Vigor Router supports importing a Let's Encrypt certificate from its web user interface. It makes the process of generating, signing and importing the certificate very easy. This document will show how to apply a Let's Encrypt for the router's domain.
1. Configure a Registered Dynamic Domain Name
In this example, we use DrayDDNS.
For details on activating DrayDDNS, please refer to https://www.draytek.com/support/knowledge-base/5168#DrayOS5_section

2. Enable the ACME Client Option
Vigor2136 will use the domain name to request a Let's Encrypt certificate. The certificate request, challenge, and download process may take a few seconds.

3. Verify Certificate Generation
Check if the Let’s Encrypt certificate is generated successfully via Configuration/ Certificate.

4. The Let’s Encrypt Certificate can be used for Vigor Router’s Local Service, including HTTPS Web Server, TR069 Server, IPsec VPN Server, and more.
Note that when using other DDNS provider’s domain to apply for a Let’s Encrypt certificate, please enable Enable HTTP Management from WAN during the certificate generation process, as the Let’s Encrypt server will need access to the Vigor Router’s HTTP port to verify authorization. Additionally, if the Vigor router is behind another NAT device, ensure that HTTP Port 80 is open to the Vigor2136 for this process to succeed.

Please disable HTTP Management from the WAN once the certificate is installed.

Comments
0 comments
Please sign in to leave a comment.