-
Is Two-Factor authentication mail able to be sent to the email address from the Active Directory?
Enable Two-Factor Authentication for VPN access and move ad-users to selected User/Group. On Active Directory, configure email address for the ad user “user3”. Make sure the email address is also shown in Attribute Editor > mail. Mail is sent to the AD user “user3”. In MONITOR > Login Users, user3 logged in as SSL VPN (two…
-
What does the result of the command "debug system show cpu status" mean?
CPU utilization: 91 % (system: 1 %, user: 2 %, irq: 0 %, softirq 90 %) system: the percentage of the CPU utilization spent on running in kernel space user: the percentage of the CPU utilization spent on running the user space process irq: the percentage of the CPU utilization spent on handling hardware interrupts softirq:…
-
How to enter the login page of the legacy device?
Sometimes you might encounter a situation that
using the latest version browser and cannot enter the login page of the legacy device
which is end-of-life (such as ZyWALL USG 100 or other legacy devices). This
article will guide you on how to resolve this situation. The
Chrome browser would return the below error message:…
-
How to set up Gmail for gateway mail notification?
Notification emails are used to
notify network administrators about events on the Zyxel device, allowing a
quick response to any issues. This example illustrates how to
configure Gmail for gateway mail notification. Configurations Create an Application Password in Gmail To generate application password in Gmail, we need to…
-
How to use iCloud email to send Email Daily Report?
How to use iCloud email
to send Email Daily Report? This example illustrates how to use iCloud email to send Email Daily
Report from Zyxel Firewall. Before Begin Please make sure the firewall works normally and the user has an iCloud
email account. Set up iCloud First, login to Apple iCloud ID manage page and add an…
-
Recovery steps if you cannot update the firmware in the running partition
If
you cannot update the firmware in the running partition Here
is a situation, if you notice you cannot update firmware to the newer firmware
such as from V4.65P1 to V4.72. You can follow the below steps to recover your
FW update function: STEP1.
Back up and download the startup-config.conf of the running partition.…
-
Failed to upgrade to the new ZLD5.21 patch 1: why and how to resolve it?
Zyxel had just released the new ZLD5.21 patch1, which fixed the parsing error in the Application signature V1.0.0.20220310.0. However, Zyxel support had received support cases, where the firmware upgrade operation failed in certain conditions, in both on-premise mode or Nebula-managed mode. This supplement document is…
-
Recovery steps for USG FLEX/ATP Series with Device HA Firmware Update Fail.
Symptom: Device
HA mode update firmware through “Cloud Firmware” upgrade, the network services
is keep running on active device and you may get dialog with “Device HA Pro
Firmware upload is in progress…” on GUI keep loading. And the firmware version
on active device is not upgrade to the new version, but passive device…
-
Cloud firmware upgrade -- On-premises mode
This tutorial introduces how to upgrade the the firmware to resolve the App-Patrol signature issue. Note: 1. This procedure can apply to premise mode devices including: USG20(W)-VPN/ATP100(W)/ATP200/ATP500/ATP700/ATP800 USG FELX100(W)/ USG FELX200/ USG FELX500/ USG FELX700 2. No matter which App-Patrol version is
installed…
-
Recovery Steps for USG FLEX/ATP Series Application Patrol Signature Issue
Symptom: The App Patrol signature release V1.0.0.20220310.0 may create
parsing error on device for both on-premises and on-cloud modes, application patrol
daemon will not work well after updating this new signature though the rest of
UTM features keep running. However, the worst case is that device may get stuck
if device…
-
How to Use Two Factor with Google Authenticator for Admin Access?
In previous firmware versions, USG supports
pin code by SMS/Email as two-factor authentication method. However, SMS-based
two-factor authentication is not safe. Compared to SMS-based method, Google
authenticator is the most secure method to receive verification code for
2-factor authentication. Google authenticator gives a…
-
Guidance to help identify, remediate and defend against this security incident
We strongly
recommend to upgrade your device firmware to ZLD4.65/5.02 in order to mitigate the risk of this security
incident Note: ZLD4.65
for ZyWALL USG Series/ZyWALL 110/310/1100 ZLD5.02
for ZyWALL ATP Series/USG FLEX Series/VPN Series You
can do cloud auto upgrade by clicking the cloud icon. Or download
firmware from…
-
How to mitigate the threat of the security incident
* Change the admin-type accounts' password We strongly recommend to change password on all of your admin-type accounts for better protection. * If
you allow traffic from Internet to your device with WebGUI and SSL VPN tunnel,
you can follow these steps to protect your device. 1. Add IP address object(s) to trusted…
-
How to Activate 3-Month Secure WiFi License
This article is only for activating the 3-Month Secure WiFi License. A. On-Cloud Mode (Activate on MyZyxel.com) 1. Log into MyZyxel.com with your account. 2. Navigate to Device Management > My Device, click on the MAC Address hyperlink
of your device. 3. In the Linked Services tab click on Details button of Secure WiFi…
-
If my device running on ZLD 4.60C0, how to upgrade it to ZLD4.60 P1?
To
upgrade your firmware to the ZLD v4.60 patch 1, there are several methods that
can achieve this purpose. Method 1. Download the
firmware from myZyxel portal and upgrade the firmware from LAN locally. Step
1: Login
to myZyxel portal, after logging into the portal, you will see your registered
device list in Device…
-
How do I check unauthorized users trying to access my device? Can I check the login history?
You
can find it from the device log directly from MONITOR > Log > View Log. In
“View Log”, choose the “User” category. When
users successfully login to the device, the device will show logged in user
information (and so do login failed users).
-
If firmware upgrading is impossible at this moment, what else I can do to avoid this vulnerability?
1. If
it is not absolutely necessary to manage devices from the WAN side, you can
turn off the FTP/TELNET/SSH/HTTPS/HTTP/SNMPv3 service on WAN. These services are disabled
by default, so you won’t have to do so unless you have enabled it in the past. Go to CONFIGURATION > Security Policy >
Policy Control and check the…
-
Is my ZyWALL/USG/VPN/ATP/USG FLEX firmware version affected by CVE-2020-29583? How to check?
Only
the Running version 4.60(XXXX.0) is affected. Go
to MAINTENANCE > File Manager >
Firmware Management > Firmware Status and check the version of Running partition. We strongly suggest
you upgrade the device to the latest version 4.60(XXXX.1). The device
is not affected when the version of Running
partition is…
-
USG FLEX Frequently Asked Questions
The following sections cover product portfolio, license service, and more. Part1 Product Portfolio Q1: Why USG FLEX? Zyxel is proud to announce the completely new ZyWALL USG FLEX series, tailored-made for SMB customer who is looking for worry-free security protection. Packed with top-notch threat intelligence,…
-
Why does the firmware version show as V4.35(VVVV.0)/4.35(WWWW.0) /4.35(ZZZZ.0) /4.35(YYYY.0) ?
The behavior was mentioned on page 20 of the release note. Select the Standby firmware row and click Reboot. After the device reboots, the correct firmware version is able to be shown on the web GUI.