To create the client to site configuration you will first need to create a certificate authority, certificate, and a user account on the router. For information on how to configure these. Please see:
How do I create a certificate authority
- On a computer or mobile device that is connected to your PR60X or PR460X router's network, access https://www.routerlogin.net. Your browser might display a security message, which you can ignore.
- A login window opens.
- Enter the router user name and password.
- The user name is admin. If you did not change your router's password during setup, enter password. The user name and password are case-sensitive.
- On the router dashboard, select VPN > Client-to-Site.
- Next, click the + button to create a new client-to-site configuration.
- Under the Tunnel Name field, add a descriptive name.
- Under the IPSec Profile field, select Default_Client_to_Site_IKEv2 profile.
- Under the Authentication Method select EAP-MSCHAPv2.
- Under the Server Certificate field, select the created certificate.
- Under the Local Identifier field, select Local WAN IP or FQDN.
- Leave Remote Identifier to ANY.
- In the Pool Range for Client LAN field, add the IP subnet range the clients will be connected to. This subnet range must differ than the subnet range already associated to the network on your router.
- Under the Custom DNS field the vaule is set to Auto and will use the DNS server provided by the PR60X or PR460X router.
- Click Apply to save the settings.
The configuration is now saved, and you can now connect remotely to the router on your Windows, macOS, iOS, and Android devices. For instructions on how to set up and connect on your device. Please see:
How to connect ikev2 in Windows
How to connect ikev2 in Android