• Router

Teleworker VPN - SSL - Apple iOS Smart VPN App

V. VPN (Virtual Private Networking)

Products:
Vigor 2135ax
Vigor 2620Ln
Vigor 2760
Vigor 2762
Show all

Keywords:
Apple
Apple iOS
Certificate
Certificate Error
Show all

Apple iOS devices such as the Apple iPad and iPhone can connect to a DrayTek router that supports SSL VPN with the free DrayTek Smart VPN App for iOS which allows iOS devices to create fast and secure SSL VPN tunnels for teleworking and/or secure browsing.

It integrates with Apple's VPN facilities so that users can quickly establish a VPN tunnel from both the Smart VPN App and through the iOS Settings - VPN menu.

Requirements:

  • Apple iPad, iPhone or iPod Touch with iOS 9.0 or later
  • DrayTek Vigor router with SSL VPN Tunnel support (i.e. Vigor 2860)
  • Static IP address or Host Name (including Dynamic DNS) for the router's WAN interface
  • Recommended: Certificate (can be self-signed) with valid Common Name (IP or Host Name) and valid To/From times

DrayTek SSL VPN with Apple devices on iOS 13 and later

The iOS 13 update from Apple introduces new requirements for Trusted SSL Certificates, which are required for operation of an SSL VPN connection.

If the Trusted Certificate used by the router does not meet these requirements, the SmartVPN app will display a connection error:

"SmartVPN"
"Connection error, please verify
certificate on the Vigor router side or
contact your administrator."

There are two recommended solutions:

Use LetsEncrypt Certificate Regenerate the Self-Signed Certificate

The certificates provided by the LetsEncrypt Certificate Authority are compatible with iOS 13 and later. If your router supports LetsEncrypt and you have set up a DrayDDNS account, the router can manage the process of getting certificates signed by LetsEncrypt. Once this is in place and the LetsEncrypt/DrayDDNS certificate is selected for SSL VPN use, your Apple device will be able to authenticate with the router.

One significant benefit of this method is that you can use the more complex "Verify Root CA" verification level without needing any additional setup.

Refer to this guide for setting up LetsEncrypt on your router:
How to apply Let's Encrypt certificate on Draytek routers

DrayTek released firmware updates in November 2019 for compatibility with Apple's iOS 13 and later.
The Self-Signed Certificate on DrayTek routers has been updated to meet these new requirements.

Update the firmware of your router to the latest version and regenerate the certificate:
How to regenerate the router's Self-Signed Certificate

If there is no firmware update available for your DrayTek router model yet, or the firmware can not be updated, use this method instead.
Set the "Valid To" date to 2 years from the date of creation when signing:
How to generate custom self-signed router certificates

Set the Certificate Verification Level

The DrayTek Smart VPN client has options to control the level of verification used for the certificates that secure the SSL VPN tunnel. Before setting up the SSL VPN connection, it's important to consider which type of certificate verification that the SSL VPN client will enforce; more verification will require additional certificate setup.

Each level of verification has different requirements and the default setting is to "Match server name", which is defined in the table below. If the certificate does not match the verification requirements, the Smart VPN application will not allow the VPN tunnel to establish and will display the error message shown to the right.


Certificate Verification LevelDescription
Basic Checks that the certificate is within the Valid To and Valid From times
Match Server Name Checks that the certificate's Common Name / CN matches the destination of the server connection.
Checks that the certificate is within the Valid To and Valid From times
Verify Root CA Checks that the certificate is signed by a trusted root authority.
Checks that the certificate's Common Name / CN matches the destination of the server connection.
Checks that the certificate is within the Valid To and Valid From times

This is configured from the Settings section of the app:

This setup guide gives instructions for two methods of configuring the VPN connection, depending on the Certificate Verify Level selected:

  • Basic Verification - This is recommended for setting up the VPN connection quickly
  • Match Server Name - This method requires configuring a valid certificate on the router before the VPN can be established, but does provide higher security because the authenticity of the VPN server can be confirmed

Step 1. Create an SSL VPN Dial-In User Account

To set up the SSL VPN profile on the router, go to [SSL VPN] > [User Account], click on the first un-used Index number link to edit the profile settings:

  • Enable the profile
  • Enter a suitable Username to for the account
  • Set a secure Password (up to 19 characters, alphanumeric and special characters allowed)
  • Set the profile to accept SSL Tunnel connections:

Click OK on that page to save the settings for that profile.

The Status text displays in red if the user is not connected and will display in green when the user has connected.

With the account created and a valid certificate installed on the router, the client can be configured to connect.


Step 3. DrayTek Smart VPN App Configuration

Open the DrayTek Smart VPN App and press + to create a new VPN profile:

  • Profile: The name of the VPN profile
  • Server: The IP address or Host Name of the SSL VPN server, the VPN server in this example is 198.51.100.103
  • Port: The port of the SSL VPN server; this will be 443 by default and should only be changed if the SSL VPN port has been changed on the router
  • Username: The VPN username such as the one created earlier in this guide
  • Password: The VPN account password
  • Connect on Demand: Used to specify criteria for starting the VPN connection, based on domain
  • Disconnect on Sleep: Disconnects the VPN when the device is put into sleep mode
  • Send All Traffic: Similar to Split Tunneling when disabled. If this is not selected, only traffic in the VPN's local subnet will go through the VPN tunnel. When enabled, this puts all Internet connectivity through the VPN tunnel.

