-
USG40 log entry: possible ARP spoofing
Hi, the following entry pops up in the firewall log periodically: Possible ARP spoofing attack on IP 192.168.1.140. Current hardware address is XXX where XXX is the correct MAC address for the IP. The IP used to belong to another device. Question: how can I get rid of the entry? It is only a minor nuisance, but still...…
-
Cannot upgrade firmware on my USG 20W
Hi I'm trying to upgrade from 3.30(BDR.5) but it always fails with the error code : 42008 "Firmware not compatible" I have tried with ZyWALL USG 20_3.30(BDQ.9)C0 from your download site - but also version BDQ.8 & BDQ.7 with same error Currently the USG 20W reboots every 20-30 minutes with a app watch dog error - and cpu…
-
ATP not respecting DNS request order
Hi, i have a ATP500 (V5.32(ABFU.0) / 2022-10-04 01:59:13) and I've been facing an issue that the ATP does not follow the correct DNS order inside its DNS section. I have a default trunk at ge2 and a PPPoE at ge3, both interfaces online. when I nslookup the ATP, it directs the request to the "DEFAULT" at ge3_ppp. Shouldn't…
-
ATP800 HA Cloud Configuration
Hi! I was wondering if it would be possible to configure the ATP800 in HA Pro mode trough Nebula (Cloud managed). We would rather manage the device through the cloud, but an HA configuration is necessary. Correct me if I'm wrong, but I can't seem to find any documentation. Thanks in advance!
-
USG FLEX 200.Access to Web interface troughth WAN2(P2)
Hello. I have USG Flex 200 with firmware V5.32(ABUI.0). WAN1(P2) - main provider. WAN2(P3) - reserved provider. I can't get access to Web interface when I try connected via WAN2(P3) but via WAN1(P2) - OK. I changed settings on WAN2(P3) and connected my main provider, disable firewall, but i still can't connected. What am I…
-
Flex 700 - Certificate download has failed
I have a USG Flex 700 running firmware version 5.31(ABWD0) which is having the same continuous error "2022-09-26 14:45:03 error myZyXEL.com Certificate download has failed.). I have tried unsuccessfully to perform the update manually, but it continues to fail that way as well. "SSL Certificate download has failed. (failed)…
-
Autoupdate didn't....why?
V4.50(ABFW.0) Have autoupdate and autoreboot enabled. But for 2 days, the ATP has not rebooted. The V4.55 is waiting on deck. Yes, it's set for daily update. What have I missed?
-
I-Phone 14 Issue in wifi enviroment
hi guys,i'm wandering around a issue with iphone14 in a wifi enviroment with an internal MS Exchange Server.This is the scenario:Usg 310 is the AP controller and the DHCP server for Vlans.Vlan33 (192.168.33.XXX) is the vlan with internal DNS Server 192.168.33.100 and LAN interface of MS Exchange Server 192.168.33.15DNS…
-
Can i Allow list a IP addredd against ADP Scan-Detection on USG FLex 500?
Afternoon, were using ADP Scan-Detection, however there are network inventory applications on a server within the network that trips this alarm every few hours. Can we permit this IP at all please ? crit adp ACCESS
FORWARD Rule_id:1 from
LAN to Any, [type:Scan-Detection(33)] tcp filtered distributed portscan
Action:No…
-
USG 1100 policy route don't work, the packet outgoing interface: doll
Hello. Site A - usg 1100 v4.72 Site B - usg flex 50W v5.32 Build 2 vti interfaces in trunk. Added policy route to Sote B via trunk. Device from site A don't have access to site B. In routing traces i see, that traffic goes to doll interface 172.20.0.90:0->172.20.77.61:049316ICMP00localThe packet outgoing interface:…
-
USG Flex 100 - Nebula Control Center - Standalone GUI
We just got a USG Flex 100 and got it online at the datacenter, and the fist question is. - If i add the USG Flex 100 to the Nebula Control Center, can i get all the functionality from the GUI i get when logged in locally to the device? - Partial Functionality? - If i add it to the NCC, can i still log in to the local GUI…
-
Ghost traffic
Hello, I cannot access a service/port when the firewall (security policy) is enabled, but the traffic goes through when it is disabled. However, I cannot see the traffic entry in the logs so I can whitelist it and reenable my firewall. Kindly advise Model: USG1100
-
Virtual Interface USG 100
In a network with additional public ip addresses, I have installed a usg 110 with static public ip address in WAN1. The configured address is 84.253.177.171/29. The gateway is 84.253.177.169.
I need to publish a local network machine with ip 192.168.1.1 on the internet. I want to configure the usg so that when an http…
-
IP Reputation false postive
Hi my ATP200 is starting to report 75.75.75.75 (Comcast DNS Servers) as "IP Reputation DB : Spam Sources/BotNets" can someone please look in to this as these are used by my users so my log is getting flooded with these events even after I have added the IP to the allow list. Thank you,
-
Trouble setting up L2TP over IPSEC on ATP100
Hi Zyxel team, We recently replaced an old CISCO firewall with a new ATP100. I tried
for several days to setup remote access via L2TP over IPSEC, where I
immediately succeeded in logging into the firewall from the outside
using the built-in L2TP client in Windows but failed to access the
network behind it. I then found the…
-
ATP100 Lan Ports
Trying to configure new ATP100, and have WAN port plugged into my internet, P4 plugged into my laptop, but not getting a light on the lan port. I tried all ports and several network cables. Anyone ever run into this issue?
-
ZYXEL USG FLEX 100W Log Display Options
I don't know when this changed but when looking at my logs, they used to contain IP addresses. When the log is emailed to me, the IP address are there. What setting or filter would stop me from seeing IP address information while looking at my log? Hope this makes sense
-
Questions about BWM feature in USG flex 200
Hi everyone. I want to guarantee some bandwidth to some traffic. I do not need to set any
caps on any traffic. For example, I want to guarantee 10Mbps for any traffic
related to Microsoft Teams. My
question is: 1
do I need to configure a reverse BWM policy for Teams traffic, like this: 2
do I need to configure the egress…
-
Routing between USG Flex 500 ethernet ports
Hi, I'm deploying USG Flex 500 and I can't figure out how to allow routing between two LANs connected to two ethernet ports. The design is as follows: P2 - WAN port to Internet P3 - DMZ port to DMZ servers P4 - Company1 LAN 192.168.245.0/24 P5 - Company2 LAN 192.168.246.0/24 and so on. Each company is in different LAN. USG…
-
Slow L2TP\IpSec speed between computers.
Hello! I think i can get much more speed during l2tp connection from home to my office network. There are an screenshots which shows, speed at my home wireless network is ~65 Mbit\sec. In the office network speed is 200Mbit\sec. In Office Zywall 110 we have VPN Server connection via L2tp\Ipsec (Ikev2) and 3 Algorythms of…