DrayTek UK Users' Community Forum

Help, Advice and Solutions from DrayTek Users

Unable to access remote management through HTTPS in Chrome

  • mpcjames
  • Topic Author
  • Offline
  • New Member
  • New Member
More
02 Feb 2015 14:47 #82552 by mpcjames
We have multiple customers using Draytek Vigor 2830.
Until approx 2 weeks again we were able to access the remote management for the routers via the address HTTPS://*WANIP*:443 or HTTPS://*WANIP:*CUSTOMPORT*.

However we are now unable to access any of these routers from Google Chrome or Firefox browsers. We are presented with the following error:

Code:
This webpage is not available A secure connection cannot be established because this site uses an unsupported protocol. Error code: ERR_SSL_VERSION_OR_CIPHER_MISMATCH

The remote management DOES work in Internet Explorer v11.

Does anyone know of a recent change to SSL in Chrome/Firefox that may break this SSL connection or certificate?

It doesn't matter which port you customise the Remtoe Mananagement HTTPS port too, it fails on all of them.

Thanks.

Please Log in or Create an account to join the conversation.

More
05 Feb 2015 17:02 #82597 by lectrician
I have found the same - Have loads of these out in the field, so am having to get used to IE again :-(

Please Log in or Create an account to join the conversation.

More
09 Feb 2015 19:23 #82642 by rguk
This is because google has killed SSLv3 within Chrome I'm yet to figure out a fix.

Found the fix :-) http://www.draytek.co.uk/download/support/readme_v2830sb.txt

SSL3 now disabled in favour of TLS by default for SSL tunnels and web management.

Thanks
Wayne
http://www.ramblinggeek.co.uk

Please Log in or Create an account to join the conversation.

More
16 Feb 2015 16:48 #82698 by rmap
Google, Mozilla & Microsoft all stated they're dropping support for SSL 3.0 due to vulnerabilities, back in October last year.

I'm glad they've fixed the 2830 for you RGUK, now hopefully they can fix the 2850 and other affected models.

It's bad enough that management over HTTPS is affected, but we use user-based web-authentication for one of our SSIDs; and I'm not happy that I have to switch to HTTP to allow users to login!

Please Log in or Create an account to join the conversation.

Moderators: Sami