-
2FA - two factor authentication | Auto setting Authenticator
Hello, Good morning, I'm using a firewall with several local users, two-factor authentication has been activated (especially by email) and it works correctly. I was wondering, is it possible to allow the end user to independently create the authenticator (google auth) without an admin enter in user management to enable it?
-
UsgFlex700 freezes almost daily
Hello, I have 2 Flex700 configured in HA, they are used as edge firewalls to connect remote locations via routed IPSEC tunnels + sslvpn for a few remote workers. They currently have ~25 ipsec tunnels which is nothing comared to their datasheet. I've been having issues with them freezing almost daily (they go completely…
-
USG Flex - Save your startup.conf before updating to 5.40 !!!
Just updated our USG FLEX 700 from 5.39 ABWD.1 to 5.40 ABWD.0. After the USG has restarted, we noticed that different config changes from 2 days ago were not longer available! Don't know, which config the USG uses after the update and reboot - but not our current (latest) running startup config. Fortunately we've saved our…
-
USG Flex 700 - Password change recommendation window - cannot be disabled
We're just commissioning our new USG Flex 700 (v5.35 ABWD.0), taking-over all settings from our USG110. Lot of typing work since a converter from USG110 to USG Flex 700 is not available. But anyway, this is not the problem. On each login the USG Flex is showing a password change recommendation window which contains a…
-
Does SecuExtender work on iPads?
Does SecuExtender work on iPads? Has anybody brought it to work?
-
Allgemeine VPN Frage zur Zyxel USG 100
Hallo, für folgendes Szenario bräuchte ich eure Hilfe: Ich habe 2 Zyxel USG 100, die durch einen Site-to-site IPSec VPN verbunden sind, das funktioniert schon seit Jahren.Der Kunde möchte jetzt noch von extern mit einem Apple MacBook, mehreren iPhones und iPads ebenfalls per VPN ins Netzwerk. Ich habe ihm für das MacBook…
-
remote LAN access from VPN SSL
Good morning everyone. I configured a VPN SSL on USG FLEX 100. The IP range assigned to VPN users is this: 192.168.100.70-192.168.100.80. For the rest I think I left everything at default, for example in the VPN SSL settings in the NETWORK EXTENSION LOCAL IP item I left 192.168.200.1. From home I connect without problems…
-
Interpreting the DNS Threat Filter report
Please help me understand what the following report means and how I can fix the problem. The client IP address in the report is the address of our internal domain controller DNS server. It is set as the primary DNS address on the client computers. Both the endpoints and the servers have endpoint-side antivirus. Where do I…
-
Why all firewall freeze?
I have unfortunately purchased various Zyxel firewalls for my customer.From the VPN100 to the Flex H series, all updated and in various networks and different contexts. But they all have one thing in common: they crash. After a month or two months the network crashes, the firewall becomes unreachable and there is no other…
-
Where is all the documentation for SecuExtender?
I bit the bullet and bought licenses for MacOS and Win11. I use the StrongSwan for Android and the Win11 clients and settings created by the Zyxel firewall wizard, and they work automatically just fine. Now, I need to know where to look after what on the firewall, in order to configure the SecuExtender VPN client. Where is…
-
Where to disable alert log for: "abnormal TCP traffic detected"
Presently lot of "abnormal TCP traffic with destination port zero" is detected, which caused an email alert log each time.Now I searched for the connected log settings where we could disable these kind of alert log. We found: Log & Report > Log Settings > System Log > Table "Active Log and Alert" and have disabled the…
-
Problem to connect ftp with 1990 port - USG Flex 100
Hello i'm try to connect an ftp server with port 1990 but not works. It works with statandard port and works if i connect form other lan not connect to firewall I not set any limitations form lan to wan Thanks
-
Can you please send me 404XZ0D0.bin - ZyWALL 2 Plus
Can you please send me a copy of latest firmware for ZyWALL 2 Plus which is apparently 404XZ0D0.bin in a PM ? Those boxes are not in production but for training for the junior IT students. Thank you, Marc Dumont
-
USG FLEX 500 FIREWALL FREEZES AND REBOOTS
I'm having issues with two USG FLEX 500s in HA (High Availability). Every 2 to 4 days, they freeze (PWR+SYS LEDs off and port LEDs blinking)." The tests I have performed are: Shut down the passive firewall and leave only the master active. Shut down the master firewall and leave only the passive one, promoted to master The…
-
Zyxel USG Flex series - any way to send DEBUG system log through e-mail?
Is there any way to send DEBUG system log through e-mail? No option in the settings, only NORMAL and ALERT.
-
Nebula GEO IP Blocking
In Nebula if you wished to use the GEO IP Blocking feature, it used to restrict you to only inputting 10 countries per rule. However I am now finding that it allows me to add more than 10 countries in a sigle GEO IP Filtering rule. Has the 10 country limit been removed entirely? Or has it been raised to a higher number of…
-
no link in P1 port, in Flex200H device
Our company has a Flex200 firewall, and the service provider device is FiberHome AN5506-02-FG GPON Modem Router (configured PPPoE connection). We receive a Flex200H device for testing, to which, if we replace our own device, there is no link on anymore the WAN (P1) port It is plugged into any other device there is physical…
-
IPSec sessions on the firewall not terminated after a while of being idle?
I have the following scenario: I manually connect with a device (smartphone or notebook) and via IPSec VPN client (the ones generated by the USG-20W-VPN), StrongSwan resp. Win1x Client from outside. Now, when I take the device(s) again in WiFi range, they reconnect to the WiFi ergo the IPSec tunnel is not used anymore.…
-
USG Flex - extending a broadcast domain for WoL magic pakets?
We have running a server in one subnet, which is able to send magic WoL pakets into the own subnet in order to wake-up computers. Such magic paket will not be routed into other subnets. But now we've extended our network with an additional subnet (VLAN) and would like to wake-up computers from that new subnet as well, but…
-
USG110 upgrade