSS), a 6-bit colour field, while adjacent devices are allocated with different colours. Before transmitting, the device checks the BSS and backs off only when the BSS is of the same colour as its own. In this way, the spectral efficiency is maximized as APs and Wi-Fi clients can transmit simultaneously even if they are on the same channel.

TWT (Target wake time)
Devices negotiate with the AP for a Target Wake Time (TWT), or joint a TWT broadcast session, and transmit data only when the TWT arrives, thereby reducing power consumption and increase network efficiency.

WPA3 (Wi-Fi Protected Access 3) enhances the security of Wi-Fi networks by addressing vulnerabilities in previous standards (WEP, WPA and WPS2) and introduces new features including stronger authentication, better encryption, and improved protection against attacks such as brute-force password guessing and man-in-the-middle exploits.
DrayTek’s Wi-Fi 6 encryption:
- WEP (64 / 128-bit)
- WPA / WPA2 / WPA3 / OWE
The comparison table below compares security design of Wi-Fi security protocols WEP, WPA, WPA2 and WPA3.
| WEP | WPA | WPA2 | WPA3 | |
|---|---|---|---|---|
| Encryption | RC4 | TKIP / RC4 | AES-CCMP | AES-CCMP / AES-GCMP |
| Session Key | 64/128 bit | 128 bit | 128 bit | 128/256 bit |
| Authentication | Open system, shared key | Pre-shared key | Pre-shared key | AES-CCMP / AES-GCMP |
| Level of Security | Very low | low | Moderate | High |
[DISPLAY OFF] —– MOBILE VIEW
| WEP | WPA | WPA2 | WPA3 | |
|---|---|---|---|---|
| Encryption | RC4 | TKIP / RC4 | AES- CCMP | AES- CCMP / AES- GCMP |
| Session Key | 64/128 bit | 128 bit | 128 bit | 128/256 bit |
| Authentication | Open system, shared key | Pre- shared key | Pre- shared key | AES- CCMP / AES- GCMP |
| Level of Security | Very low | low | Moderate | High |
| Encryption | WEP: RC4 WPA: TKIP / RC4 WPA2: AES-CCMP WPA3: AES-CCMP / AES-GCMP |
| Session Key | WEP: 64/128 bit WPA: 128 bit WPA2: 128 bit WPA3: 128/256 bit |
| Authentication | WEP: Open system, shared key WPA: Pre-shared key WPA2: Pre-shared key WPA3: AES-CCMP / AES-GCMP |
| Level of Security | WEP: Very low WPA: low WPA2: Moderate WPA3: High |
URL Reputation
URL Reputation is a cloud-based threat intelligence service that adds an extra layer of security to protect LAN clients during their online activities.
With a total of 82 content categories, including 10 security-focused ones, it provides comprehensive and up-to-date protection for both home and business networks.
These categories cover a wide range of areas—from malware, spyware, and adware, to parental controls, business productivity, and social networking—helping to create a safer online environment, enhance employee productivity, and support efficient bandwidth management.

IP Reputation
Every internet communication involves source and destination IP addresses. Cybercriminals often exploit known malicious IPs to launch attacks using various techniques, including:
- Botnets
- TOR nodes and anonymous proxies
- Command-and-Control (C2) servers
- Phishing servers
- Distributed Denial of Service (DDoS) attacks

IP Reputation helps identify and block traffic from these high-risk IP addresses, adding an essential layer of network protection against cyber threats.
Blocking communication with malicious IP addresses is critical for network security. However, relying on static blocklists is no longer effective, as they lack the real-time, predictive intelligence needed to combat evolving threats. The IP Reputation Service addresses this challenge by delivering dynamic, real-time scoring and classification of IP addresses. It enables the automatic blocking of:
- High-risk traffic
- Suspicious proxies
- Malware distributors
- IPs associated with recent malicious activity
The system evaluates IPs based on multiple factors, including infection history, protocol behaviour, and attack frequency. Each IP is assigned a reputation score, which determines whether it should be trusted, monitored, or blocked, ensuring proactive and intelligent network protection.
IAM (Identity and Access Management)
Vigor2136 Series with the new DrayOS5 is Zero Trust ready!
IAM (Identity and Access Management) is a cybersecurity system that controls user access by managing digital identities, authentication, and authorisation, to ensure correct access to network resources such as applications and devices.

