-
[Trade-Up Program] 🔄 Time to Trade Up: Say Goodbye to Legacy USG, Hello to Next-Level Securi…
Time to Trade Up: Upgrade Your Legacy USG and Unlock a Powerful New Experience.
-
Recovery Steps for USG FLEX/ATP Series Application Patrol Signature Issue (Jan. 2025)
Symptom: The App Patrol signature release V1.0.0.20250123.0 may create parsing error on device for On-premises mode, application patrol daemon will not work well after updating this new signature though the rest of UTM features keep running. However, the worst case is that device may get stuck if device did rebooting…
-
Zyxel USG FLEX and ATP series – Upgrading your device and ALL credentials to avoid hackers' attack
Zyxel team has been tracking the recent activity of threat actors targeting Zyxel security appliances that were previously subject to vulnerabilities and admin passwords have not been changed since then. Users are advised to update ALL administrators accounts for optimal protection. Based on our investigation, the threat…
-
Important Reminder for your Content Filter Service
At Zyxel, we are committed to providing you with the most advanced and secure services possible. In line with this commitment, we continuously enhance our Content Filter service to ensure top-notch security detection from Trellix. To ensure your service running stable and efficiently, please upgrade firmware to the latest…
-
How to solve the issue "ZTP is already enabled" on VPN series?
Symptom: Unable to access the web GUI. Access the web GUI but the page "ZTP is already enabled" appears. The device is on-premises mode and never deployed using ZTP. Q1. What are the impact model and version for this issue? Affected model Affected version VPN50 5.00 through 5.36(ABHL2)C0 VPN100 5.00 through 5.36(ABFV.2)C0…
-
What should I do if the device failed to be upgraded to the latest firmware?
Please follow the procedure to upgrade the firmware Step 1. Make sure you have on-site local support that able to reach the device Step 2. Unplug all WAN connections. Step 3. Access the device via LAN IP. Step 4. Copy startup-config.conf to recover.conf. Download "recover.conf" to your PC. Step 5. Switch to standby…
-
Routing public class c over VPN Tunnel
Hello, Here is our setup. Location A has public class C (1.1.1.0/24). Location B has a single public IP. Loc B has internal IPs 192.168.5.1/24. Both locations have ATP800 and are connected to each other VPN tunnel. Loc A vti IP 10.10.20.10. Loc B vti IP 10.10.20.20. On Loc A ATP, we have policy route to route 1.1.1.5 -…
-
multiple site to site vpn accessing the same resources.
This is not the typical vpn access that i usually setup and it has me a bit stumped. I have a site to site vpn that was setup to access a set of devices on the network. I'll try and explain this best I can. ips are just examples and there are 4 devices that need to be accessed. VPN-1 Site A (devices vlan…
-
IKEv2 and Windows 11 on standalone ATP500
Hi there, because the actual IPSec client from Zyxel does not support ARM proccessors, i had to configure VPN IPSec IKEv2 to use the buildin Windows 11 VPN client. That raises a bunch of questions: How can i use a trusted certificate instead of the "buildin". I cannot use the official bought FQDN based cert, because while…
-
USG110 upgrade
-
IPSec sessions on the firewall not terminated after a while of being idle?
I have the following scenario: I manually connect with a device (smartphone or notebook) and via IPSec VPN client (the ones generated by the USG-20W-VPN), StrongSwan resp. Win1x Client from outside. Now, when I take the device(s) again in WiFi range, they reconnect to the WiFi ergo the IPSec tunnel is not used anymore.…
-
USG Flex - VPN Logins into different subnets possible?
Hi guys, Before I dig deeper into the manual … Is it generally possible to have different VPN configurations to different subnets/VLANs simultaneously active on an USG Flex? Presently we've got two configurations active, one SSLVPN profile and another IPSec profile. The corresponding profile is automatically chosen…
-
USG Flex - extending a broadcast domain for WoL magic pakets?
