-
MFA for VPN users (eg for non-SSL VPN with Zyxel client) - new news ?
This article is very big on buzzwords but light on details: [2021 Issue 06] Go Beyond VPN with Zero Trust in Hybrid Work — Zyxel Community Are finally getting MFA (eg with Google Authenticator, better Microsoft Authenticator) for VPN users, especially in non-Nebula firmware for USG and/or Flex units ?
-
Content filter ATP out of office
Hi everyone. I would like to be able to apply content filtering outside of the office. I need a safe browsing of my clients. Is there a possibility with DNS filtering? Thank's!!!!
-
Secuextender suddenly refuses connecting Mac os
Hi, I installed secuextender on two macbooks running OS 10.9.5 (Mavericks). On one of them I have a Windows 7 partition with Secuextender. I used it for three weeks without issues. Then I bought the Licence. Two days later it stopped working on the two Macbook (but not on the Win partition). Our software guy can't manage…
-
USG210: Use LAN-Clients on different WAN Ports
Hi everyone,I ahd the idea to let the LAN Clienbts connect to different WAN Ports.Our USG210 has two ISPs connected to WAN1 and WAN2, most used as failover or higher bandwidth. Now we had the idea to set the USG, that some LAN Clients use only WAN1 and some should use only WAN2. Dont ask why, its a inhouse case... I tried…
-
DNSSEC implementation. Anything needed on my USG?
Hi, Working on implementing DNSSEC support, so our mailserver, sitting behind a USG 110 can utilize e.g. DANE, in addition to increasing security around DNS. I can't seem to find any Zyxel documentation mentioning DNSSEC for the USG series, so perhaps I don't need to do anything on that?
-
Repeatedly used wrong user name leads to lockout - how to release the IP?
We have arranged different SSLVPN users which are connecting via SecuExtender. All works fine.Yesterday we've created a new SSLVPN user account. But our new colleague has repeatedly typed a wrong user name (e.g. "USER10" instead "USER_10") again and again. After trying the predefined number of login attempts the USG110…
-
Is it possible to import a list of static DHCP assignments to the USG FLEX 500 firewall?
We're switching from OPNsense to the USG FLEX 500 and don't want to manually retype 200+ entries of MAC and IP Adresses + client names. Is there a way to import a predefined list of these entries? I already have the exported list ready, but can't find a way to import it anywhere.
-
how many static user can create in usg flex500?
how many static users can create in usg flex 500? can I use a guest user as a wireless user? how many users can connect from only 1 guest user account at a time?
-
Replace NSG100 with USG Flex 500
Here is the scenario: 1 Nebula Org with 3 current sites.
Site 1 has a USG Flex 500 configured correctly. Site 2 has a NSG100 that I want
to replace with a USG Flex 500. I already purchased the new USG Flex 500, this is
just a question on installation sequence with minimal down time. I want to pre-configure the USG Flex as…
-
IPSec VPN Client: outside office configuration
Hello, Is there a way to configure the VPN client to open the tunnel only if the client is NOT in specific networks? Makes no sense to open the tunnel when the client is in the office. Thanks S.
-
SSL VPN Problem with "consumer" router
Hi everyone. this is my first time using firewall for VPN, previously i was using openVPN only. i have problems with creating simple SSL VPN: i can connect, but can't access to other devices on the LAN. i'm using a zyxel USG20. because i can't set the isp router to bridge, i set thw WAN with an IP on same network range of…
-
alert "interface wan1 dead, related policy route rules will be disabled
Hi community today we noticed that our internet connection was down for some time. In the USG60 (firmware 4.7) log we got the alert: >Interface
wan1 dead, related policy route rules will be disabled< >Trunk
SYSTEM_DEFAULT_WAN_TRUNK dead, related policy route rules will be disabled< does anybody know this issue or by what…
-
USG110 with WAC6503D-S access points. Limited to 100mb?
We have recently upgraded from ADSL to Fibre, so from 16mb to 350mb. Speedtest will NOT go above 100mb. If I use the ISPs router, straight away to 350mb. Tried wireless and wired; no difference. Looked at lots of settings in the USG, but nothing is jumping out at me as a throttle. Please help.....
-
Problems with the policy: "Wiz_WAN_to_Device_Deny_651"
Hy, I'm writing because with the last versions of firmware of my USG60, with the configuration of GEO/IP (with choice Italy connections), the Windows Pc can't connect to the server in remote (because the internet operators give IP from other european countries). To pass the problem I had to desable the policy…
-
Schedule disconnect of pppoe connection
Hello all! One question: Here in Germany most DSL connections with dynamic IP are doing a dis- and reconnect from provider side every 24 hours. To prevent that this happens during normal day-time several devices allow to schedule this on client side - this prevents an additional disconnect on provider side. Is there a way…
-
What can we learn from "Wireless Health"
I know the wireless healt funcntion from Nebula and really like it.Since ATP 5.1 we have a Beta function. I've enabled it, but how do I read the result? Do we have the same function as on Nebula, if it's not longer beta?ThanksMario
-
USG20-VPN, L2TP/IPSec, Static client IP ?
Hi, I’ve configured a USG20-VPN for L2TP/IPSec VPN server.I’ve configured some Windows VPN Client to connect to this Server. It works!Clients receive an IP in range set in Server (IP_Range_Pool) But now, how/where to configure the USG20 to Reserve one specific static IP for one specific Client ?! I have tried somethings in…
-
SSO restricts access to application through VPN tunnel
We have SSO working for all users, but we have a IPSEC VPN tunnel between Site A and Site B offices. And when Web Authorization is enabled users at Site A cannot access application running on Site B. This is a screen of our AuthPolicy. Should i change Incoming to LAN and Destination to WAN to make it work? thank you
-
L2TP over IPSEC no more working on Android 11(ColorOS 11.2)
Hello Everybody, Since i change my smartphone, I can't connect on the L2TP over IPSEC vpn anymore. My smartphone config: - Android 11 - Smartphone Oppo Find X3 Pro (ColorOS 11.2) The VPN Config : Like this guide searchArticle!viewBlob.action (zyxel.com) The question is : Am i alone with this problem :-) ? Thanks a lot for…
-
QoS / BWM - Setup questions
I will probably make a support request since I am not figuring this out, but I'll give the community a shot to explain. This is a small guide for how I configured it on my previous Ubiquiti EdgeMax 6P device, which was super simple and a breeze to do. https://www.youtube.com/watch?v=o-g2P3R84dw (from approximately…