Threat Protection

Threat Protection2026-06-29T15:19:27+10:00

Threat Protection

AI-Assisted Edge Firewall with Cloud Intelligence

Threat Protection

AI-Assisted Edge Firewall with Cloud Intelligence

Secure the Perimeter. Protect Every Device. Simplify Your Security.

In an era of evolving cyber threats, traditional defences are no longer enough. DrayTek Threat Protection is an AI-driven, cloud-enhanced security service integrated directly into selected Vigor routers. It provides enterprise-grade protection for your router, local network, and every connected device, without the complexity or high costs of traditional security appliances.

Why Choose DrayTek Threat Protection?

DrayTek bridges the gap between sophisticated security and operational simplicity. By combining gateway-based enforcement with real-time cloud intelligence, we provide a shield that learns and adapts to new threats.

AI-Assisted DetectionUses behaviour-based analysis to identify threats that traditional signature-based tools may miss
Agentless ProtectionSecures computers, mobile phones, and IoT devices without requiring software installation on every endpoint
Encrypted Traffic SafetyEffectively identifies threats hidden within encrypted traffic without the performance impact of full SSL inspection

[DISPLAY OFF] —– MOBILE VIEW

AI-Assisted Detection
Uses behaviour-based analysis to
identify threats that traditional
signature-based tools may miss
Agentless Protection
Secures computers, mobile phones,
and IoT devices without requiring
software installation on every
endpoint
Encrypted Traffic Safety
Effectively identifies threats hidden
within encrypted traffic without
the performance impact
of full SSL inspection

DrayTek Security Solutions Comparison

Key FeaturesRouter
(Manual setup)
Router + URL/IP Reputation Key
(Manual setup)
Router + Threat
Protection
(Sentry/Guardian)

(AI-assisted)
Network Protection
DoS/Flood Defense
(With Anti-DDoS)
Port Scan Blocker
Brute Force Protection
Device Detection & Identification
Device Exploit Hot Patching & Command Injection Protection
Anomaly Detection
Web & Content Security
Content Filtering
URL/IP Reputation
Automation
Automated Policy Enforcement

[DISPLAY OFF] —– MOBILE VIEW

Router
(Manual setup)
Network Protection
DoS/Flood Defense
Port Scan Blocker
Brute Force Protection
Device Detection &
Identification
Device Exploit Hot
Patching & Command
Injection Protection
Anomaly Detection
Web & Content Security
Content Filtering
URL/IP Reputation
Automation
Automated Policy
Enforcement
Router +
URL/IP Reputation Key

(Manual setup)
Network Protection
DoS/Flood Defense
Port Scan Blocker
Brute Force Protection
Device Detection &
Identification
Device Exploit Hot
Patching & Command
Injection Protection
Anomaly Detection
Web & Content Security
Content Filtering
URL/IP Reputation
Automation
Automated Policy
Enforcement
Router +
Threat Protection
(Sentry/Guardian)

(AI-assisted)
Network Protection
DoS/Flood Defense
(With Anti-DDoS)
Port Scan Blocker
Brute Force Protection
Device Detection &
Identification
Device Exploit Hot
Patching & Command
Injection Protection
Anomaly Detection
Web & Content Security
Content Filtering
URL/IP Reputation
Automation
Automated Policy
Enforcement

DrayTek Security Solutions Comparison

Router + URL/IP Reputation Key (Manual setup)
Network Protection
DoS/Flood Defense
Port Scan Blocker
Brute Force Protection
Device Detection & Identification-
Device Exploit Hot Patching & Command Injection Protection-
Anomaly Detection-
Web & Content Security
Content Filtering
URL/IP Reputation
Automation
Automated Policy Enforcement-
Router   (Manual setup)  
Network Protection
DoS/Flood Defense
Port Scan Blocker
Brute Force Protection
Device Detection & Identification-
Device Exploit Hot Patching & Command Injection Protection-
Anomaly Detection-
Web & Content Security
Content Filtering-
URL/IP Reputation-
Automation
Automated Policy Enforcement-

Key FeaturesRouter
(Manual setup)
Router + URL/IP Reputation Key
(Manual setup)
Router + Threat Protection Sentry/Guardian
(AI-assisted)
Network Protection
DoS/Flood Defense  (With Anti-DDoS)
Port Scan Blocker
Brute Force Protection
Device Detection & Identification
Device Exploit Hot Patching &
Command Injection Protection
Anomaly Detection
Web & Content Security
Content Filtering
URL/IP Reputation
Automation
Automated Policy Enforcement

Benefits & Business Outcomes

[DISPLAY OFF] —– MOBILE VIEW

Core Protection Layers

1. Router & Edge Security

The first line of defence. Hardens the network edge by mitigating DoS/DDoS attacks, detecting port scans, and blocking brute-force access attempts. Ensures maximum uptime and stability during active cyber-attacks.

