-
Zyxel security advisory for OS command injection vulnerability of firewalls
CVE: CVE-2022-30525 Summary Zyxel has released patches for an OS command injection
vulnerability found by Rapid 7 and urges users to install them for optimal
protection. What is the vulnerability? A command injection vulnerability in the CGI program of some
firewall versions could allow an attacker to modify specific files…
-
How to remove User/Group accounts (CLI)
I am looking for a way to remove users on ZLD appliances, similar to the one explained here: https://mysupport.zyxel.com/hc/en-us/articles/360006854279--ZLD-How-to-add-new-User-Group-accounts-CLI- Any hints?
-
ATP500 Connection refused via web
Hi, I've got an ATP500, this morning I've tried to logon via web. Connection refused. I tried to logon via SSH, no problem. I've tried to reboot. Connection refued. I've Update ATP500 via ssh to ATP500_V5.30(ABFU.0)C0, nothing changed. I cannot use web GUI. Any suggestion? Thanks. Bye
-
Ip Mac Binding Problems
If I activate ip mac binding and I received a lot log entries like: Drop packet lan1-0.0.0.0-30:01:50:0F:11:22 The mac address is reserved in the dhcp table list and connected to ip address 10.0.0.14. Only for this one interface I received this log. The device is a wlan mesh. So why do I have the drop log entries and how…
-
Firewall logs - Default Rule
Using a USG 1000 Created firewall rule to block a range of addresses in the Netherlands89.248.160.0 - 89.248.175.255 The rule is configured to deny with a log alert (red text), any connection attempt from these addresses. The rule is the first in the my firewall (Priority 1) However the log is showing the connection…
-
I found a user automatically created from anonymous account
In my log i found this: username:zyxelmd, usertype:admin, action:create. (Account: ) I checked in users section and i really found they new user zyxelmd I checked all the others log available and i didn't find any other login account. Nobody entered in configuration settings. There is only one admin user configured and it…
-
Zywall 110: Subnet Problem with IPSec VPN
We have a Zywall 110 with two IPSec VPN connection. First VPN connects to the remote network 10.10.125.0/24 (10.10.125.1 - 10.10.125.254)Second VPN connects to the remote network 10.10.0.0/18 (10.10.0.1 - 10.10.63.254) In the VPN Configuration the Network mask is displayed correctly (Remote Policy: SUBNET, 10.10.0.0/18).…
-
bandwidth limit
I have a VLAN on my internal network with the name of VISAO-ALUNOS, but this VLAN has no bandwidth limit. Where I limit the bandwidth of this VLAN so that it stays with, for example, 10Mb, this in Firewall Flex 200.
-
IPSEC VPN Site to Site and specific destination ip
I have to configure an IPSEC VPN Site to site from my ATP 500 (on the left) to a custumer network (on the right) I have been able to setup the VPN Gateway and connection but the customer requests that the computer of my LAN must appear to his network as using a specific ip that the customer give to me:174.100.4.24 Is there…
-
IPSec VPN Internet traffic (not) working
Hi, I have successfully configured IPSec VPN and my users have access to internal resources and to the internet. However, I would like for this internet traffic to be monitored (e.g. SSL inspection, Content filter, etc.) and I can't seem to figure out how to do that. I thought the policy route is a solution but regardless…
-
How to enable ICMP
How to enable ICMP to ping to IP: 192.141.xx.xx. I have the Flex 200
-
SecuExtender SSL disconnects after 2 minutes
Hello, I have problems in several ATPs when connecting through SecuExtender SSL.They connect without problems, but after 2 minutes it disconnects for no apparent reason.This happens with the latest update 5.30, and latest version of SSL SecuExtender 4.0.4.0 and on several devices, example ATP500 or ATP700. What can be the…
-
Webaccess vs SSl VPN
In regards to the security risk announced last friday, I'm pondering in how to go about restricting wan webaccess to the device from my wan ip without interfering with SSl VPN. Currently managing about 50 Companies with this setup. and they connect from many different IP's so i can't really add them all nor do i want to.…
-
Not able to log in to the VPN2S after Firmware upgrade
after unboxing I logged in and no problem to connect. the first otion was to upgrade sw. When trying to login after sucessfully upgrade, the login tells me that : 1.Turn on Javascriptand Cooki settingsinn your web browser. 2.Turn off Popup Windows Blockingin your browser. It has been nearly impossible to log in. how…
-
Something not right with DNS? Destination unreachable
Before I start its really
bugging me that I can't remove default DNS forwarders just saying! Zywall 110 and VPN300
firmware upto date This is what I'm see
when a PC by DNS to 192.168.53.1 VLAN53 to zywall 110 go to look up a
request with DNS forwarder * 192.168.53.2 to my BIND server. Its like the USG is
rate limiting…
-
USG Flex 200 - L2TP over IPsec, not working after firmware 5.30
Hello there After upgrading Flex 200 from firmware 5.20 to 5.30, our users cant sign in anymore. Anyone get the samme error. We are using RADIUS for Duo. If we create a local test-user in the Flex200, its works. But then our duo/2-factor not working Solution is to run users on the "Local" So radius is not working anymore.
-
Zyxel firewall does not show the Netflow section
I have a Zyxel firewall which, despite being monitored in SNMP, does not show the Netflow section. how do I whitelist?
-
ATP500: update from 5.21 patch1 to 5.30 and SSL VPN problem
Hi,after the update of the firmware of my ATP 500 from 5.21 Patch 1 to 5.30 we are facing some problems with SSL VPN access.Some users who before update were able to connect to the VPN and stay connected for long time, now, after a short while (usually a few minutes) are disconnected without any reason (see picture below…
-
Why the outside port don't work
USG40W Add of the internal ip adress 192.168.1.171 in the range of lan1 After Add of a service on a tcp port 8790 Add of a group and in these grp add the service. All was saved all seems like an other objet. No error encounters. Add of a nat rules : Apply button was pressed. Add of two policy rules : Port closed. could you…
-
Issues when upgrading from 5.21 to 5.30 when ATP 500 hardware is in HApro
Issues when upgrading from 5.21 to 5.30 when ATP 500 hardware is in HApro I click download updates from the server and updateThe passive ATP500 is being updated, the active hangs (but continues to work) Writes that the download is in XA and hangs for several hoursAfter that, it starts working without error, the active one…