-
Configuration migration best practice
Zyxel migration best practices focus on using the Zyxel Firewall Configuration Converter to migrate settings from older USG/ATP/VPN models to new USG FLEX H-Series. Essential steps include taking a full configuration backup (startup-config.conf), updating firmware, using the automated tool, and manually validating security…
-
How do I resolve the "The value in this field is a duplicate" error when configuring a VLAN ID?
Question: How do I resolve the "The value in this field is a duplicate" error when configuring a VLAN ID on the USG FLEX H? Answer: The error message "The value in this field is a duplicate" indicates that the VLAN ID you are attempting to configure (e.g., VLAN ID 11) is already in use on another interface. To resolve this…
-
Why does the NCC event log show a “logs were dropped” message on USG FLEX H models?
Question: Why does the NCC event log show a “logs were dropped” message on USG FLEX H models? Answer: The reason is that device local logs currently display up to maximum 2,048 entries at a time. Any additional logs are dropped and therefore not shown on the NCC side. NCC will instead display a message such as “193 logs…
-
APC: New Country Support
APC - New Country Support To support global deployments, the AP Controller now includes expanded country code support for Sri
Lanka. Requirements for Support * Firewall Firmware: Must be running version 1.39 or later. * AP Firmware: Managed Access Points must be updated to version 7.12 or 7.40, depending on the model. This…
-
VPN Traffic Statistics Enhancements
VPN Traffic Statistics and Usage Monitoring A new GUI enhancement provides deeper visibility into VPN performance, allowing administrators to monitor tunnel utilization more effectively. New Monitoring Metrics * Usage Percentage: The VPN status page now displays a percentage of usage for each individual VPN tunnel, making…
-
APC: SSID Scheduling Enhancements
APC - SSID Scheduling The AP Controller (APC) features have been updated to include SSID Scheduling, bringing the standalone and on-premise controller experience in line with the Nebula cloud style. Key Implementation Details * Advanced Mode: To access scheduling features, administrators must enable "Advanced Mode" within…
-
SSL VPN Authentication with OIDC External Groups
SSL VPN with OIDC External Groups Building on the OpenID Connect (OIDC) support introduced in previous versions, Zyxel firewalls now support OIDC External Groups specifically for SSL VPN authentication. Configuration Workflow * Server Setup: Configure the OIDC server settings (e.g., Microsoft Entra ID) and verify…
-
CLI Script Support for Advanced Configuration
Advanced CLI Script Support The latest release introduces the ability for administrators to upload and execute CLI scripts directly through the firewall's web interface. This is ideal for deploying consistent configurations across multiple branch offices or performing complex object modifications. Script Requirements *…
-
Firmware Upgrade Policy and Exclusions
Official Firmware Upgrade Policy To ensure reliability, especially for customers using specialized firmware builds, Zyxel has refined its firmware upgrade policies across cloud and local management platforms. Firmware Categories and Upgrade Rules * Official and Beta Versions: Standard official releases (e.g., C0) and Beta…
-
Firmware Upgrade Priority: Stable vs. Latest
Firmware Upgrade Priority Enhancement Starting with uOS 1.39, Zyxel introduces a new firmware categorization system to give administrators better control over their update cycles. Users can now choose between Stable and Latest firmware types. Firmware Type Definitions * Stable (Default): Versions that have undergone…
-
Let's Encrypt Certificate Support in uOS 1.39
Let's Encrypt Certificate Support uOS 1.39 introduces native support for Let's Encrypt, a free and automated Certificate Authority (CA). This feature allows Zyxel firewalls to automatically request, install, and renew trusted certificates, eliminating the manual effort and cost associated with traditional CA services. Key…
-
Configuring Cloudflare as DDNS Provider
Modern Dynamic DNS Support Zyxel firewalls now support Cloudflare as a standard DDNS provider, offering a more secure and modern alternative to traditional services. Security via API Tokens Unlike traditional DDNS services that rely on usernames and passwords, the Cloudflare integration uses API Tokens and Zone IDs. This…
-
H Series DHCP Lease Live Tool
Real-Time Network Monitoring To assist with network troubleshooting and client management, a new live tool for DHCP Leases has been added for the USG Flex H series in the Nebula Control Center. Tool Overview This tool provides a real-time view of all IP addresses currently assigned by the firewall's DHCP server.…
-
IPS Bypass Control for Trusted Applications
Optimizing IPS Performance Zyxel has introduced IPS Bypass Control to address high CPU usage scenarios, particularly in environments with heavy encrypted UDP traffic like schools or campuses. The Challenge of Encrypted Traffic Traditional IPS inspection often struggles with encrypted UDP protocols such as QUIC or media…
-
H Series Application Bandwidth Limit Feature
Granular Traffic Control The USG Flex H series now supports Application Bandwidth Limiting, a feature previously available on ATP and USG Flex firewalls. This allows administrators to either block specific applications entirely or restrict their bandwidth consumption to ensure critical business services remain performant.…
-
H Series SSL VPN with NID FS Support
Modernizing Remote Access Zyxel has expanded NID FS support to SSL VPN connections for the H series firewalls. This integration enables the use of modern OIDC-based authentication for remote workers. OpenVPN Connect Support Because the standard SecuExtender software does not yet support OIDC/NID FS, this feature is…
-
Unusual Admin Login Detection
Securing Management Access To enhance security for firewall management, Zyxel has introduced the Unusual Admin Login detection feature. This feature monitors login attempts and alerts administrators to suspicious activity that might indicate compromised credentials. How Detection Works The system utilizes a 30-day sliding…
-
H Series Captive Portal with NID FS Integration
Identity Federation for Captive Portals The USG Flex H series now supports Captive Portal authentication integrated with Zyxel's Nebula Identity Federation Service (NID FS ). This allows for a more streamlined authentication flow using external Identity Providers (IdPs) like Google Workspace, Microsoft Entra ID, or Zyxel's…
-
Device Health Anomaly Detection Enhancement
Enhancing Network Visibility with AI Secure Reporter has introduced significant enhancements to its Device Health Anomaly Detection feature, primarily targeting USG Flex 500H and 700H models. This feature utilizes AI to establish a performance baseline from the previous week, monitoring critical metrics such as CPU usage,…
-
Why my SIP server/VoIP service can't work after upgrading from ZLD to uOS (USG FLEX H)?
uOS does not support SIP transformations function. If your SIP server behind the firewall and it requires SIP transformations, please check with SIP server vendor how to work without SIP transformations. If it doesn't require SIP transformations, please check the SIP server's setting and the NAT rules on the firewall.