With processes including identifying, authenticating, authorising users or groups, and assigning appropriate levels of access, IAM enhances both security management and the user experience and plays an important role in cloud-based services.
The IAM solution from Vigor2136 is Zero Trust Ready, and allows you to grant and categorize user privileges, create and manage access policies, and define large-scale group policies that integrate multiple filtering rules and traffic-shaping settings.
Users & Groups
- User accounts and user groups allow flexible access level control.
- Existing external authentication server is supported.
- User and MFA protection can be easily configured.

Access Policies
System administrators can create access policies for the local users in this tab. The access policies can be configured based on:
- MAC address filter list
- The allowed / blocked user list
- The login sessions lifetime
Access policies can be combined to create a robust security framework for your system.

Group Policies
Group policies can be configured for predefined local resources such as employees, workstations, network printers, and local servers. Network Firewall and traffic shaping policies can be configured to enhance network security and optimise traffic flows.
Conditional Access Policy
Conditional access policies can be configured to request users to provide multiple forms of authentication before granting appropriate access to a resource.
- Specify a period for the user to re-authenticate
- Restrict access to specific source IP addresses or ranges of IP addresses
- Specify VLAN-based access level in your conditional policies
- Set up time schedules when users are allowed to log-in

Resources Tab
Configure local resources such as IP and Mac addresses for workstations, network printers, PBX systems, NVR systems, servers, etc.
Backup and Restore
Backup or restore router settings such as Users and Groups, Access and Group Policies, etc. A Password protection can be applied before backup or restore.

Seamless Wi-Fi Roaming

Fast & Smooth Handover
Seamlessly switch between access points with intelligent roaming support.Supports both Over-the-DS (via wired backbone) and Over-the-Air handoffs, ensuring reliable connectivity for video calls, voice communications, and real-time applications.
Smarter Assisted Roaming
Configurable signal thresholds and AP steering guide devices to stronger access points and help balance network loads.
Enjoy stable, consistent performance across all devices everywhere.
Always Optimized for Business
From offices to campuses, seamless roaming delivers uninterrupted mobility.Built to provide reliable coverage for the demands of modern workplaces.
Mesh Wi-Fi
Vigor2136ax-4G supports up to 7 APs, which can form one or more Wireless Groups. Each group can form Mesh links automatically based on the optimum signal level among the APs and devices.



Hotspot Web Portal
Market your business while offering free Wi-Fi

Wi-Fi Marketing
Redirect hotspot guests to the company homepage, online surveys, or display a promotion message.
Grow Customer Mailing List
Require guests to leave contact info or social media accounts before they can use the Internet services.
Various Authentication Types
Various login methods are supported to meet your business needs, including Facebook Login, Google Login, SMS PIN, and RADIUS.
3rd-Party Service Compliant
Supports external captive portal authentication so you can keep using the Wi-Fi marketing solution you prefer.
Data Quota Management
Bandwidth management is integrated into the Hotspot features to control the bandwidth and session usage of the Hotspot guests.
LAN Management
The LAN Management platform allows easy and flexible configuration for Vigor devices on the LAN side, supporting up to 20 VigorAPs (including a root AP) and 5 VigorSwitches.
Automatic Device Discovery
Just connect new devices such as Vigor Switches or APs to the LAN port, Vigor2136 will auto-configure the new devices into the network.

Provisioning
New devices such as Vigor Switch/AP can be configured into the network automatically.
Monitoring
A summarized view of the network at the same page allows fast monitoring of all devices in the network.
System Maintenance
Tasks such as factory reset, backup and restore of configuration settings, or remote reboot can be performed from the Vigor routers, without needing to log in to the devices’ management pages.
Management Solution
On-Device Network Management with DrayTek Virtual Controller
The DrayTek Virtual Controller is a built-in management platform available on supported routers and firewalls.
It delivers centralised network control without cloud dependency, helping reduce data exposure risks while
enhancing security and privacy.
Wireless Management
- Mesh Controller – Easily build and manage wireless mesh networks with auto-routing and self-healing capabilities.
- AP Management (APM) – Automatically discover, configure, and monitor connected VigorAPs, making it simple to deploy multiple APs with unified settings.
Switch Management
- Central Switch Manager (SWM) – Detect and manage supported VigorSwitches, push configurations, monitor device status, and apply VLAN or QoS policies, all from a single local interface.
Unified Mesh & AP Management
The Virtual Controller offers two modes, providing flexibility for different deployment needs.

