cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1827
Views
0
Helpful
9
Replies

Help configuring SSL on RV220W router

kippage01
Level 1
Level 1

Hi I need some assistance configuring a RV220W router for SSL VPN for my company. I've never tried to do this before and have many questions. Is there someone who would be willing to assist me?

1 Accepted Solution

Accepted Solutions

Hello,

Thank you for your reply.

I'm sorry it still appears to be complicated but let me tell you that it is completely normal, what happens is that the browser does not recognize your public IP or the Dynamic DNS name as a trusted website, so it warns you that it may not be secured, now, since you know it is your router then you can bypass the error and continue.

The only way to get rid of the error is to purchase a certificate from a certificate authority and add it to your router so that the browsers can recognize the site as secure. Please keep in mind that this is not needed for the SSL VPN to work, you can just bypass the error and continue with the connection.

Also I forgot to mentioned that this SSL VPN is only supported with Windows XP, Windows Vista and Windows 7 32 bits, 64 bits OS's and Windows 8 is not supported.

Please let me know if you have any other questions and don't forget to mark the question as correct if it was helpful to you so that other members of the forum can benefit from the information.

View solution in original post

9 Replies 9

Andrew Lien
Level 1
Level 1

Hi, kippage01

 

My name is Andrew Lien and I am a content developer for the Cisco Knowledge Base. There are a few knowledge base articles you can use to help you configure SSL on the RV220W. I will link a few, but refer to the table below on how to use GuideMe to help you discover articles relating to your need for assistance for the RV220W

Configuration of SSL VPN Client Routes on RV220W

Generation of an SSL (Secure Socket Layer) Certificate on RV120W and RV220W

Domain Management on RV220W and RV120W

Change the password in SSL VPN ClientPortal on RV220W and RV120W

Configuration of IP Address Range and Routes for Secure Sockets Layer (SSL) VPN Clients on the RV220W

User Accounts Configuration on RV220W and RV120W

View Secure Sockets Layer Virtual Private Network Connection (SSL VPN) Status on RV220W and RV120W

 

If you need more articles on how to configure the RV220W, you can use the GuideMe tool to further specify the articles you need.

 

 

"Guide Me"

Cisco has a very useful tool called GuideMe, is made for small business products, you can use this address for accessing the tool: http://sbkb.cisco.com/CiscoSB/Loginr.aspx?alt1=&pid=4&eroute=Super , is very easy to use, just complete the 3  spaces on this way:

Select a category: (Select the device type on request), e.g.  Routers

Enter model: (Type the model on request), e.g. RV042

Question: (Type what  you want to know  about the device), e.g.  VPN

And it'll be showing all the information you need about what you query.

 

I would like to add to my reply that there is an article that might directly help you in SSL VPN for the RV220w. I will link it below:

Configuration of Secure Socket Layer Virtual Private Network (SSL VPN) Host Names Port Forwarding on RV220W

 

Different device, but this article can help you set up VPN on windows 8 clients.

http://sbkb.cisco.com/CiscoSB/ukp.aspx?login=1&pid=2&app=search&vw=1&articleid=2931&donelr=1

cchamorr
Level 5
Level 5

Hello, 

I have to say that Andrew Lien's answer is very complete and accurate but maybe a little on the advanced side of the configuration.

If you are only looking to enable SSL VPN on your router and access it veru quickly and have no need for certificates or domains or changing the default portal layout, then here are a few steps that you can follow and have the VPN working in no time.

1- Enable remote management

To do this, go to Administration - Remote management, then click on the check mark to enable remote management and make sure you are using port 443 or 60443 at the bottom of the page. Then click on save

2- Create SSL VPN users

To do this, go to Administration, User Management - Users, click on Add and create a new "SSL VPN User" under user type.

This is it, there is not more configuration required for the SSL VPN to start working.

For you to connect, from a remote location open Internet Explorer and go to the external IP address of your router using the port that you configured for remote management, for instance: https://xxx.xxx.xxx.xxx:443 or https://xxx.xxx.xxx.xxx:60443, then use the SSL VPN User you created to log into the router, you will get to the portal page.

Please keep in mind that you need to have a Public IP address on the WAN port of your router for this to work.

I hope this helps.

Thank you for demystifying this somewhat. I have a Dynamic DNS Host thru dyndns.org that points to my router. When I follow your instructions I do get to the client portal, but the process is difficult. Whenever I try to access the router firmware the browser warns me that the connection may be unsafe and there is a slash thru the https://. If i tell the browser to proceed anyway it will get there eventually, but may have to try 2 or more times. Why does this happen?

