-
Recovery steps for USG FLEX/ATP Series with Device HA Firmware Update Fail.
Symptom: Device
HA mode update firmware through “Cloud Firmware” upgrade, the network services
is keep running on active device and you may get dialog with “Device HA Pro
Firmware upload is in progress…” on GUI keep loading. And the firmware version
on active device is not upgrade to the new version, but passive device…
-
Cloud firmware upgrade -- On-premises mode
This tutorial introduces how to upgrade the the firmware to resolve the App-Patrol signature issue. Note: 1. This procedure can apply to premise mode devices including: USG20(W)-VPN/ATP100(W)/ATP200/ATP500/ATP700/ATP800 USG FELX100(W)/ USG FELX200/ USG FELX500/ USG FELX700 2. No matter which App-Patrol version is
installed…
-
Recovery Steps for USG FLEX/ATP Series Application Patrol Signature Issue
Symptom: The App Patrol signature release V1.0.0.20220310.0 may create
parsing error on device for both on-premises and on-cloud modes, application patrol
daemon will not work well after updating this new signature though the rest of
UTM features keep running. However, the worst case is that device may get stuck
if device…
-
How to Use Two Factor with Google Authenticator for Admin Access?
In previous firmware versions, USG supports
pin code by SMS/Email as two-factor authentication method. However, SMS-based
two-factor authentication is not safe. Compared to SMS-based method, Google
authenticator is the most secure method to receive verification code for
2-factor authentication. Google authenticator gives a…
-
Guidance to help identify, remediate and defend against this security incident
We strongly
recommend to upgrade your device firmware to ZLD4.65/5.02 in order to mitigate the risk of this security
incident Note: ZLD4.65
for ZyWALL USG Series/ZyWALL 110/310/1100 ZLD5.02
for ZyWALL ATP Series/USG FLEX Series/VPN Series You
can do cloud auto upgrade by clicking the cloud icon. Or download
firmware from…
-
How to mitigate the threat of the security incident
* Change the admin-type accounts' password We strongly recommend to change password on all of your admin-type accounts for better protection. * If
you allow traffic from Internet to your device with WebGUI and SSL VPN tunnel,
you can follow these steps to protect your device. 1. Add IP address object(s) to trusted…
-
How to Activate 3-Month Secure WiFi License
This article is only for activating the 3-Month Secure WiFi License. A. On-Cloud Mode (Activate on MyZyxel.com) 1. Log into MyZyxel.com with your account. 2. Navigate to Device Management > My Device, click on the MAC Address hyperlink
of your device. 3. In the Linked Services tab click on Details button of Secure WiFi…
-
If my device running on ZLD 4.60C0, how to upgrade it to ZLD4.60 P1?
To
upgrade your firmware to the ZLD v4.60 patch 1, there are several methods that
can achieve this purpose. Method 1. Download the
firmware from myZyxel portal and upgrade the firmware from LAN locally. Step
1: Login
to myZyxel portal, after logging into the portal, you will see your registered
device list in Device…
-
How do I check unauthorized users trying to access my device? Can I check the login history?
You
can find it from the device log directly from MONITOR > Log > View Log. In
“View Log”, choose the “User” category. When
users successfully login to the device, the device will show logged in user
information (and so do login failed users).
-
If firmware upgrading is impossible at this moment, what else I can do to avoid this vulnerability?
1. If
it is not absolutely necessary to manage devices from the WAN side, you can
turn off the FTP/TELNET/SSH/HTTPS/HTTP/SNMPv3 service on WAN. These services are disabled
by default, so you won’t have to do so unless you have enabled it in the past. Go to CONFIGURATION > Security Policy >
Policy Control and check the…
-
Is my ZyWALL/USG/VPN/ATP/USG FLEX firmware version affected by CVE-2020-29583? How to check?
Only
the Running version 4.60(XXXX.0) is affected. Go
to MAINTENANCE > File Manager >
Firmware Management > Firmware Status and check the version of Running partition. We strongly suggest
you upgrade the device to the latest version 4.60(XXXX.1). The device
is not affected when the version of Running
partition is…
-
USG FLEX Frequently Asked Questions
The following sections cover product portfolio, license service, and more. Part1 Product Portfolio Q1: Why USG FLEX? Zyxel is proud to announce the completely new ZyWALL USG FLEX series, tailored-made for SMB customer who is looking for worry-free security protection. Packed with top-notch threat intelligence,…
-
Why does the firmware version show as V4.35(VVVV.0)/4.35(WWWW.0) /4.35(ZZZZ.0) /4.35(YYYY.0) ?
The behavior was mentioned on page 20 of the release note. Select the Standby firmware row and click Reboot. After the device reboots, the correct firmware version is able to be shown on the web GUI.
-
How to setup SecuReporter on USG and server side?
SecuReporter is a server can analyze all of traffic that pass through by USG. You can follow these steps to setup all of it. On USG side: * Enable SecuReporter license. (30 days for free tail) * Enable SecuReporter service. * Enable "Collect Statistics" in all of UTM functions. (Monitor > UTM Statistics) On SecuReporter…
-
How to recovery database when it is broken.
When file system broken, the device is unable boot up successfully. And may display error log like: mount: wrong fs type, bad option, bad superblock on /dev/loop0, missing codepage or other errorYou can the follow this steps to recovery device database.(Console cable is required) (1) Plug-in power cable and enter to debug…
-
How to backup running configuration if forgot password?
Note: You must physically beside at your device, and using serial connection for below SOP You can follow these steps to backup device running config: 1. Reboot device 2. Enter debug mode and type “atkz –b” 3. Use “atgo” booting device 4. Now device will reset system-default configuration and backup old startup-config.conf…
-
How to get different privileges by RADIUS authentication
Background: In the
ZyWALL USG, you can
configure local users
with different privileges such as admin, limited-admin, users
and guests. This allows users
to have different privileges when they login to the USG.
For ext-user accounts, which are authenticated by an external RADIUS server, the USG sets
the privilege for…
-
The procedure to configure the email log?
Step-by-Step: Step 1: Go to Configuration > Log & Report > E-mail Daily Report > Select the Enable Email Daily Report checkbox > Enter the necessary info of Email Settings/Schedule/Report Item > Click on Apply Log Settings Step-by-Step: Step 1: Go to Configuration > Log & Report > Log Settings > Select System Log >…
-
How can I upgrade the firmware by using FTP?
You can access the device by using a console and enable FTP on the USG. On your PC, use CLI commands to access the USG by FTP. Set the binary and add the file.(paste the path of bin file) After clicking Enter, the firmware starts to upgrade. VERIFICATION: If the configuration is correct, you will see the “Transfer…
-
How to Configure Single Sign-on with ZyWALL/USG and SSO agent?
SETUP/STEP BY STEP PROCEDURE: (Download SSO agent : http://www.zyxel.com/tw/zh/products_services/sso_agent.shtml?t=p) Configuration example Configuring AAA server ▪Configuring AAA server on ZyWALL/USG▪CONFIGURATION > Object > AAA server > Active Directory > Click “Edit”▪Edit AAA server parameters Configuring Auth. method…