Press Save and the device will give this warning:

Press Allow to continue and enter the device's PIN when prompted to save the profile:

Once the VPN has saved, it is recommended to set the VPN client to allow TLS 1.2 as the highest SSL security protocol. This is done in the Settings section of the App:


The VPN tunnel can now be established, go to the Home section of the App and the VPN profile will show with a red icon to indicate that it is disconnected. Pressing the "i" icon by the profile will go into the settings for the profile. Pressing on the red icon will go to the options to enable and start the VPN tunnel:

In the VPN status section, ensure that the VPN profile is Enabled and press the Status option to start the VPN tunnel:

Note: Only one profile can be active at a time, when using multiple profiles, selecting another profile will disable the previously enabled profile.

If the VPN connection is successful, it will change the Status to Connected and display the IP address and traffic sent through the VPN tunnel.

The Home section of the App will show the profile with a green status icon when connected:

To delete a profile, slide it to the left to display the Delete option:


The VPN tunnels configured in the DrayTek Smart VPN App can be enabled and disabled through the Settings - VPN menu on the iOS device. If there are multiple profiles, going into the VPN menu will allow the user to select which profile to connect with.


The status of the VPN tunnel can be viewed from the router's web interface under [VPN and Remote Access] > [Connection Management]:


Step 1. Install a valid certificate for HTTPS and SSL VPN on the router

The Smart VPN App for iOS requires a valid certificate on the device it's connecting to, this means that the CN / Common Name of the certificate must match the IP address or Host Name of the VPN server that the Smart VPN App is connecting to and that the certificate has not expired (or is within its Valid To and Valid From time).

To create a custom self-signed certificate on the router with valid Common Name details, follow this guide.

To create and install certificates signed by a Trusted Certificate Authority on the router, follow this guide.

To create and install certificates signed by a Trusted Certificate Authority on the Vigor 3900 and Vigor 2960, follow this guide.


This example uses the IP address 198.51.100.103 for both the public IP address of the router and the router certificate Common Name.

If the router has a Host Name associated with its public IP address, the host name can be used as the Common Name instead.

It's possible to create a certificate that will work with dynamic IP addresses by using the router's Dynamic DNS facility and a dynamic DNS hostname as the certificate's Common Name.


 

Step 2. Create an SSL VPN Dial-In User Account

To set up the SSL VPN profile on the router, go to [SSL VPN] > [User Account], click on the first un-used Index number link to edit the profile settings:

  • Enable the profile
  • Enter a suitable Username to for the account
  • Set a secure Password (up to 19 characters, alphanumeric and special characters allowed)
  • Set the profile to accept SSL Tunnel connections:

Click OK on that page to save the settings for that profile.

The Status text displays in red if the user is not connected and will display in green when the user has connected.

With the account created and a valid certificate installed on the router, the client can be configured to connect.


Step 3. DrayTek Smart VPN App Configuration

Open the DrayTek Smart VPN App and press + to create a new VPN profile:

  • Profile: The name of the VPN profile
  • Server: The IP address or Host Name of the SSL VPN server, the VPN server in this example is 198.51.100.103
  • Port: The port of the SSL VPN server; this will be 443 by default and should only be changed if the SSL VPN port has been changed on the router
  • Username: The VPN username such as the one created earlier in this guide
  • Password: The VPN account password
  • Connect on Demand: Used to specify criteria for starting the VPN connection, based on domain
  • Disconnect on Sleep: Disconnects the VPN when the device is put into sleep mode
  • Send All Traffic: Similar to Split Tunneling when disabled. If this is not selected, only traffic in the VPN's local subnet will go through the VPN tunnel. When enabled, this puts all Internet connectivity through the VPN tunnel.

Press Save and the device will give this warning:

Press Allow to continue and enter the device's PIN when prompted to save the profile:

Once the VPN has saved, it is recommended to set the VPN client to allow TLS 1.2 as the highest SSL security protocol. This is done in the Settings section of the App:


The VPN tunnel can now be established, go to the Home section of the App and the VPN profile will show with a red icon to indicate that it is disconnected. Pressing the "i" icon by the profile will go into the settings for the profile. Pressing on the red icon will go to the options to enable and start the VPN tunnel:

In the VPN status section, ensure that the VPN profile is Enabled and press the Status option to start the VPN tunnel:

Note: Only one profile can be active at a time, when using multiple profiles, selecting another profile will disable the previously enabled profile.

If the VPN connection is successful, it will change the Status to Connected and display the IP address and traffic sent through the VPN tunnel.

The Home section of the App will show the profile with a green status icon when connected:

To delete a profile, slide it to the left to display the Delete option:


The VPN tunnels configured in the DrayTek Smart VPN App can be enabled and disabled through the Settings - VPN menu on the iOS device. If there are multiple profiles, going into the VPN menu will allow the user to select which profile to connect with.


The status of the VPN tunnel can be viewed from the router's web interface under [VPN and Remote Access] > [Connection Management]:


How do you rate this article?

1 1 1 1 1 1 1 1 1 1


Add a comment to this article

In the below box, you can add comments which you consider might be helpful to other users reading this article:

(Will be shown on your comment)
(Optional, Not shown/published)


NOTE : All comments are reviewed before publication and may not be posted or may be redacted if the editors do not consider them helpful. The use of offensive or obscene language, copyrighted material, or advertising or promotion or linking to any other product or service is prohibited. By submitting your comment, you confirm that you are the original author and assign copyright of the content to DrayTek indefinitely and irrevocably.