Mash Mode
Automatically creates a self-healing wireless mesh with the Vigor2136 Series as the Root AP and up to 7 Node APs, delivering simple, scalable, and reliable Wi-Fi coverage.
AP Management Mode
For networks with more than 8 APs, the Virtual Controller automatically switches to AP Management Mode, allowing centralised management of up to 20 APs directly through the router’s interface.
Seamless Mesh Role Assignment
When powered on, devices automatically discover each other and assign roles as Root or Node Aps, no manual setup required. This streamlined process enables rapid mesh network formation with optimised coverage and self-healing reliability.

SWM (Switch Management)
The Vigor2136 Series can operate as a master controller to centrally manage and monitor up to 5 switches. It also provides visibility into connected PD devices behind the switches, such as IP cameras and access points.

Device Management
Easily monitor switch status, firmware versions, and uptime across all managed devices from a single interface.

Port Profile
Create and apply multiple port profiles to configure PoE, VLAN, QoS, and other settings across selected switches with ease.

Maintenance
Easily perform configuration backup and restore, remote reboots, or full factory resets.
Unified Mesh & AP Management
The Virtual Controller offers two modes, providing flexibility for different deployment needs.

Mash Mode
Automatically creates a self-healing wireless mesh with the Vigor2136 Series as the Root AP and up to 7 Node APs, delivering simple, scalable, and reliable Wi-Fi coverage.
AP Management Mode
For networks with more than 8 APs, the Virtual Controller automatically switches to AP Management Mode, allowing centralised management of up to 20 APs directly through the router’s interface.
Seamless Mesh Role Assignment
When powered on, devices automatically discover each other and assign roles as Root or Node Aps, no manual setup required. This streamlined process enables rapid mesh network formation with optimised coverage and self-healing reliability.

SWM (Switch Management)
The Vigor2136 Series can operate as a master controller to centrally manage and monitor up to 5 switches. It also provides visibility into connected PD devices behind the switches, such as IP cameras and access points.

Device Management
Easily monitor switch status, firmware versions, and uptime across all managed devices from a single interface.

Port Profile
Create and apply multiple port profiles to configure PoE, VLAN, QoS, and other settings across selected switches with ease.

Maintenance
Easily perform configuration backup and restore, remote reboots, or full factory resets.
Wireless Management Solution

Mesh (ax model)
Up to 7 APs
- DrayTek Wireless app-support
- Discovery
- Auto-Provisioning
- Monitoring
- Centralized Hierarchy View

Virtual AP Controller
Up to 9 VigorAPs
- Auto-Discovery
- Auto-Provisioning
- Monitoring
- Centralized View
- Alarm
- Reboot VigorAP Remotely
- Wi-Fi Client Load Balancing

Device Management
View and Configure VigorAPs
- Device List
- Mesh Status
- AP Adoption
Switch Management Solution

SWM (Switch Management)
The Vigor2136 Series can operate as a master controller to centrally manage and monitor up to 5 switches. It also provides visibility into connected PD devices behind the switches, such as IP cameras and access points.

Device Management
Easily monitor switch status, firmware versions, and uptime across all managed devices from a single interface.

Port Profile
Create and apply multiple port profiles to configure PoE, VLAN, QoS, and other settings across selected switches with ease.

Maintenance
Easily perform configuration backup and restore, remote reboots, or full factory resets.
Software Management
VigorACS 3

- Zero Touch Deployment & Provisioning
- Auto VPN
- Interface Quality & SLA
- VoIP Optimization & Monitoring
- Application Visibility
- Application Based SD-WAN Policy
- Customized Hotspot Page with Multilingual
- Hotspot Clients Analytics
- ACS Server Load Balancing / Failover
In-the-Box

Vigor2136ax-4G

Cellular Antenna x 2

Wi-Fi Antenna x 2

RJ-45 Cable
(Ethernet)

