The certificate needs to be trusted and match the FQDN (not IP) of your external connection point. Basically this won't work in your current config. You'll need at least to have DNS setup and a A record to your public IP and a certificate for that FQDN. There are free cert services such as StartSSL.