Best Of
Re: Odd 2FA Security Issue With The USG40
I would guess, that maybe the former session/s get cached and since it's the same client/machine the credentials are still valid? Or the 2FA has a general grace period per user/machine?
Are the links you receive maybe even the same?
I would try logging in, clicking the 2FA, logging out immediately, logging in, compare the links.
Next I would try different clients and see if the 2FA can be skipped with those too.
If it just applies to the same client, the real world implications would exist, but the chances of exploiting this are very slim.
Re: Odd 2FA Security Issue With The USG40
Hi @JCE,
Can you test again and check if the IP shows up in twofa-ipsec-ip? It should be listed in twofa-ipsec-ip before clicking the authorization email.
Once you click the authorization email, it will be delisted from twofa-ipsec-ip.
Here are the steps:
- Connect the VPN client.
- Type the CLI command "debug system ipset" to check if the VPN client's IP address is listed in twofa-ipsec-ip."
e.g.
Name: twofa-ipsec-ip
Type: hash:ip
Revision: 3
Header: family inet hashsize 1024 maxelem 65536
Size in memory: 16496
References: 2
Members:
X.X.X.X <= You should be able to see the IP address in the member list before clicking the authorization email
Re: SMS 2FA On Usg 40 (Latest FW) Question For UK Based Unit
Hi @JCE ,
You can use ClickSend to send SMS for 2FA. Please refer to the link below for instructions on how to configure two-factor authentication (2FA).
https://kb.zyxel.com/KB/searchArticle!viewDetail.action?articleOid=018012&lang=EN
Re: USG Flex 100 L2TP VPN not letting me access shared folders of the LAN
windows firewall
Re: Trunking port on GS1200-5/GS1200-8?
The configuration I posted in september 2019 needed only minor changes to the GS1900-24E setup (as shown in the included image here).
Since I changed it to the following settings, everything works now as I wanted to.
I have 2 separated VLANS for all wired connections and two WIFI networks, one for VLAN1 and the other one for VLAN 100.
So far I was very happy with this.
Re: GS1200-8 802.1Q VLAN: Must all ports be connected to VLAN 1?
Re: NWA50AX & NWA55AXE Email Log option disappeared
Hi @NickU ,
You can download the full CLI-reference manual for the NWA/WAC/WAX Series here.
By the way, you also can download other materials at Zyxel Download Library