2. Network & Device Monitoring

Provides total network visibility. Threat Protection automatically discovers and continuously monitors every device on your LAN. It instantly detects and isolates compromised or suspicious devices, preventing lateral movement of threats across the network.

2. Network & Device Monitoring

Provides total network visibility. Threat Protection automatically discovers and continuously monitors every device on your LAN. It instantly detects and isolates compromised or suspicious devices, preventing lateral movement of threats across the network.

3. IoT & Unmanaged Device Defence

Closes the “IoT gap” for devices that cannot run antivirus software (e.g., POS systems, IP cameras, printers). Uses behavioural anomaly detection to stop exploit and injection attacks at the network level.

4. Safe Browsing & Content Filtering

Blocks access to known phishing sites, malware hosts, botnet destinations, and ransomware command centres in real-time. Easily enforce acceptable-use policies with flexible, category-based filtering at the user or device level.

4. Safe Browsing & Content Filtering

Blocks access to known phishing sites, malware hosts, botnet destinations, and ransomware command centres in real-time. Easily enforce acceptable-use policies with flexible, category-based filtering at the user or device level.

Product Tiers & Supported Platforms

CategorySentryGuardian
Target EnvironmentSOHO / Small OfficesSMB / High-Density Branches
Supported ModelsVigor2136 / 2767 seriesVigor2867 / 2928 series
Supported FirmwareF/W 5.3.7 or laterFuture Support
Max. LAN DevicesUp to 100 devicesUp to 200 devices
DeploymentEdge Gateway + CloudEdge Gateway + Cloud

[DISPLAY OFF] —– MOBILE VIEW

Sentry
Target Environment
SOHO / Small Offices
Supported Models
Vigor2136 / 2767 series
Supported Firmware
F/W 5.3.7 or later
Max LAN Devices
Up to 100 devices
Deployment
Edge Gateway + Cloud
Guardian
Target Environment
SMB / High-Density Branches
Supported Models
Vigor2867 / 2928 series
Supported Firmware
Future Support
Max. LAN Devices
Up to 200 devices
Deployment
Edge Gateway + Cloud

Simple Deployment. Intelligent Operation

Zero-Touch Maintenance

Seamless Integration
Built into your Vigor router—no extra hardware required.

Automatic Updates
Security intelligence is constantly updated via the cloud to defend against the latest zero-day threats.

Minimal Setup
Policy-based configuration allows you to secure your office in minutes, not hours.

Actionable Visibility

Stop guessing about your network health. Our Unified Cloud Dashboard provides:

  • Real-time visibility into active threats and device status.
  • Comprehensive reports on security events and long-term trends.
  • Easy-to-understand metrics designed for business owners and MSPs alike.

Use Cases

Retail & POS

Protect payment systems and guest Wi-Fi from internal and external breaches.

Modern SMBs

Secure sensitive client data and financial transactions.

Interface

Featured Products

[DISPLAY OFF] Vigor2136 series

[DISPLAY OFF] Vigor2136ax-4G

[DISPLAY OFF] Vigor2767 series

[DISPLAY OFF] Vigor2928 series

FAQ

What is VigorShield?2026-05-13T09:41:27+10:00

DrayTek VigorShield is a comprehensive security system that protects business networks at the router level. Instead of offering security as isolated features, VigorShield integrates multiple gateway security services into one unified layer. Positioned at the network’s edge, it serves as a barrier, preventing threats from reaching internal network resources. The router, equipped with these security features, acts as the primary defence, safeguarding all connected devices, including PCs, servers, IoT devices, and unmanaged endpoints, without requiring additional agents or security hardware.

Is VigorShield a subscription service?2026-05-13T15:12:00+10:00

Currently, two subscription-based security services are available. The first, URL/IP Reputation, blocks access to known malicious destinations by assessing the reputation of URLs and IP addresses before allowing connections. This helps prevent threats such as malware, phishing, and command-and-control activities at the gateway.
The second security service is Threat Protection.

What is Threat Protection?2026-05-13T09:41:42+10:00

Threat Protection is an AI-assisted, cloud-based firewall system that is currently being released for DrayOS 5 routers. It is a subscription-based Software-as-a-Service (SaaS) product in DrayTek’s VigorShield offering, with advanced gateway-level security that safeguards networks and connected devices from emerging cyber threats through intelligent traffic analysis and threat detection at the network edge. It is built on DrayTek’s Edge-to-Cloud architecture, powered by intelligence from over 8 million networks and 500 million IoT devices.