Power Adaptor

Quick Start Guide
Note :
The throughput figures are maximum, based on DrayTek internal testing with optimal conditions. The actual performance may vary depending on the different network conditions and applications activated.
Models
| Model | Vigor2136 | Vigor2136ax | Vigor2136ax-4G |
|---|---|---|---|
| Product | ![]() | ![]() | ![]() |
| Gigabit WAN | 1 x 2.5 GbE | 1 x 2.5 GbE | 1 x 2.5 GbE |
| Selectable Gigabit WAN/LAN | 1 x 2.5 GbE | 1 x 2.5 GbE | 1 x 2.5 GbE |
| 4G LTE | 2 x USB 2.0 | 2 x USB 2.0 | 2 x nano SIM slots (SIM slot 2 for Failover) 1 x USB 2.0 |
| Wireless WAN | |||
| Gigabit LAN | 3 | 3 | 3 |
| VPN Tunnels | 16 | 16 | 16 |
| Wireless LAN | WiFi 6, AX3000 | WiFi 6, AX3000 | |
| Wi-Fi Antenna | 2.7dBi for 5GHz 2.6dBi for 2.4GHz | 2.7dBi for 5GHz 2.6dBi for 2.4GHz | |
| VoIP (2xFXS) |
Specifications
Interface (gDisplayOff)
| Interface | |
|---|---|
| WAN Port | 1 x 2.5 GbE |
| Selectable Gigabit WAN/LAN | 1 x 2.5 GbE |
| LAN Port | 3 x Gigabit Ethernet |
| SIM Slot | 2 x nano SIM slots (SIM slot 2 for Failover) |
| USB Port | 1 x USB 2.0 for 4G/LTE USB modem, storage, printer or thermometer |
| Wi-Fi Antenna | 2x External Dipole, Gain: 2.7 dBi for 5GHz, 2.6 dBi for 2.4GHz (ax model) |
| 2.4G WLAN | 802.11ax 2×2 MIMO, up to 574Mbps Link Rate (ax model) |
| 5G WLAN | 802.11ax 2×2 MU-MIMO, up to 2402Mbps Link Rate (ax model) |
[DISPLAY OFF] —– MOBILE VIEW
| Interface |
|---|
| WAN Port: 1 x 2.5GbE |
| Selectable Gigabit WAN/LAN: 1 x 2.5GbE |
| LAN Port: 3 x Gigabit Ethernet |
| SIM Slot: 2 x nano SIM slots (SIM slot 2 for Failover) |
| USB Port: 1x USB 2.0 for 4G/LTE USB modem, storage, printer or thermometer |
| Wi-Fi Antenna: 2 x External Dipole Gain: 2.7 dBi for 5GHz, 2.6 dBi for 2.4GHz (ax model) |
| 2.4G WLAN: 802.11ax 2×2 MIMO, up to 574Mbps Link Rate (ax model) |
| 5G WLAN: 802.11ax 2×2 MU-MIMO, up to 2402Mbps Link Rate (ax model) |
Performance (gDisplayOff)
| Performance | |
|---|---|
| NAT Throughput w/ Hardware Acceleration | 2300 Mbps |
| IPsec VPN Performance | 390 Mbps (AES 256 bits) |
| Wireguard VPN Throughput | 90 Mbps |
| Max. Number of NAT Sessions | 50,000 |
| Max. Concurrent VPN Tunnels (including OpenVPN/ SSL-VPN/Wireguard) | 16 |
[DISPLAY OFF] —– MOBILE VIEW
| Performance |
|---|
| NAT Throughput w/ Hardware Acceleration: 2300 Mbps |
| IPsec VPN Performance: 390 Mbps (AES 256 bits) |
| Wireguard VPN Throughput: 90 Mbps |
| Max. Number of NAT Sessions: 50,000 |
| Max. Concurrent VPN Tunnels (including OpenVPN/ SSL-VPN/Wireguard): 16 |
4G LTE (gDisplayOff)
| 4G | |
|---|---|
| LTE Category | CAT.6 |
| LTE Antenna (External Dipole) | 2 |
| Max. Rx Link Rate | 300 Mbps |
| Max. Tx Link Rate | 50 Mbps |
| FDD Band | 1 (2100MHz), 20 (800MHz), 28 (700MHz), 3 (1800MHz), 7 (2600MHz), 8 (900MHz) |
| TDD Band | 38 (2600MHz), 40 (2300MHz) |
| WCDMA (3G) Band | 1, 8 |
| 4G |
|---|
| LTE Category : CAT.6 |
| LTE Antenna (External Dipole) : 2 |
