-
How to mitigate DDoS Attacks?
Over the past few days, users have been subjected to a significant DDoS (Distributed Denial of Service) attack, causing widespread outages. The following signs will help you recognize if this is the case: If you have experienced the following problems in the past few days you have likely been subjected to a DDoS attack:…
-
How to Configure Scheduled Updates for the Geo-IP DB on USG Flex H models?
Question : How to Configure Scheduled Updates for the Geo-IP DB on USG Flex H models? Answer : Please navigate to the Web GUI path: Object > Address > GeoIP. To enable Auto Update and configure the day and time for scheduled updates of the GeoIP database, follow the instructions shown below:
-
How to update Geo-IP DB manually by Web-GUI on the USG Flex H models?
Question : How to update Geo-IP DB manually by Web-GUI on the USG Flex H models? Answer : Please navigate to the Web-GUI path : Object > Address > GeoIP> Click "Update Now" button to update the Geo-IP DB, as shown in below:
-
Why can't I block websites using the Web Content Filter on ATP and USG FLEX?
Question: Why can't I block websites using the Web Content Filter on ATP and USG FLEX? Answer: It is not a bug. The issue is related to the browser update with TLS 1.3 Kyber support introduced in May 2024. If you are experiencing issues with blocking websites using the Web Content Filter, please ensure that firmware on…
-
How can I check if SSL Inspection is working normally on the USG Flex H models?
Question : How can I check if SSL Inspection is working normally? Answer : Once SSL Inspection is set up successfully, whenever a client accesses the internet, the certificate will be replaced by the firewall's certificate. For instance, the user configures the SSL Inspection profile on the security policy of the USG Flex…
-
Opening the web site is very slow and logs appear "Service Unavailable" regarding to content filter
Question: It's very slow when opening website, and logs show Answer: This is because your network environment blocks our content filter’s external query IP. We recommend that you turn off the content filter/DNS threat filter as a workaround. And check whether there is any blocked on the device above.
-
How to Enable Safe Search on USG FLEX H Series?
Question: How to Enable Safe Search on USG FLEX H Series? Answer: Currently, Safe Search is not supported on the Zyxel USG FLEX H series firewall. The feature is not available in the current release, but it is planned for a future update.
-
USG FLEX H Series - External Block List
USG FLEX H Series - External Block List Overview The External Block List (EBL) is a feature that allows the firewall to import a text file hosted on an external web server. This block list contains IP addresses or URLs that should be blocked by the firewall. This is useful for enhancing security by preventing access to…
-
Do we need to add a security policy to allow DNS from LAN to the device when using DNS domain scan?
Question: In the ZLD series, if we want to enable the DNS content filter, we must create a security policy to allow DNS queries from the LAN to the device. For uOS, do we still need to add a security policy to allow DNS traffic from the LAN to the device when using a DNS domain scan? Answer: When the UTM DNS domain scan is…
-
What is the difference between the deny and reject in security policy?
Question: What is the difference between the deny and reject in security policy Answer: Deny: Select deny to silently discard the packets without sending a TCP reset packet or an ICMP destination-unreachable message to the sender. Reject: Select reject to discard the packets and send a TCP reset packet or an ICMP…
-
How to unlock blocked IP in USG FLEX H series?
Question If users enter wrong username/password too many times and get locked, how to unlock the account? Answer Check lockout IP usgflex200hp> show lockout-users Unlock lockout IP usgflex200hp> cmd lockout-users unlock ip 10.214.48.21
-
How to Configure Content Filter with HTTPs Domain Filter?
The Content Filter with HTTPs Domain Filter allows you to block HTTPs websites by category service. The filtering feature is based on over 100 categories that is built in USG Flex H such as pornography, gambling, hacking, etc. When the user makes an HTTPS request, the information contains a Server Name Indication (SNI)…
-
How to Configure DNS Content Filter
Compared to web content filter, DNS content filter is a stronger tool for SMB because it can restrict the number of attacks faced by network access, thereby helping to reduce the remediation workload of IT professionals. DNS content filter intercept DNS request from client, check the domain name category and takes a…
-
How to Configure Reputation Filter- URL Threat Filter
URL Threat Filter can avoid users to browse some malicious URLs (such as anonymizers, browser exploits, phishing sites, spam URLs, spyware) and allows administrator to manage which URLs can be browsed or not. This example demonstrates how to configure the URL Threat Filter to redirect web access after the client hits the…
-
How to Configure Reputation Filter- DNS Threat Filter
DNS Threat Filter is a mechanism aimed at protecting users by intercepting DNS request attempting to connect to known malicious or unwanted domains and returning a false, or rather controlled IP address. The controlled IP address points to a sinkhole server defined by the administrator. When a client wants to access a…
-
How to Block Facebook
This is an example of using USG Flex H UTM Profile in a Security Policy to block access to a specific social network service. You can use Content Filter and Policy Control to make sure that a certain web page cannot be accessed through both HTTP and HTTPS protocols. USG Flex H with Block Facebook Settings Example Note: All…
-
How to block the client from accessing a certain country using Geo IP?
The Geo IP offers to identify the country-based IP addresses; it allows you to block the client from accessing a certain country based on the security policy. When the user makes HTTP or HTTPS request, USG Flex H queries the IP address from the cloud database, then takes action when it matches the block country in the…