-
How to resolve problem with ike vpn connection after upgrading to firm 5.3?
After upgrading the Flex 500 and Flex 100 to firmware 5.3 I have problem with the ike vpn connection. The site to site VPN connected and data flow from the Flex 500 to the Flex 100 and USG 60, bur data does nor flow from the USG 60 and FLEX 100 to the Flex 500. Data flow in both direct between F100 and USG 60. Also with…
-
Delete Device/Account
How do you remove a device and account from Zyxel?
-
How to setup a Wireguard server behind the Firewall
Behind my Zyxel firewall (USG Flex 50) I run a Qnap NAS with a Wireguard server. In order to access this device from outside, I have set up the Wireguard server on the NAS. But I have no idea, how I need to setup the firewall in order to reach my NAS over the Wireguard tunnel - also asking Dr. Google didn't really help.…
-
LTE7490-M904 Firewall configure error
Hello, Do someone have idea what is wrong with this configuration? I try to get security camera image working trouhg web. I atteched images of my settings what I have configured. Can`t get working this with Zyxel LTE7490-M904 (Firmware V1.00(ABQY.3)C0). I tested with Huawei router and it works like a charm. My camera IP:…
-
Zyxel USG20-VPN FireWall Update
Hi there, I got an USG20-VPN the version is v4.65(ABAQ.1), I want to upload the newest version like v5.30(ABAQ.0). But I don't know why I can't successfully do it. Is there any other way I could try?Thanks for helping me. Best regards.
-
USG20W-VPN wlan state
How can I switch ON/OFF wi-fi radio without reboot the firewall? In the front view of the virtual device, the wlan led is always off and I can't see the real state of the wlan
-
USG110 - FW v4.72 - different vulnerabilities solved (or not?)
Just reading the feature log of the latest FW patch v4.72. It's listing the following vulnerabilities which have been dealt with: CVE-2022-0778CVE-2022-0342CVE-2021-44224 So far so good. But your latest security advisory of today (…
-
Zyxel security advisory for OS command injection vulnerability of firewalls
CVE: CVE-2022-30525 Summary Zyxel has released patches for an OS command injection
vulnerability found by Rapid 7 and urges users to install them for optimal
protection. What is the vulnerability? A command injection vulnerability in the CGI program of some
firewall versions could allow an attacker to modify specific files…
-
How to remove User/Group accounts (CLI)
I am looking for a way to remove users on ZLD appliances, similar to the one explained here: https://mysupport.zyxel.com/hc/en-us/articles/360006854279--ZLD-How-to-add-new-User-Group-accounts-CLI- Any hints?
-
ATP500 Connection refused via web
Hi, I've got an ATP500, this morning I've tried to logon via web. Connection refused. I tried to logon via SSH, no problem. I've tried to reboot. Connection refued. I've Update ATP500 via ssh to ATP500_V5.30(ABFU.0)C0, nothing changed. I cannot use web GUI. Any suggestion? Thanks. Bye
-
Ip Mac Binding Problems
If I activate ip mac binding and I received a lot log entries like: Drop packet lan1-0.0.0.0-30:01:50:0F:11:22 The mac address is reserved in the dhcp table list and connected to ip address 10.0.0.14. Only for this one interface I received this log. The device is a wlan mesh. So why do I have the drop log entries and how…
-
Firewall logs - Default Rule
Using a USG 1000 Created firewall rule to block a range of addresses in the Netherlands89.248.160.0 - 89.248.175.255 The rule is configured to deny with a log alert (red text), any connection attempt from these addresses. The rule is the first in the my firewall (Priority 1) However the log is showing the connection…
-
I found a user automatically created from anonymous account
In my log i found this: username:zyxelmd, usertype:admin, action:create. (Account: ) I checked in users section and i really found they new user zyxelmd I checked all the others log available and i didn't find any other login account. Nobody entered in configuration settings. There is only one admin user configured and it…
-
Zywall 110: Subnet Problem with IPSec VPN
We have a Zywall 110 with two IPSec VPN connection. First VPN connects to the remote network 10.10.125.0/24 (10.10.125.1 - 10.10.125.254)Second VPN connects to the remote network 10.10.0.0/18 (10.10.0.1 - 10.10.63.254) In the VPN Configuration the Network mask is displayed correctly (Remote Policy: SUBNET, 10.10.0.0/18).…
-
bandwidth limit
I have a VLAN on my internal network with the name of VISAO-ALUNOS, but this VLAN has no bandwidth limit. Where I limit the bandwidth of this VLAN so that it stays with, for example, 10Mb, this in Firewall Flex 200.
-
IPSEC VPN Site to Site and specific destination ip
I have to configure an IPSEC VPN Site to site from my ATP 500 (on the left) to a custumer network (on the right) I have been able to setup the VPN Gateway and connection but the customer requests that the computer of my LAN must appear to his network as using a specific ip that the customer give to me:174.100.4.24 Is there…
-
IPSec VPN Internet traffic (not) working
Hi, I have successfully configured IPSec VPN and my users have access to internal resources and to the internet. However, I would like for this internet traffic to be monitored (e.g. SSL inspection, Content filter, etc.) and I can't seem to figure out how to do that. I thought the policy route is a solution but regardless…
-
How to enable ICMP
How to enable ICMP to ping to IP: 192.141.xx.xx. I have the Flex 200
-
SecuExtender SSL disconnects after 2 minutes
Hello, I have problems in several ATPs when connecting through SecuExtender SSL.They connect without problems, but after 2 minutes it disconnects for no apparent reason.This happens with the latest update 5.30, and latest version of SSL SecuExtender 4.0.4.0 and on several devices, example ATP500 or ATP700. What can be the…
-
Webaccess vs SSl VPN
In regards to the security risk announced last friday, I'm pondering in how to go about restricting wan webaccess to the device from my wan ip without interfering with SSl VPN. Currently managing about 50 Companies with this setup. and they connect from many different IP's so i can't really add them all nor do i want to.…