We have running a server in one subnet, which is able to send magic WoL pakets into the own subnet in order to wake-up computers. Such magic paket will not be routed into other subnets. But now we've extended our network with an additional subnet (VLAN) and would like to wake-up computers from that new subnet as well, but…
-
Cannot send mail to two-factor authentication for SSL VPN
Hi, I would like to use two-factor authentication for SSL VPN access but from the logs I see this error and I can't understand what I should do. Thanks Max
-
wildcard in whitelists (on-premise)
Hello folks, Are there wildcards that can be used in Web Content Filter —> Trusted Web Sites and in DNS Content Filter —> Allowed sites ? for example *.google.com works with any 3th level domain? I refer to ATP / USG Flex Series, don't know if there are differences in H series Searched a little bit in the community but did…
-
no link in P1 port, in Flex200H device
Our company has a Flex200 firewall, and the service provider device is FiberHome AN5506-02-FG GPON Modem Router (configured PPPoE connection). We receive a Flex200H device for testing, to which, if we replace our own device, there is no link on anymore the WAN (P1) port It is plugged into any other device there is physical…
-
¿falso positivo?
¿es correcto el bloqueo de url2319.nexa.pro ? 2025-05-02 10:58:55warnURL Threat Filterurl2319.nexa.pro:Malicious Sites, SSI:N 192.168.xx.xx:63085 167.89.123.90:443 ACCESS BLOCK 2025-05-02 10:58:55warnURL Threat Filterurl2319.nexa.pro:Malicious Sites, SSI:N 192.168.xx.xx:63073 167.89.118.61:80 ACCESS BLOCK 2025-05-02…
-
Zywall 110 remove corrupted firmware from debug mode?
Zywall boots up but no webaccess. No ping on any port. Lots and lots of error suggesting all kind of files missing via console port though. Is it possible to erase the fimrware as the system seems to think it can start the firmware image. Some at command to wipe out the firmware?
-
Usg flex h with build in wifi
I was wondering if there will be an model of the flex h series with build in WiFi. There is an flex 100 ax, but i think in 2030 this will eol?
-
VPN100 IPSec VPN Issue
I have a Zyxel VPN100 and trying to get an IPSec VPN tunnel established with another device on another network It gets through phase 1 and phase2 and says the tunnel is built successfully. But then it always says IKE SA is disconnected and the tunnel collapses The VPN100 is behind another router that is not in bridge mode…
-
Moving Configuration between different models
I have now some ZyWALL 310 I wish to upgrade to a newer model. Can I move the configuration to the new firewall, probably a USGFLEX, or do I need to rewrite it from scratch ?
-
Legacy firmware for Zywall USG 200
Hi, I'm trying to upgrade the firmware from version 2.20(AQU.1) to the latest 3.30(AQU.7) I tried to upgrade directly to the latest version but I get the error that says the firmware is not compatible, I was looking for the intermediate versions but are not available anymore from the site ftp.zyxel.com. there is a way…
-
Zyxell ZyWall 110
Hello, I am the owner of ZyWall 110, which has been purchased second-hand. It is registered to my ZyXell account and has been updated. The device is located at the entrance of my network, where I have proxmox and QNAP servers. My primary question is how to configure LT2P and SSL VPN connections to my servers. I do not have…
-
H-serie firewall v1.32(ACLP.0), Gui Object-Schedule creation not possible. What is wrong?
I want to create a schedule plan to disable internet access on WAN port and to disable power on the poe port for energy savings during night hours. The stop time (05:30Hr) is later as the start time (00:30hr) on the same day. I failed to create a recurring schedule object in gui, by getting an error message. Entering the…
-
Locked out of admin account on USG FLEX 100W
Hi, I have been having a running battle with a USG FLEX 100W for over a year now. I keep getting locked out of the admin account after a period of time. This is despite repeatedly resetting and re-configuring the device on a couple of occasions. Typically, I would factory reset the device, reconfigure from scratch, set the…
-
Zyxel SCR50AXE change the MAC on WAN port.
Hello, how do I change the MAC address on the WAN port of the Zyxel SCR50AXE ?