We are experiencing high demand. Processing time may be longer than usual.   Learn more >

DrayTek Vigor2133Vac Gigabit VoIP 802.11ac Firewall VPN Router - NBN Ready
SKU# AC20156, Model# Vigor2133Vac

This Product is currently unavailable.

Customers also bought
Customers also viewed

SKU # AC20156 | Model # Vigor2133Vac

See an error? Click here and let us know

DrayTek Vigor2133Vac Gigabit VoIP 802.11ac Firewall VPN Router - NBN Ready - Built-in 802.11ac (AC1200) Wi-Fi up to 300+867Mbps - SIP VoIP (2x FXS) - 1x GbE WAN port with 1x USB port for 3.5G/4G Mobile Fail-Over, 4x GbE LAN ports with 30,000 NAT sessions and IPv6 - Object-based SPI Firewall, Content Security Management (CSM) and QoS - 2x VPN tunnels with 2x SSL VPN Tunnels - 2x USB for 3G/4G Backup, FTP server & network printers - 802.11b/g/n (2.4G), 802.11 a/n/ac (5G) - 2 Years Limited Warranty

Manufacturer Warranty: 2 Years Limited Warranty

· 1 x Gigabit Ethernet WAN port with 1 x USB port for 3.5G / 4G Mobile Fail-Over and 4 x Gigabit Ethernet LAN ports with 30,000 NAT sessions and IPv6
· Object-based SPI Firewall, Content Security Management (CSM) and QoS
· 2 x VPN tunnels including 2 x SSL VPN tunnels
· Built-in 802.11ac Wi-Fi (Vac/ac model) and SIP VoIP (2x FXS)
· NBN Ready to connect to NTD (Network Termination Device)

Vigor2133Vac Gigabit broadband router with SPI Firewall, 802.11ac (AC1200) Wi-Fi, VoIP and 2 x VPN tunnels including 2 x SSL-VPN tunnels

The DrayTek Vigor2133Vac high-performance router is designed for super-fast broadband networks. Features include 1x Gigabit Ethernet WAN port for Internet access and 3G/4G backup provided via the 2 USB ports by attaching a supported 3G/4G USB modem. The support of 802.1Q VLAN on WAN enables the router to provide triple-play services to your home network. Business-grade features include extensive Firewall with Content Filtering, VPN, Bandwidth Management, making the Vigor2133Vac router a perfect solution for home office and teleworkers.

Read more about DrayTek Vigor2133Vac Gigabit VoIP 802.11ac Firewall VPN Router - NBN Ready on the official DrayTek website


DrayTek Vigor2133Vac Gigabit VoIP 802.11ac Firewall VPN Router - NBN Ready - Desktop Overview 1

DrayTek Vigor2133Vac Gigabit VoIP 802.11ac Firewall VPN Router - NBN Ready - Desktop Overview 2

1. Built-in 802.11ac Wi-Fi (Vac/ac model)

The Vigor2133Vac router includes integrated 802.11ac dual-band Wi-Fi delivering wireless throughput up to 867 Mbps. Business-grade features include AirTime Fairness, Router-Assisted Roaming, and Band-Steering ensuring smooth wireless connections for HD videos, gaming, and internet phones.

DrayTek Vigor2133Vac Gigabit VoIP 802.11ac Firewall VPN Router - NBN Ready - Desktop Overview 3

2. Bandwidth Management with Intelligent VoIP QoS

The Vigor2133Vac router has the “VoIP QoS” feature to guarantee priority for VoIP calls. This ensures good call quality even when the Internet bandwidth is limited. QoS functions allow the network administrator to set priorities for certain types of traffic such as VoIP or Video streaming to ensure the required level of performance is achieved even under network congestion. The traffic type can be assigned to each of the three QoS classes and reserved bandwidth allocated.

In addition, the bandwidth usage of each LAN client can be managed via Session Limit and Bandwidth Limit feature. You may also set up the “Smart Bandwidth Limit” to apply bandwidth limit only to the PCs which are running inappropriate applications, such as P2P download.

3. LAN and VLAN

The Vigor2133Vac has 4 x Gigabit LAN ports and supports 30,000 NAT sessions.

The Vigor2133Vac supports both port-based and 802.1q tagged VLANs. Port-based VLANs allow the assignment of a VLAN and an IP subnet to each router LAN port. The 802.1q tagged VLANs can extend up to 8 VLANs and four IP subnets to an attached switch.

4. Firewall

The Vigor2133Vac has powerful firewall features including object-oriented SPI (Stateful Packet Inspection) firewall, DoS (Denial of Services), CSM (Content Security Management) and WCF (Web Content Filter).

Stateful Packet Inspection (SPI) Firewall monitors incoming and outgoing packets at layer 3 (OSI model) and passes or blocks the data packets based on the configuration.

The DoS feature protects the network for unwanted access requests from DoS attackers.

CSM enables network administrators to control and manage IM (Instant Messenger) and P2P (Peer-to-Peer) applications, for instance, to keep network users from accessing inappropriate contents and ensure that network traffic flow efficiently.