What is the difference between VigorShield and Threat Protection?2026-05-13T09:41:51+10:00

VigorShield refers to DrayTek’s range of security system products, which includes the URL/IP Reputation product and the Threat Protection product.

What are Sentry and Guardian?2026-05-13T09:42:02+10:00

These are two tiers of Threat Protection for routers at two different levels. Sentry is designed for SOHO environments such as cafés, retail, and small offices, and runs on the Vigor2136 and Vigor2767 series routers, supporting up to 100 LAN devices. Guardian scales to SMB environments with higher device density, targeting higher-end routers such as the Vigor2867 and Vigor2928 series for up to 200 LAN devices. Both tiers share the same architecture and capabilities.

Do I need URL/IP Reputation as well as Threat Protection?2026-05-13T09:42:07+10:00

No. Threat Protection includes URL content filtering and IP reputation, so there is no need to purchase a separate subscription for these services.

How does Threat Protection protect IoT devices?2026-05-13T09:43:26+10:00

IoT (Internet of Things) devices, such as Smart Home Assistants, Smart Fridges, cameras, and Smartwatches, sometimes have vulnerabilities that can be exploited by cybercriminals to gain access to a network. Threat Protection guards against these attacks by identifying abnormal patterns in IoT traffic, stopping exploitation and injection attacks at the network level.

How can Threat Protection be managed?2026-05-13T09:43:52+10:00

For a single-site deployment, DrayTek has a single organisation portal, but for multi-site deployments, the MSP multi-tenant portal is available. This will be suitable for a managed service provider that has to manage several clients through a central portal.

Can Threat Protection block social networking websites?2026-05-13T09:44:35+10:00

Yes. The network administrator can restrict connected devices from accessing specific categories of websites via the Assets page in the portal. Different policies can be applied to individual users or user groups.

Which DrayTek routers are compatible with Threat Protection?2026-05-13T15:37:57+10:00

Currently, Sentry is compatible with Vigor2136 and Vigor2767 routers, while Guardian is available for Vigor2867 and Vigor2928 routers.

How many devices are supported?2026-05-13T15:36:58+10:00

Sentry, for Vigor2136 and Vigor2767 routers, supports up to 100 LAN devices. Guardian, for higher-end DrayOS 5 routers, supports up to 200 LAN devices.

How much does it cost?2026-05-19T14:56:52+10:00

Subscriptions are annual and start from less than 60 cents per day. Contact your friendly DrayTek reseller for accurate pricing today.
Note: There is a different licence package for Sentry and Guardian.

ProductCodeDescription
SentryDTP112SOne (1) year Threat Protection for Vigor2136/Vigor2767 series
GuardianDTP212GOne (1) year Threat Protection for Vigor2927/Vigor2867 series

 

How are Devices Counted within Threat Protection?2026-05-13T15:35:34+10:00

The number of devices seen on the router LAN is counted towards the total node count. Devices are tracked using each device’s MAC address.

What happens when the number of devices on the LAN is greater than the installed Threat Protection licence?2026-05-13T15:34:59+10:00

Threat Protection will continue to work; any additional devices over the licensed node count will not be protected.

What are the requirements to run Threat Protection on my network?2026-05-13T15:34:24+10:00

The main requirements to run Threat Protection on your network are:

  1. A compatible DrayOS 5 router, such as the Vigor2136, Vigor2767, Vigor2928, Vigor2867.
  2. The router must be running the latest firmware (Version 5.3.7.1 and above)
  3. A MyVigor account
  4. A valid Threat Protection licence key
  5. An Internet connection
Is a free trial available for Threat protection?2026-05-13T15:33:39+10:00

Yes, a free 30-day trial of Threat Protection is available. Please ensure you meet the requirements to run Threat Protection on your network.

How do I get a free Threat Protection trial?2026-05-21T13:49:52+10:00

To get a free 30-day trial of Threat Protection for your network, please contact our sales team at sales@draytek.com.au or complete the contact form below.  They will need the following information:

  1. Your details (Name / Email address)
  2. MyVigor details
  3. Router model
  4. Router LAN MAC address
How long does it take to activate Threat Protection?2026-05-13T15:30:33+10:00

This process usually takes 24 to 48 hours.

Getting Started

If you have any questions regarding VigorShield Threat Protection, you can use the Contact Sales form below to get answers or request more information.

Please tell us about your project and we will contact you ASAP.
Go to Top