DrayTek UK Users' Community Forum

Help, Advice and Solutions from DrayTek Users

Local Certificate Generation stuck on Requesting

  • lozcozard
  • Topic Author
  • User
  • User
More
19 Jan 2017 22:01 #1 by lozcozard
I am trying to connect to the SSL VPN option in the latest firmware for my 2760n. My software (Cisco Anyconnect and Drayteks one) both would not connect. The Cisco one reports SSL warnings (Certificate does not match server name, Certificate is from an untrusted source), so I assume it IS connecting, but when I click Connect Anyway it says connection attempt has failed.

So I thought maybe I need to fix those SSL errors. I went to Certificate Management >> Local Certificate and clicked to generate a new cert.

The status is Requesting and it has been like that for several days. So it seems stuck.

Anyone know why this is, how to rectify and get a cert installed?

Thanks

Please Log in or Create an account to join the conversation.

  • lozcozard
  • Topic Author
  • User
  • User
More
19 Jan 2017 22:06 #2 by lozcozard
After posting I found this webpage http://www.draytek.com/en/faq/faq-management/management.system-maintenance/how-to-generate-unique-self-signed-certificate-and-replace-the-default-one/ which says to request a root CA first. So I did that, and then I could click Sign on the local cert page, so did that. So maybe this will help.

but I wont know because I had to choose tomorrow as the valid date, it would not allow me to choose the same date as today strangely.

So will check again tomorrow.

Please Log in or Create an account to join the conversation.

  • lozcozard
  • Topic Author
  • User
  • User
More
22 Jan 2017 23:16 #3 by lozcozard
Managed to get the SSL cert, all says OK, but going to the https for my router reports its not secure as its self signed, and Cisco Anyconnect still does not connect.

Please Log in or Create an account to join the conversation.

More
24 Jan 2017 10:05 #4 by admin3
The SSL VPN tunnel protocol on DrayTek routers is specific to DrayTek, you need to connect with the DrayTek SSL VPN client: SmartVPN
If it still can't connect, have a look at the support guides for SSL VPN in the knowledgebase, you can change the Certificate Verification level so that it doesn't require all of the certificate details to match, which might help for troubleshooting.



Forum Administrator

Please Log in or Create an account to join the conversation.

  • lozcozard
  • Topic Author
  • User
  • User
More
24 Jan 2017 13:34 #5 by lozcozard
Ah that works! Great, thanks a lot. I assumed any VPN client would work. I did not want to use SmartVPN as it opens up a main window on my Mac, and no Menu icon/process from which I can connect/disconnect. But its not a big deal as it wont be used often, just when I am working away from home and work.

BUT its extrenely slow. Less than 1Mbs per second. My office and home both have super fast broadband, so I expected similar speeds. Why would it be so slow? Is that a Draytek router issue, or is that what you get with VPNs all the time?

I wanted to use the router for VPN so I dont need a dedicated computer running just to provide a VPN service I dont use often, but I cant if speeds will be less than 1Mbs per second.

Thanks

Please Log in or Create an account to join the conversation.

More
24 Jan 2017 15:00 #6 by admin3
That's good, and bad :)

For the speed issue, I think it would be worth trying different TLS versions by changing the settings in the "Advanced" settings for the VPN tunnel. Beyond that, it may be worth making a support ticket to look into the cause of the speed issue.



Forum Administrator

Please Log in or Create an account to join the conversation.