WCF classifies all websites into 64 categories and allows network administrators to select categories to protect the users from undesirable website content. DrayTek uses the CYREN WCF database for its Vigor routers, and each router includes a free 30-day trial license.
The object-based firewall provides flexibility by using Objects in the firewall settings. Objects can be created and placed in groups for IP, service type, keyword, file extension, etc. This allows a filter rule to be applied to many IP addresses, reducing the 
number of firewall filters required. In addition, these objects and groups can be reused for other firewall settings resulting in a 
reduced amount of work required to create multiple firewall rules.

Firewall rules can be applied according to a Time Schedule to control access to the Internet or network services according to predetermined time slots. Up to 4-time schedules can be applied to each firewall filter rule. For example, social media can be restricted during work hours and be allowed during off work hours in a company.

5. High-Performance VPN

The Vigor2133Vac router allows up to 2 concurrent VPN connections including 2 x SSL VPN tunnels. This can be used to establish LAN-to-LAN VPN connections between local networks and the main office so that hosts on the local network can access the main office network without requiring individual dial-up VPN connections.

The Vigor2133Vac router can also be the VPN server allowing up to two dial-in VPN connections.

Supported VPN protocols include PPTP, L2TP, IPsec, IKEv2, L2TP over IPSec, and SSL VPN.
The SSL technology allows secure Web encryption such as those used for 
online banking. With Vigor2133Vac, you can create SSL VPN in Full Tunnel mode or Proxy mode.

DrayTek Vigor2133Vac Gigabit VoIP 802.11ac Firewall VPN Router - NBN Ready - Desktop Overview 4

6. Central AP Management

Vigor2133Vac supports Central AP Management (APM) with a console to auto-configure and manage up to 2 directly connected (via LAN cables) Draytek wireless Access Points including VigorAP 800, VigorAP 810, VigorAP 900 & VigorAP 910C.

The Dashboard feature displays the status such as traffic and number of attached stations, of all the attached Access Points.

With Auto Provisioning enabled on the attached Access Points, WLAN profiles can be created and applied to the selected Access Points from the central console.

The AP Maintenance feature allows a number of actions to be programmed, including Configuration Backup and Restore, Firmware Upgrade, Remote Reboot and Factory Reset, for selected Access Points.

The connected Access Points can also be displayed on a map or floor plan showing their locations and basic descriptions. Other features include Traffic Graph, Rogue AP detection, Event Log, Total Traffic, Station number and Access Point load balancing.

7. Remote Access Management

The Vigor2133Vac includes a number of management options to provide both local and remote access to monitor and manage the router.

The TR-069 feature integrates with the VigorACS 2 centralised management system. This can be used to allow system integrators or network administrators to configure, monitor and manage the Vigor2133Vac remotely from the comfort of their offices or homes. It can also be used to Auto-Provision the Vigor2133Vac remotely by sending configuration data to the router. There are 3 wizards: Configuration Wizard, VPN Wizard and Firmware Upgrade Wizard. These allow network administrators to quickly and easily carry out complex tasks.

Alarm & Log Management features ensure real-time notifications and alerts to specified phone numbers or email accounts in relation to any faults or issues of the connected CPEs.
A number of diagnostic functions are also available for the network administrator to monitor and troubleshoot any network issues. These include Data Flow Monitor, Traffic Graph and Syslog Explorer, etc.

Like all Vigor routers, Vigor2133Vac supports management options include HTTP, HTTPS, FTP, SSH, Telnet and SNMP.



  • Interface
    • 1 x GbE WAN port
    • 4 x GbE LAN port
    • 2 x USB 2.0 port
    • 2 x FXS port (Vac model)
    • Factory Reset Button
    • Power On/Off Switch
  • Power
    • DC 12V @2A
    • Max. Power Consumption: 24 watts
  • Temperature
    • Operating: 0°C ~ 45°C
    • Storage: -25°C ~ 70°C
  • Humidity
    • Operating: 10% ~ 90% (non-condensing)
  • Dimension (mm)
    • 207 (L) x 131 (W) x 42 (H)
      (8.1″ x 5.2″ x 1.7″)


  • WAN
    • PPPoE Client
    • DHCP Client
    • Static IP
    • PPTP/L2TP
    • 802.1Q VLAN Tagging
    • Triple-Play Applications
    • 3G/4G Backup
  • IPv6
    • PPP
    • DHCPv6 Client
    • Static IPv6
    • TSPC
    • AICCU (AYIYA/Heartbeat)
    • 6rd
    • 6in4 Static Tunnel
  • Failover
    • 3G/4G Backup
  • Connectivity Detection
    • ARP
    • Ping Probe

LAN Managment

  • VLAN
    • Up to 8 VLAN
    • 802.1Q Tag-based VLAN
    • Port-based VLAN
  • DHCP Server
    • Up to 4 IP Subnet
    • Bind-IP-to-MAC
    • Custom DHCP Option
  • DNS Control
    • Local Name Server
    • Conditional DNS Forwarding
  • Hotspot Portal
    • Authentication by Click-Through, Social Login, and SMS PIN
    • Custom Portal Page
    • URL Redirection
    • Walled-Garden


