-
💡Duo Security Authentication Integration Guide
This discussion has been moved.
-
[2026 January Spotlight] Integrate Secure Cloud Authentication with the USG FLEX H series
As organizations adopt cloud services and support remote and hybrid work models, identity has become a critical foundation of modern security. Traditional authentication methods based on locally managed accounts are increasingly difficult to scale and protect against today’s threats, including credential theft and…
-
USG FLEX 200H (uOS 1.39, Nebula-managed): AD bind account works only in CN=Users — "Invalid DN synta
Nebula-managed USG FLEX 200H, uOS 1.39, NCC 20.10, Windows Server 2022 AD. The AD server object (NCC → Firewall settings → Authentication Server) authenticates SSL-VPN users. With the bind account in its own OU (a dedicated service account, Domain Users only), the Configuration Validation test returns "Invalid DN syntax"…
-
USG FLEX 200H – Inbound UDP/5060 (SIP) not forwarded by Virtual Server NAT rule
ENVIRONMENT Device: Zyxel USG FLEX 200H Firmware: V1.39(ABWV.0) WAN interface: vlan7_PPPoE (PPPoE, dynamic public IP, referred to as <WAN-IP>) LAN interface: vlan10 (internal network 10.10.10.0/24) Internal server: 10.10.10.10 (Asterisk PBX, listening on UDP 5060) Remote peer: Deutsche Telekom SIP servers, 217.0.0.0/13…
-
Primary WAN not returning after connectivity failure on FLEX 200H
It now happened for the 2nd time on our appliance. On 2:45:22 this night our provider went down and internet switches to WAN2. 2:46:17 WAN1 got it's connectivity back. However, our internal network and VLAN's still went online through WAN2. Had to force it by disabling WAN2 for a second(we did that on 09:00, so hours after…
-
Firmware 1.39 - secondary WAN IP
Did something change with firmware 1.39 when having a secondary WAN IP? Now it seems that all outbound trafic is using the secondary WAN IP and not the primary WAN. IP on the default TRUNK. Is that normal behavior? Policy route is not an option. I have one VPN connection that requires the secondary WAN IP.
-
Tailscale exit node issue in v1.39
Hi Team, Our customer is using the Tailscale feature with USGFLEX500H configured as Exit Node. This used to work fine with USGFLEX firmware 1.36. But it stopped working when we upgraded 1.36→ 1.38. The release notes of 1.39 mention that the issue is solved (see screenshot), however the customer still suffers from the this…
-
DHCP client WAN ports not working in V1.39
Hello. After updating a 200HP and a 500H to version 1.39, the DHCP client on the WAN side fails to obtain an IP address from the Internet Service Provider (ISP). I reverted to the partition running version 1.38, and everything is working correctly again; the DHCP client successfully obtains an IP address on the WAN ports…
-
v1.38 Dashboard Issues
So I load my dashboard and get this error (I have cleared Edge's cache too) This is being caused by the client usage widget Error Failed to load interface list Error Code: (500) /api/show/gui/widget/client/usage
-
Site to site zone not saving in config
USG FLEX 700H V1.39(ABZI.0)ITS-26WK36-m12745 So at first I though this was some other bug then I looked at the config for site to site Zywall110V4 zone and it was set at none which is odd because I know I would of set that so changed it back to IPSec_VPN and save the config. But I could not put my finger on it as to…
-
USG FLEX 50HP (uOS 1.39, Nebula-managed): firewall-originated traffic (AD/RADIUS lookup) does not en
Two Nebula-managed sites: USG FLEX 200H at the main site with the Windows AD, USG FLEX 50HP at a branch, Nebula site-to-site VPN between them, both uOS 1.39, NCC 20.10. The 50HP should authenticate SSL-VPN users against the AD at the main site. Traffic from LAN clients crosses the tunnel fine (domain-joined PCs, DNS).…
-
USG FLEX 200H – IKEv2 Remote Access VPN client shows Connected but FLEX does not establish any IKE/I
We are experiencing an issue with IKEv2 Remote Access VPN on a Zyxel USG FLEX 200H. The VPN client may show "Connected", but the USG FLEX does not establish or maintain any IKE/IPsec Security Association, and the client cannot access the configured internal network. Device information Model: Zyxel USG FLEX 200H Firmware:…
-
uOS 1.39 - Flex 500H crashed AP Management
Hello everyone, I updated this 500H on premise from 1.38 to 1.39 So after the reboot I saw the AP red and then offline. I tried to change the cable, zero difference. I tried to change the port, zero difference. Always blinking green and yellow, then red 3 times, then shut down. I tried to link it to another switch inside…
-
Cert SSL - autorenew via DigiCert or Sectigo or others
Hello everyone, I recently purchased an SSL certificate, but I read about the 200-day renewal hassle that will later become 100 and then 47 days. It's a terrifying thing for manual certificate replacement, which requires the H-series firewall.How can someone get a recognized SSL certificate (on a domain of the customer's…
-
[USG Flex H] - DDNS public IP - decrease minimum check period
Hello, I would like to decreare the minimum check period for a public check URL. Until now, the minimum is fixed to 5 minutes; this can be a problem, because, if the WAN IP change, the DDNS can check a public URL to know the new IP, in the worst-case scenario, only after 5 mins after the change. Is possible to change this…
-
USG FLEX 200H: Shared BWM still affects unrelated VLANs on current firmware
This appears to be the same Shared BWM issue reported in this thread in April 2025. https://community.zyxel.com/en/discussion/29056/usg-200h-wan-upload-problem#latest Since that discussion is now closed, I am opening a new thread because I can still reproduce the issue on the current USG FLEX 200H firmware. My setup: USG…
-
50H bandwidth management dropped capacity?
Hello, I have fiber WAN with 100/100Mbps (Download/Upload). Always gives more than that typically 110/120Mbps. When I activate BWM in 50H, upload drops to max 80Mbps. No specific impact on download. And this happens even if there is only the Default rule in BWM, no other rules added. I have tested this with the ISP own…
-
[USG Flex H] - Ping packets lost and port led unusual flickering
Hello, I've an 500H and from 2 days more or less, I see an unusual flickering of port status as if there were more activity than usual (DDos attach or similar). All of these ports flickering at the same way, at the same moment and all are belonging to the same interface (LANIface in the LAN zone): Home Alarm UPS TVs When I…
-
IPSec VPN: multiple phase 2 and SNAT
Hi, On a USG FLEX 700 H, I needed to configure an IPsec VPN with one Phase 1 and 13 Phase 2 policies. I need to configure SNAT for all Phase 2 policies. However, when SNAT is configured in the VPN connection, it is applied only to the first Phase 2 policy and not to the others. As a workaround, I had to configure 13…
-
SSL VPN with Radius authentication fails to connect after few days
I have set up SSL VPN on ZyXEL FLEX 200H with Radius Authentication. This all works fine, but after a few days users can't connect anymore. I don't see anything in my NPS logs and also no connection tries in de FLEX. If I do a telnet to the port, it's not responding. If I turn off SSL VPn and turn it back on, everything…