AnyConnect: Installing a Self-Signed Certificate as a Trusted Source
The documentation set for this product strives to use bias-free language. For the purposes of this documentation set, bias-free is defined as language that does not imply discrimination based on age, disability, gender, racial identity, ethnic identity, sexual orientation, socioeconomic status, and intersectionality. Exceptions may be present in the documentation due to language that is hardcoded in the user interfaces of the product software, language used based on RFP documentation, or language that is used by a referenced third-party product. Learn more about how Cisco is using Inclusive Language.
Objective
The objective of this article is to guide you through creating and installing a self-signed certificate as a trusted source on a Windows machine. This will eliminate the “Untrusted Server” warning in AnyConnect.
Introduction
The Cisco AnyConnect Virtual Private Network (VPN) Mobility Client provides remote users with a secure VPN connection. It provides the benefits of a Cisco Secure Sockets Layer (SSL) VPN client and supports applications and functions unavailable to a browser-based SSL VPN connection. Commonly used by remote workers, AnyConnect VPN lets employees connect to the corporate network infrastructure as if they were physically at the office, even when they are not. This adds to the flexibility, mobility, and productivity of your workers.
Certificates are important in the communication process and are used to verify the identity of a person or device, authenticate a service, or encrypt files. Self-signed certificate is a SSL certificate which is signed by its own creator.
When connecting to AnyConnect VPN Mobility Client for the first time, users may encounter an “Untrusted Server” warning as shown in the image below.

Follow the steps in this article to install a self-signed certificate as a trusted source on a Windows machine, to eliminate this issue.
AnyConnect Software Version
- AnyConnect — v4.9.x (Download latest)
Check Time Settings
As a prerequisite, you need to ensure that your router has the correct time set, including time zone and daylight savings time settings.
Step 1
Navigate to System Configuration > Time.

Step 2
Ensure that everything is set correctly.

Create a Self-Signed Certificate
Step 1
Log into the RV34x series router and navigate to Administration > Certificate.

Step 2
Click on Generate CSR/Certificate.

Step 3
Fill out the following information:
- Type: Self-Signed Certificate
- Certificate Name: (Any name that you choose)
- Subject Alternative Name: If an IP address will be used on the WAN port, select IP Address below the box or FQDN if you will be using the Fully Qualified Domain Name. In the box, enter the IP address or FQDN of the WAN port.
- Country Name (C): Select the Country where the device is located
- State or Province Name (ST): Select the State or Province where the device is located
- Locality Name (L): (Optional) Select the Locality where the device is located. This could be a town, city, etc.
- Organization Name (O): (Optional)
- Organization Unit Name (OU): Company Name
- Common Name (CN): This MUST match what was set as the Subject Alternative Name
- Email Address (E): (Optional)
- Key Encryption Length: 2048
- Valid Duration: This is how long the Certificate will be valid. The default is 360 days. You can adjust this to any value you want, up to 10,950 days or 30 years.
Click on Generate.

Step 4
Select the Certificate that was just created and click on Select as Primary Certificate.

Step 5
Refresh the Web User Interface (UI). Since it is a new certificate, you will need to log in again. Once you have logged in, go to VPN > SSL VPN.

Step 6
Change Certificate File to the newly created Certificate.

Step 7
Click Apply.

Installing a self-signed certificate
To install a self-signed certificate as a trusted source on a Windows machine, to eliminate the “Untrusted Server” warning in AnyConnect, follow these steps:
Step 1
Log into the RV34x series router and navigate to Administration > Certificate.

Step 2
Select the default self-signed Certificate and click on the Export button to download your Certificate.

Step 3
In the Export Certificate window, enter a password for your Certificate. Re-enter the password in the Confirm Password field and then click Export.

Step 4
You will see a pop-up window to notify that the Certificate has been downloaded successfully. Click Ok.

Step 5
Once the Certificate has been downloaded to your PC, locate the file, and double click it.

Step 6
The Certificate Import Wizard window will appear. For the Store Location, select Local Machine. Click Next.

Step 7
On the following screen Certificate location and information will be displayed. Click Next.

Step 8
Enter the Password you selected for the Certificate and click Next.

Step 9
On the next screen, select Place all certificates in the following store and then click on Browse.

Step 10
Select Trusted Root Certification Authorities and click OK.

Step 11
Click Next.

Step 12
A summary of the settings will be displayed. Click Finish to import the Certificate.

Step 13
You will see a confirmation that the Certificate was imported successfully. Click OK.

Step 14
Open Cisco AnyConnect and attempt to connect again. You should no longer see the Untrusted Server warning.
Conclusion
There you have it! You have now successfully learned the steps to install a self-signed certificate as a trusted source on a Windows machine, to eliminate the “Untrusted Server” warning in AnyConnect.
Cisco AnyConnect – Untrusted VPN Server Blocked!

