To be more helpful, we probably need more information. However, judging from the error you listed, I would say the HTTP server in the router did not return a certificate to your VPN client.
One possibility is that your CA is doing manual CA enrollment (default), and you need to setup auto-enrollement by configuring a one time password on the CA database:
crypto pki server mycs password generate 75
The 75 in this case is says the password is valid for 75 mintues. Any enrollment that has this password will be automatically approved, not just submited.