| Max. Rx Link Rate: 300 Mbps |
| Max. Tx Link Rate: 50 Mbps |
| FDD Band : 1 (2100MHz), 20 (800MHz), 28 (700MHz), 3 (1800MHz), 7 (2600MHz), 8 (900MHz) |
| TDD Band : 38 (2600MHz), 40 (2300MHz) |
| WCDMA (3G) Band : 1, 8 |
Internet Connection (gDisplayOff)
| Internet Connection | |
|---|---|
| IPv4 | PPPoE, DHCP, Static IP |
| IPv6 | PPP, DHCPv6, Static IPv6, TSPC, 6rd, 6in4 Static Tunnel |
| 802.1p/q Multi-VLAN Tagging | |
| Multi-VLAN/PVC | |
| 4G/LTE WAN with USB modem | |
| WAN Failover | |
| Connection Detection | ARP, Ping |
| WAN Data Budget | |
| Dynamic DNS | |
| DrayDDNS | |
[DISPLAY OFF] —– MOBILE VIEW
| Internet Connection | |
|---|---|
| IPv4: PPPoE, DHCP, Static IP | |
| IPv6: PPP, DHCPv6, Static IPv6, TSPC, 6rd, 6in4 Static Tunnel | |
| 802.1p/q Multi-VLAN Tagging | |
| Multi-VLAN/PVC | |
| 4G/LTE WAN with USB modem | |
| WAN Failover | |
| Connection Detection: ARP, Ping | |
| WAN Data Budget | |
| Dynamic DNS | |
| DrayDDNS | |
LAN Management (gDisplayOff)
| LAN Management | |
|---|---|
| VLAN | 802.1q Tag-based, Port-based |
| Max. Number of VLAN | 8 |
| Number of LAN Subnet | 4 |
| DHCP Server | Multiple IP Subnet, Custom DHCP Options, Bind-IP-to-MAC |
| Wired 802.1x Authentication | |
| Port Mirroring | |
| Local DNS Server | |
| Conditional DNS Forwarding | |
| Hotspot Web Portal | 2 |
| Hotspot Authentication | Click-Through, External Portal Server |
[DISPLAY OFF] —– MOBILE VIEW
| LAN Management | |
|---|---|
| VLAN: 802.1q Tag-based, Port-based | |
| Max. Number of VLAN: 8 | |
| Number of LAN Subnet: 4 | |
| DHCP Server: Multiple IP Subnet, Custom DHCP Options, Bind-IP-to-MAC | |
| Wired 802.1x Authentication | |
| Port Mirroring * Future Support | |
| Local DNS Server | |
| Conditional DNS Forwarding | |
| Hotspot Web Portal | 2 |
| Hotspot Authentication: Click-Through, External Portal Server | |
Networking (gDisplayOff)
| Networking | |
|---|---|
| Routing | IPv4 Static Routing, IPv6 Static Routing, Policy Route, Inter-VLAN Routing, RIP v1/v2, BGP, OSPF(V2/V3) |
| Policy-based Routing | Protocol, IP Address, Port |
| DNS Security (DNSSEC) | |
| Multicast | IGMP v2/v3, IGMP Proxy, IGMP Snooping & Fast Leave |
| Local RADIUS server | |
| SMB File Sharing | (Requires external storage) |
[DISPLAY OFF] —– MOBILE VIEW
| Networking | |
|---|---|
| Routing: IPv4 Static Routing, IPv6 Static Routing, Policy Route, Inter-VLAN Routing, RIP v1/v2, BGP, OSPF(V2/V3) | |
| Policy-based Routing: Protocol, IP Address, Port | |
| DNS Security (DNSSEC) | |
| IGMP: IGMP v2/v3, IGMP Proxy, IGMP Snooping & Fast Leave | |
| Local RADIUS server: | |
| SMB File Sharing: (Requires external storage) | |
VPN (gDisplayOff)
| VPN | |
|---|---|
| LAN-to-LAN | |
| Teleworker-to-LAN | |
| Protocols | IPsec, IKEv2, IKEv2-EAP, IPsec XAuth, OpenVPN, Wireguard |
| User Authentication | Local, RADIUS, TACACS+, mOTP, TOTP |
| IKE Authentication | Pre-Shared Key, X.509 |