If you are seeing this you’re using the (default) self signed certificate, or you connected to an IP address rather than the FQDN. But unlike before, you can now ‘lower’ the security so it does not warn you every time.
Solution
1. From the warning screen (shown above) select ‘Change Settings…’.
2. Untick the ‘Block connections to untrusted servers’ option.

Or if you are on OSX

3. Now when you connect, you get the option of suppressing the warnings for this VPN connection.
Untrusted server blocked cisco anyconnect что делать
This error appears when attempting to make a connection to the VPN.

Select the gear icon.

Select VPN, and then select Message History.

These type of errors are usually some SSL/TLS issue.
Run a Wireshark capture on the PC getting this error, and see if there is some issue with the key exchange.

In this example, when the error appeared, the Event Viewer captures certificate related issues.

Did you find this article helpful?
If so, consider buying me a coffee over at 
Untrusted server blocked cisco anyconnect что делать
AnyConnect не смог установить соединение с указанным безопасным шлюзом
По какой причине AnyConnect не смогла установить соединение с указанным сообщением об ошибке безопасного шлюза?
- Проблема с антивирусом или брандмауэром: Антивирусное программное обеспечение может иногда вмешиваться в процесс подключения VPN-клиента AnyConnect и не разрешать ему подключаться к внешним сетям или серверам по соображениям безопасности. Много раз это заблокирует много входящих и исходящих соединений. Таким образом, вы не сможете подключиться к своему любимому VPN с помощью Anyconnect.
- Неправильная конфигурация клиента: Если вы неправильно настроили свой клиент Anyconnect и сохраненные в нем конфигурации VPN неверны, тогда вы столкнетесь с проблемами при установлении успешных соединений.
- Интернет ограничения: Время от времени ваш провайдер может заблокировать IP-адреса некоторых стран, и вы не можете сознательно пытаться подключиться к VPN той же страны, которая была заблокирована вашим провайдером. Тогда вы столкнетесь с проблемами.
Решение 1. Отключение антивируса
Отключить антивирус
Решение 2. Остановите службу подключения к Интернету
- Нажмите Windows + R и введите services.msc
- Когда откроется окно с сервисами, выполните поиск Общий доступ к интернету оказание услуг. Щелкните правой кнопкой мыши и выберите Стоп.
Остановка службы ICS - Затем выйдите из Сервисы окна, закрыв его.
Решение 3. Отключите общий доступ к подключению к Интернету (ICS)
- Откройте панель управления
- Идти к Сеть и Интернет-обмен а затем нажмите Смените настройки адаптера.
Центр коммуникаций и передачи данных - После этого вам нужно будет щелкнуть правой кнопкой мыши на подключение к общей сети, а затем нажмите на свойства.
- В окне свойств нажмите на разделение
- Оказавшись там, вы должны снять флажок с надписью «Разрешить другим пользователям сети подключаться к Интернету через этот компьютер».
- После этого нажмите ОК.
Решение 4. Выберите опцию Подключиться к текущей сети в AnyConnect VPN.
- Открой Клиент AnyConnect, и где вы видите сеть написано, щелкните правой кнопкой мыши на нем.
- Нажмите на «Подключаться только к текущей сети».
Клиент Cisco AnyConnect
Решение 5. Попробуйте альтернативное соединение
Untrusted server blocked cisco anyconnect что делать

| Страница 1 из 1 | [ Сообщений: 2 ] |
Connect to Untrusted VPN Server using Cisco AnyConnect via command line in Windows
I have 2 VPN and sometimes I should switch them very often. I decided to create .bat file which could connect to desired VPN with credentials set in this file.
So I create .bat file with following code:
Where 1.txt contains credentials of VPN #1 which has trusted cerficate. here’s what 1.txt contains:
Where 1 goes for GROUP with number 1.
The second VPN is untrusted and I have this prompt awaring me what VPN is untrusted. I used similar code for .bat file:
And following data in 2.txt:
(«y» goes for accepting untrusted server)
But now it says «Login failed» after entering password is prompted and then it appears in loop and never stops.
The question is: how should I modify my 2.txt file to make script connect to VPN #2?
1 Answer 1
AnyConnect’s behavior with untrusted server handling is detailed in the admin guide. Please refer to it for details.
If your client is configured to block connections to untrusted servers, first your input text needs to be modified to change the preference to accept connections. This is the case of handling the red prompt (Untrusted error) as mentioned in the admin guide. Text input —
Once you saved the preference, you have to re-initiate the connection. This time client will provide options to continue connection and import the certificate as well. Among other certificate errors, AnyConnect will allow user to import the certificate only if the source is untrusted. For example, if the certificate is expired, user can not import the certificate. This is the case of handling the white prompt (Untrusted warning).
In your text input, you are actually missing the input for importing the certificate. So, try —