-
💡Duo Security Authentication Integration Guide
This discussion has been moved.
-
[2026 January Spotlight] Integrate Secure Cloud Authentication with the USG FLEX H series
As organizations adopt cloud services and support remote and hybrid work models, identity has become a critical foundation of modern security. Traditional authentication methods based on locally managed accounts are increasingly difficult to scale and protect against today’s threats, including credential theft and…
-
IPSec VPN Setup
I have a FLEX 200H that I am trying to setup IPsec VPN on. For the life of me cannot get it to work. I am have a old FLEX 200 and it was simple. Now have my options are gone. I am trying to set it up inside the network of the FLEX 200 so that it is read when I do cut over with minimal down time. I also use the web…
-
USGFlex200H blocking Macs from connecting to Windows server
Macs use SMB to connect to windows servers, our canon copiers also use SMB for scanning documents to a Windows server. Our old Zyxel firewall died, I've installed the new one (200H) and it's blocking all SMB traffic. The Macs can't connect to the Windows server and the Canon copiers can't scan to the Windows server. My…
-
USG FLEX H Series - V1.39 not stable has some issues
Not sure if its my config or if it need redoing but its not good. I think there is one good thing about it which is real DMZ V1 now works like ZLD but the UI is slow give errors like when editing firewall rules error code 10017 show object address-object fqdn wildcard IP192168500 which IP192168500 is not a fqdn! remote VPN…
-
Flex100H ARP entries
hi all, I am trying to set up the necessary entries for wake on lan to work via the CLI on a USG Flex 100H, firmware version 5.42(ABUH.0). I am following this guide: https://community.zyxel.com/en/discussion/30559/how-do-i-create-a-static-arp-entry-on-usg-flex-h-series-devices It worked fine, until after adding a few…
-
USG FLEX 500H stuck in boot loop
Hi, My Zyxel USG FLEX 500H is stuck in a boot loop and I can't get it to boot normally. So far I have tried: Performing a factory reset. Connecting through the serial console. Switching to the other boot partition using: atcd 2 atgo (I also tried atcd 1 with the same result.) Unfortunately, none of these methods solved the…
-
Anyone running USG FLEX H-series in a complex multi-site environment?
Hi all, We've been running Zyxel USG firewalls for about 10 years now — first the USG 20/60 series, then the USG FLEX 200/700 — and have been very happy with them throughout. Recently we upgraded part of our fleet to the new USG FLEX H-series (200H and 500H, currently on firmware 1.38(ABWV.0), Nebula-managed), and…
-
USG FLEX 100->USG FLEX 50H conversion?
Hello, I have an USG FLEX 100 router and would like to use/convert its configuration to an USG FLEX 50H router. What would be the best steps to perform this conversion of USG FLEX 100->USG FLEX 50H? Thanks. Jimmy
-
[USG Flex H] - Secondary firmware image/partition
Hello, I have an USG Flex H firewall and seems that is not present the possibility to boot up the firewall from a secondary boot partition. In some other brand (I have two switches of other brand), there is a possibility to boot up the system from two images; those images containing the firmware and I can choice what image…
-
Unable to Duplicate Working USG500H-ATP200 VPN for Add'l Site
Fairly new USG500H is not connecting to a remote ATP200 over site-to-site VPN. Both devices are being managed via NCC. The ATP200 is a fresh enrollee and had to be reconfigured as a result. On the USG500H, I have duplicated a working manual-link VPN settings (using the gateway/remote address of the remote site) and it will…
-
Sherlock Holmes the why the SecuExtender SSL VPN stop working
V1.38(ABWV.0)ITS-26WK16-m11228 But isn’t the SecuExtender SSL VPN to do with ZLD? Yes and if you think about When you have eliminated the impossible, whatever remains, however improbable, must be the truth! So I have a Zywall 110 I test SSL VPN LAN side it works but from the internet it don't...hmm I did a packet capture…
-
Remote Access VPN Setting changes can't be saved USG FLEX 200H
Hello, I have converted a config from a USG FLEX 200 and loaded it onto a factory new USG FLEX 200H. Now i want to change the Remote Access VPN Settings, for example the ip-adress pool or the DH group and i get this error. Does this error come from issues in the config conversion? I already tried to take out all groups or…
-
Copy config from USG Flex 50HP to another USG Flex 50HP
-
FLEX 100H v1.38 BWM policy created for specific VLAN affects *all* interfaces
As the title states, there seems to be some bug with BWM. If we create a BWM policy to limit the internet bandwidth on vlan100 to 150mbps upload/download, the policy also affects the internet *upload* bandwidth on other interfaces(download seems unaffected on the other interfaces). Screenshot of the BWM policy is below.…
-
v1.38 Dashboard Issues
So I load my dashboard and get this error (I have cleared Edge's cache too) This is being caused by the client usage widget Error Failed to load interface list Error Code: (500) /api/show/gui/widget/client/usage
-
DHCP relay not working over site-to-site VPN on FLEX 200H
We operate a network with approximately twelve branch offices and a centralized server infrastructure at our headquarters. All branch offices are connected to the headquarters via site-to-site VPN tunnels. The branches contain only Windows clients, while DHCP is provided centrally by a Windows DHCP server at the…
-
Packet capture: not possible for VPN interfaces
Hello, I have SSL VPN setup and is up and running. In the Diagnostics - Packet Capture I can't select corresponding interface. Why?!
-
[USG Flex H] - Whitelisting/Blocklisting MACs address to join into network
Hello everyone, there is a possibility to whitelist or blocklist some mac address to join into network? I mean, if I would like to deny some mac address (on an physical eth or on a Wifi AP) to prevent to access to my network/subnet/VLAN, there is a possibility to deny or allow a mac address to join into? I can allow/deny…
-
[USG Flex 500H] - Group Port P1-P2 with P3 --> P12
Hello everyone, While waiting to purchase this firewall, I'm doing some research on how to redo the configuration and transfer it between my current 200HP and the new 500H. I read that ports P1 and P2 can't be grouped with other ports (the post is from May 2024; is this still the case?) I'd like to implement this…