| IPsec Authentication | SHA1, SHA256 |
| Encryption | DES, 3DES, AES128, AES192, AES256 |
| Single-Armed VPN | |
| NAT-Traversal (NAT-T) | |
| VPN Connection Status | |
| Backup & Restore | |
[DISPLAY OFF] —– MOBILE VIEW
| VPN | |
|---|---|
| LAN-to-LAN | |
| Teleworker-to-LAN | |
| Protocols: IPsec, IKEv2, IKEv2-EAP, IPsec-XAuth, OpenVPN, Wireguard | |
| User Authentication: Local, RADIUS, TACACS+, mOTP, TOTP | |
| IKE Authentication: Pre-Shared Key, X.509 | |
| IPsec Authentication: SHA1, SHA256 | |
| Encryption: DES, 3DES, AES128, AES192, AES256 | |
| Single-Armed VPN | |
| NAT-Traversal (NAT-T) | |
| VPN Connection Status | |
| Backup & Restore | |
Security (gDisplayOff)
| Security | |
|---|---|
| URL/IP Reputation | |
| Firewall Filter | IP, Content, Traffic |
| Port Knocking | |
| Defense Setup | ARP Spoofing, IP Spoofing |
| MAC Filtering Profile | |
| IPv6 Address Security | |
[DISPLAY OFF] —– MOBILE VIEW
| Security | |
|---|---|
| URL/IP Reputation | |
| Firewall Filter: IP, Content, Traffic | |
| Port Knocking | |
| Defense Setup: ARP Spoofing, IP Spoofing | |
| MAC Filtering Profile | |
| IPv6 Address Security | |
IAM (gDisplayOff)
| IAM | |
|---|---|
| Users & Groups | |
| Access Policies | |
| Group Policies | |
| Conditional Access Policy | |
| Resources | |
| Account Status* | |
| Backup and Restore | |
[DISPLAY OFF] —– MOBILE VIEW
| IAM | |
|---|---|
| Users & Groups | |
| Access Policies | |
| Group Policies | |
| Conditional Access Policy | |
| Resources | |
| Account Status | |
| Backup and Restore | |
Bandwidth Management (gDisplayOff)
| Bandwidth Management | |
|---|---|
| Traffic Shaping Policy | |
| IP-based Bandwidth Limit | |
| IP-based Session Limit* | |
| QoS (Quality of Service) | IP Address, Port, Application |
| APP QoS | |
| Default Policy | |
| VoIP Prioritization | |
[DISPLAY OFF] —– MOBILE VIEW
| Bandwidth Management | |
|---|---|
| Traffic Shaping Policy | |
| IP-based Bandwidth Limit | |
| QoS (Quality of Service): IP Address, Port, Application | |
| APP QoS | |
| Default Policy | |
| VoIP Prioritization | |
Wireless LAN (ax model) (gDisplayOff)
| Wireless LAN (ax model) | |
|---|---|
| 2.4GHz WLAN | 802.11ax 2×2 MIMO |
| 5GHz WLAN | 802.11ax 3×3 MU-MIMO |
| Antennas | 3 |
| Antenna Spec | 2 x External Detachable + 1 x 5GHz Internal PIFA |
| 2.4GHz Antenna Gain | 2.6dBi |
| 5GHz Antenna Gain | 2.7dBi |
| 2.4GHz Max. Link Rate | 574Mbps |
| 5GHz Max. Link Rate | 2402Mbps |
| Max. Number of SSIDs per band | 8 |
| Security Mode | OWE, WEP, WPA, WPA2, Mixed (WPA+WPA2), WPA3, Mixed (WPA2+WPA3) |
| Authentication | Pre-Shared Key, 802.1x |
| WiFi 6 | |
| OFDMA | |
| Roaming | Assisted Roaming |
| WPS | PIN, PBC |
| WDS | Repeater |
| Access Control | Access List, Client Isolation, Hide SSID, Wi-Fi Scheduling |
| AirTime Fairness | |
| Band Steering | |
| WMM | |
| Mesh (5GHz only) | Root |
[DISPLAY OFF] —– MOBILE VIEW
