-
Why can't I ping servers over VPN when IKEv2 VPN is established on SecuExtender?
Question: IKEv2 VPN is established on SecuExtender. However, I cannot ping the gateway IP of USG FLEX or servers in LAN. Answer: Review the Two-Factor Authentication (2FA) settings:* Navigate to Object > Auth. Method > Two-Factor Authentication > VPN Access. * Check if 2FA is enabled for all VPN services and users. * If…
-
How to resolve SecuExtender VPN Error Code 70?
Question: I am encountering Error Code 70 while trying to activate SecuExtender VPN, even though I have administrative rights. How can I resolve this? Answer: Error Code 70 typically indicates that the VPN client cannot access the licensing server to get the authorization token needed for activation. To resolve this issue,…
-
How to Resolve VPN Certificate Issues Between uOS and ZLD Devices?
Question: What should I do if the self-generated certificate from uOS can't be used for IKEv2 VPN on ZLD devices? Answer: If you encounter an issue where a self-generated certificate from a uOS device cannot be used for an IKEv2 VPN gateway profile on ZLD devices, follow these steps: * The issue arises due to the ZLD VPN…
-
Why does the L2TP VPN not work on Windows 10 but works fine on Windows 11?
Question: Why does the L2TP VPN not work on Windows 10 but works fine on Windows 11? Answer: This issue can be related to certain Windows updates that interfere with VPN connections. Specifically, the patches KB5036893 and KB5036892 released by Microsoft have been known to break VPN functionality. Suggestion: To resolve…
-
Is SecuExtender compatible with Microsoft SurfacePRO with ARM processor?
```html Q: Is SecuExtender compatible with Microsoft SurfacePRO with ARM processor? A: No, SecuExtender is not compatible with ARM processors. While the installation may complete successfully, the application will not run on ARM-based devices. It is recommended to use Windows built-in VPN for devices running on ARM…
-
Why can't you establish an SSL VPN connection with the USG Flex/ATP models?
Question : While establishing the SSL VPN connection, it will be disconnected shortly. Why can't you establish an SSL VPN connection? Answer : The possible reason is that Two-Factor Authentication for SSL VPN Access is enabled, but the user account has not been activated yet. Please disable this option, as shown below:…
-
How to fulfill split tunnel for Windows native VPN with IKEv2?
Question: How to fulfill split tunnel for Windows native VPN with IKEv2? Answer: In the current design, Windows native VPN interface can't separate Internet traffic from VPN tunnel. The only way to fulfillit is to create an additional routing on your PC. Disable PC default gateway from your VPN interface. 1.Go to Control…
-
Does Windows native VPN support split tunnel?
Question: This problem is on the Windows native VPN, it does not support split tunnel, so even set it as a split tunnel, Windows still does not create a route after installing the script. Answer: No. The problem is on the Windows native VPN, it doesn't support split tunnel. So even we set it as split tunnel, Windows still…
-
L2TP VPN doesn't work on Windows 10, but it works perfectly on Windows 11. What should I do?
Question My L2TP VPN on Nebula doesn't work on Windows 10, but it works perfectly on Windows 11. What should I do? Answer It looks like the issue you're experiencing is related to specific Windows updates on Windows 10. The patches KB5036893 and KB5036892 have been reported to break VPN connections. To resolve this issue,…
-
Can we export the cfg from a perpetual VPN client and import it into time-based VPN client?
Question Can we export the configuration file from a perpetual VPN client V3.8.204.61.32 and import it into a time-based VPN client V7.7.40.019 or V6.6.87.108? Answer Since the feature sets of the perpetual VPN client and the time-based VPN client are different, we can not import the configuration from a perpetual VPN…
-
Intel® Killer™ Control Center casue SSL VPN disconnecting immediately
If you are experiencing SSL VPN disconnecting immediately after connecting, it might be related to the Intel's Killer Control Center. To troubleshoot this issue, follow these steps: Disable the Killer Network Service. If disabling the service resolves the problem, please contact Zyxel Support for further helps
-
How do I set up NAT port forwarding for remote AP usage on the firewall?
Scenario : Users may wish to use the remote AP service behind a NAT scenario. For example, in the topology below, the remote AP will establish a VPN service to the destination firewall USG Flex 100. Remote AP === internet === USG Flex 200 === (NAT ports forwarding) === USG Flex 100 Users may wonder how to set up NAT port…
-
WebGUI show Site to Site VPN is up but traffic cannot pass through
Checking: 1)You have allow ESP Protocol from WAN to Device. Firewall cannot decrypt packets without allowing ESP rule. 2)You have allow rule for zone "IPsec_VPN" if you use Policy based VPN (If you customize the VPN zone, please make sure you have the corresponding allowed rules) 3)Check you have correct static…
-
Why the site-to-site VPN tunnel will disconnect hourly? How to reslove it?
Scenario : Users may encounter a situation in the site-to-site VPN tunnel that will disconnect hourly. This article will guide you on how to identify the possible reasons and resolve this problem. Answer : The possible reason for the site-to-site VPN disconnecting hourly is that the Phase 2 SA Lifetime is set to 3600…
-
SecuExtender SSLVPN can't connect
Symptom: 1)SSLVPN can not connect on Windows SecuExtender clients, but always can connect on MacOS clients. 2)You have Destinat NAT to SSL Port on upper device, which means the port have been translated, For example. Firewall_IP:50000 → Firewall_IP:10443 (SSLVPN Port) Workadound: Since requst from windows SecuExtender…
-
Sign self-cerfictate for remote VPN
Scenario: You need to sign a self-certificate since the original cerficate had expired .And you tried to sign from Firewall GUI. Solution: For remote VPN certificate usage, You need to be awared for these 1)Key Type must be "RSA-SHA256" 2)Extended key Usage must contain "IKE Intermediate"
-
What does "Ignore Don't Fragment setting in IPv4 header" in VPN connection page?
Question: What does "Ignore "Don't Fragment" setting in IPv4 header" in VPN connection page? Answer: Select this to fragment packets larger than the MTU (Maximum Transmission Unit) that have the “Don't Fragment” bit in the IP header turned on. When you clear this the Zyxel Device drops packets larger than the MTU that have…
-
Why can't we select a certificate in VPN Phase 1 for authentication?
Question: I can import a third-party certificate to FLEX/ATP without any errors. However, I am unable to select this certificate for VPN phase 1 authentication. What could be the issue? Answer: ZLD does not support ECDSA certificates in the VPN module, so we cannot select them in Phase 1. Please sign the certificate again…
-
Implement NAT over IPSec VPN by Route-Based VPN
Topology & Scenario: Your headquarter office may have many IPsec VPN tunnels with Branch, However, all branch offices have the same subnet for example 192.168.11.0/24. To meet the application, need a fake subnet represent for each Branch which means the headquarter only know the fake subnet. For example: 192.168.100.0/24 →…
-
Implement NAT over IPSec VPN by Policy Based VPN
Topology & Scenario: Your headquarter office may have many IPsec VPN tunnels with Branch, However, all branch offices have the same subnet for example 192.168.11.0/24. To meet the application, need a fake subnet represent for each Branch which means the headquarter only know the fake subnet. For example: 192.168.100.0/24 →…