Hello,

Thank you for your reply.

I'm sorry it still appears to be complicated but let me tell you that it is completely normal, what happens is that the browser does not recognize your public IP or the Dynamic DNS name as a trusted website, so it warns you that it may not be secured, now, since you know it is your router then you can bypass the error and continue.

The only way to get rid of the error is to purchase a certificate from a certificate authority and add it to your router so that the browsers can recognize the site as secure. Please keep in mind that this is not needed for the SSL VPN to work, you can just bypass the error and continue with the connection.

Also I forgot to mentioned that this SSL VPN is only supported with Windows XP, Windows Vista and Windows 7 32 bits, 64 bits OS's and Windows 8 is not supported.

Please let me know if you have any other questions and don't forget to mark the question as correct if it was helpful to you so that other members of the forum can benefit from the information.

I purchased the RV220W because I have clients whom I would like to support remotely. They have a mixture of Macs and PCs and I had hoped to simplify the connection process and do it securely by using an SSL VPN. It appears now that I did not have sufficient knowledge of the limitations of the router to accomplish my aims. It appears from your answer the options I have left are to use PPTP or IPsec VPN. Do you agree? What limitations will the router have doing this?

I'm using a Win 64 bit system to test the SSL VPN, and while I did get to the portal, when I attempted to use the VPN Tunnel icon that did not work. Your answer explains this.

I get the https:// error logging into the router firmware locally to configure it using its local IP address as well as remotely with the SSL VPN. I attempted to create a self-certificate to overcome this problem, but I do not have sufficient understanding of the terms and what are valid entries. For example is the Name field merely a descriptive name or does it have some othe significance? In the Subject field the CN code is required, but does it have to be an IP address? Or can it be something else? If so what IP address?

Everything you have said has been very helpful, so I am marking it as Correct even though I am disappointed I won't be able to used the router as I had intended. Now I have to learn hoe to configure the other VPN connection methods and will probably need some help with that. I want to do my best to make any VPN connections as secure as I possibly can to keep myself and my clients safe from the crackers! I'm getting quite an education! I guess I need it!

 

Hello, 

I'm very sorry it took me so long to reply, but it has been a crazy day.

Before I answer your questions, I have a question of my own.

Can you explain with as much detail as you can, what is the purpose for the VPN connection? What exactly are you trying to accomplish?

I ask because I'm not sure I understand correctly what you are trying to do. According to your last post, you got this router for your clients to connect remotely to it so that you can support their remote workstations?

Please clarify this point so that I can get a better idea what you are trying to do and if this solution will even work for your purposes.

I have used in the past a software VPN program on my Macintosh that allows customers to join my network remotely. Once they are on my network I can use VNC software to show them how to do things on their own system. Also, I can remotely control their systems with their permission. The VPN makes that easy to do because once they have a local IP address the VNC software works better and it is easier for them. I ran into problems when my ISP changed their gateway equipment, which is faulty and no longer supports my VPN. They usually do not offer anything but the most basic support, however, I have been through this with the highest levels of their tech support and they have not resolved the problem with their equipment. So, I decided to get my own equipment and the RV220W seemed to be ideal to make it easy for the customers to connect with just a browser. I think now that its SSL VPN limitations may prevent me from using it as I had hoped, but maybe I can use PPTP or IPsec. This requires more configuration by the customer, but maybe my investment in the RV220W will not be a complete loss. I hope this answers your question. And thanks for your support.

Hello, 

Thank you for the very complete answer. 

Now that I know what you are trying to accomplish I think I have good news.

Despite the fact that the SSL VPN has its limitations in regards to the supported OS's, you can also use the PPTP which is compatible with most OS's, 32 and 64 bits, Windows and Mac, even iOS and Android.

Also, they are not mutually exclusive meaning you can have them both configured at the same time, SSL and PPTP and they will coexist without issue.

Furthermore I was doing a little research and it seems you can "export" and "import" your PPTP settings to make it easier for your customers (I haven't verified this but I found this article: https://www.raymond.cc/blog/export-and-import-dial-up-and-vpn-settings-in-windows/

I don't know how current or accurate it is though)

To configure PPTP follow the instruction on this verified link:

http://sbkb.cisco.com/CiscoSB/ukp.aspx?vw=1&docid=f577457477f94c60ba65b9675b6b03f7_Setup_PPTP_Connection_to_RV220W_from_the_Windows_7_Operating.xml&pid=2&respid=0&snid=4&dispid=0&cpage=search

I hope this was helpful.