| Wireless LAN (ax model) | |
|---|---|
| 2.4GHz WLAN: 802.11ax 2×2 MIMO | |
| 5GHz WLAN: 802.11ax 3×3 MU-MIMO | |
| Antennas | 3 |
| Antenna Type: 2 x External Detachable + 1 x 5GHz Internal PIFA | |
| 2.4GHz Gain: 2.6dBi | |
| 5GHz Gain: 2.7dBi | |
| 2.4GHz Max. Link Rate: 574Mbps | |
| 5GHz Max. Link Rate: 2402Mbps | |
| Max. Number of SSIDs per band | 8 |
| Security Mode: OWE, WEP, WPA, WPA2, Mixed (WPA+WPA2), WPA3 Mixed (WPA2+WPA3) | |
| Authentication: Pre-Shared Key, 802.1x | |
| WiFi 6 | |
| OFDMA | |
| Roaming: Assisted Roaming | |
| WPS: PIN, PBC | |
| WDS: Repeater | |
| Access Control: Access List, Client Isolation, Hide SSID, Wi-Fi Scheduling | |
| AirTime Fairness | |
| Band Steering | |
| WMM | |
| Mesh (5GHz only): Root | |
Management (gDisplayOff)
| Management | |
|---|---|
| Local Service | HTTP, HTTPS, Telnet, SSHv2, FTP, TR-069 |
| Port Knocking for Local Service | |
| Config File Export & Import | |
| Firmware Upgrade | WUI, TFTP, TR-069 |
| Access Control | Access List, Brute Force Protection |
| Notification Alert | SMS, E-mail |
| SNMP | v1, v2c, v3 |
| Syslog | |
| Virtual AP Controller (Device up to) | 20 |
| Mesh (Number of manageable APs) | 7 |
| Virtual Switch Controller | 5 |
| Managed by VigorACS | Since f/w v5.3.5 |
[DISPLAY OFF] —– MOBILE VIEW
| Management | |
|---|---|
| Local Service: HTTP, HTTPS, Telnet, SSH v2, FTP, TR-069 | |
| Port Knocking for Local Service | |
| Config File Export & Import | |
| Firmware Upgrade: WUI, TFTP, TR-069 | |
| Access Control: Access List, Brute Force Protection | |
| Notification Alert: SMS, E-mail | |
| SNMP: v1, v2c, v3 | |
| Syslog | |
| Virtual AP Controller (Device up to): 20 x VigorAPs | |
| Mesh (Number of manageable APs): 7 x VigorAPs (ax model) | |
| Virtual Switch Controller: 5 x VigorSwitches | |
| Managed by VigorACS Since f/w v5.3.5 | |
Physical (gDisplayOff)
| Physical | |
|---|---|
| Power Supply | DC 12V @ 1.7A |
| Max. Power Consumption | 20.5 watts |
| Dimension | 207mm x 131mm x 42mm |
| Weight | ???g |
| Operating Temperature | 0 to 45°C |
| Storage Temperature | -25 to 70°C |
| Operating Humidity (non-condensing) | 10 to 90% |
[DISPLAY OFF] —– MOBILE VIEW
| Physical | |
|---|---|
| Power Supply: DC 12V @ 0.9A (Vigor2136) DC 12V @ 1.5A (Vigor2136ax) | |
| Max. Power Consumption: 10 watts (Vigor2136) 18 watts (Vigor2136ax) | |
| Dimension: 207mm x 131mm x 42mm | |
| Weight: 452g (Vigor2136) 508g (Vigor2136ax) | |
| Operating Temperature: 0 to 45°C | |
| Storage Temperature: -25 to 70°C | |
| Operating Humidity (non-condensing): 10 to 90% |
Note :
- All specifications are subject to change without notice.
- The throughput figures are maximum, based on DrayTek internal testing with optimal conditions. The actual performance may vary depending on the different network conditions and applications activated.
Reviews
DrayTek Vigor2135ax Review Published in APC Magazine Issue 523 – Sep 2023