  • Static Route
    • 30 IPv4 Static Routing Rules
    • 40 IPv6 Static Routing Rules
    • Inter-VLAN Routing
  • Dynamic Routing
    • RIP v1/v2
  • Policy-Based Routing
    • 10 Route Policy
    • Criteria: Protocol, Source IP, Destination IP, Destination Port
    • Failover options


  • Performance
    • Up to 2 concurrent tunnels
    • Up to 2 concurrent SSL VPN
  • Protocols
    • PPTP, L2TP, IPsec, L2TP over IPsec, SSL, IKEv2
    • LAN-to-LAN VPN
    • Teleworker-to-LAN VPN
  • Encryption
    • MPPE 40/128 bit
    • Hardware-based AES/DES/3DES
  • Authentication
    • MD5, SHA-1
    • Pre-Shared Key, Digital Signature (X.509)
    • mOTP
  • Advanced
    • Hub-and-Spoke Topology support
    • NAT-Traversal (NAT-T)
    • Dead Peer Detection (DPD)
    • DHCP over IPsec
    • Single-Armed VPN


  • NAT
    • One-to-One Port Redirection
    • Range-to-Range Port Redirection
    • Open Ports
    • Port Triggering
    • DMZ Host
    • ALG: SIP, RTSP, FTP, TFTP, H.323
    • VPN Pass-Through: PPTP, L2TP, IPsec
    • UPnP
  • Firewall Filter
    • IP-based Firewall Policy
    • User-based Firewall Policy
    • Object-based Configuration
    • Schedule Enable/Disable
  • Content Filtering
    • URL Keyword Filtering
    • Category Filtering (subscription required)
    • DNS Keyword Filtering
    • Web Features Filtering
  • Attack Protection
    • DoS Defense

Bandwidth Management

  • Bandwidth Policy
    • Session Limit
    • Bandwidth Limit
    • IP-Based Policy
    • Scheduled Enable/Disable
  • Quality of Service
    • Layer 3 QoS (TOS/DSCP)
    • Layer 2 QoS (802.1p)
    • 4-Level Priority with user-defined classification
    • Bandwidth Borrowing
    • Guaranteed bandwidth for VoIP traffic
    • APP QoS

Network Features

  • Network Features
    • Dynamic DNS
    • DNS Security
    • RADIUS Client
    • Bonjour
    • IGMP Proxy
    • IGMP Snooping
    • SMB File Sharing
  • User Authentication
    • Local User Database
    • RADIUS Server

Wireless LAN (n/ac/Vac)

  • Standards
    • 802.11b/g/n (2.4G)
    • 802.11 a/n/ac (5G)
  • SSID
    • Up to 4 SSID per radio
    • SSID-based 802.1Q VLAN
  • Radio Management
    • Auto Channel Selection
    • Auto Channel Width (2.4G)
    • Wi-Fi Scheduling
  • Security
    • WEP, WEP-802.1x, WPA-PSK, WPA-802.1x, WPA2-PSK, WPA2-802.1x
    • Hidden SSID
    • Client Isolation
    • Access Control per SSID
    • WPS
  • Advanced
    • AirTime Fairness
    • Band Steering (ac/Vac model)
    • WMM
  • WDS
    • Bridge
    • Repeater/li>

VoIP (Vac model)

  • General
    • Protocol: SIP, RTP/RTCP
    • 6 SIP Registrars
    • G.168 line echo-cancellation
  • Call Services
    • Call Hold/Retrieve
    • Call Waiting
    • Call Transfer
    • Call Forwarding (Always, Busy, No Answer, Busy or No Answer)
    • CLIR (Calling Line Identification Restriction)
    • Call Barring (Incoming / Outgoing)
    • DND (Do Not Disturb)
    • MWI (Message Waiting Indicator) (RFC-3842)
    • Hotline
    • Intercom (dial 10 or 20 for Phone 1 or Phone 2)
  • Dial Plan
    • Press for more than 5 seconds then release the button to do the factory reset.
    • Digit Map
    • Call Barring
    • Regional
  • Voice Codec
    • G.711 a/u law
    • G.726 32kbps
    • G.729 A/B
  • DTMF Tone
    • In band
    • Out band (RFC-2833)
    • SIP Info


  • Configuration
    • Web Interface: HTTP, HTTPS
    • Command-Line Interface: Telnet, SSH
    • TR-069 via VigorACS
    • Config File Export & Import
    • Compliant with the config file exported from Vigor2760
  • F/W Upgrade
    • TFTP, HTTP, TR-069
  • Admin Access Control
    • 2-level Administration Privilege
    • Access from the Internet
    • Access List
  • Monitoring
    • Dashboard
    • Syslog
    • SMS/E-mail Alert
    • TR-069 via VigorACS
    • SNMP v2, v2c, v3
  • Central Management
    • Wireless Controller for up to 2 VigorAP


SKU # AC20156 | Model # Vigor2133Vac

See an error? Click here and let us know