-
💡Duo Security Authentication Integration Guide
This discussion has been moved.
-
[2026 January Spotlight] Integrate Secure Cloud Authentication with the USG FLEX H series
As organizations adopt cloud services and support remote and hybrid work models, identity has become a critical foundation of modern security. Traditional authentication methods based on locally managed accounts are increasingly difficult to scale and protect against today’s threats, including credential theft and…
-
cloud dns filter keeps blocking a site, doenst matter what i do on the PC or Firewall
Dieser Server konnte nicht nachweisen, dass es sich bei ihm um ast-systec.com handelt. Das Sicherheitszertifikat stammt von dnsft.cloud.zyxel.com. Dies kann auf eine Fehlkonfiguration zurückzuführen sein oder auf einen Angreifer, der Ihre Verbindung abfängt.
-
Tailscale exit node issue in v1.39
Hi Team, Our customer is using the Tailscale feature with USGFLEX500H configured as Exit Node. This used to work fine with USGFLEX firmware 1.36. But it stopped working when we upgraded 1.36→ 1.38. The release notes of 1.39 mention that the issue is solved (see screenshot), however the customer still suffers from the this…
-
[USG Flex H] - Multiple NAT rule for different interface
Hello, I've an USG Flex H, and a "particular" request: I've an Home Assistant instance reachable from internet: my intent is to use the same DDNS address and the same port to reach Home Assistant both from internet and lan. For example: From internet: https://myaddress.no-ip.org:80443 —> 192.168.0.1:8443 From LAN:…
-
[uOS 1.39] Problems with HTTPS sessions
After updating to 1.39, we noticed, particularly on the 200H models but also on some 100H models, a significant increase in "log deny wan-to-device" entries. Specifically, I’ve noticed that the destination IP is my public IP, and the source always appears to be legitimate websites. Since the destination port is always an…
-
USG FLEX 500H/uOS dynamic policy-based IPsec issue – RCO/R-CARD traffic works on VPN100/USG but fail
Hello Zyxel Support, We are migrating an existing working RCO/R-CARD IPsec environment from an older Zyxel VPN100/USG/ZLD firewall to a new Zyxel USG FLEX 500H running uOS. The old VPN100/USG is currently working correctly. The new USG FLEX 500H can establish the IPsec tunnel and can transport ICMP and generic UDP traffic,…
-
FW V1.39 – Issue with SSL-VPN in combination with IPsec
Since the update to version 1.39, strange issues have arisen with connections to the back-office that route through SSL-VPN followed by IPsec-VTI-VPN. To clarify the setup: Site A (USG FLEX 100 H, FW 1.39), Site B (USG FLEX 200 H, FW 1.39), Site C (USG FLEX 200 H, FW 1.38). All sites are interconnected via IPsec VTI VPN.…
-
[USG Flex 500H + NWA130BE] - Different speedtest value between LAN and Wifi
Hello, I've an USG Flex 500H and an NWA130BE. The topology is: USG Flex 500H —> P1 —> WAN (2.5Gb) USG Flex 500H —> P3 —> VLAN 10 (Main wifi) —> NWA130BE profile Wifi 7 (forced to 802.11be at 320Mhz MLO enabled) USG Flex 500H —> P4 —> PC with Realtek 2.5GbE Family Controller adapter (lastest driver) and cable CAT7 600Mhz My…
-
[USG Flex H] - Interface in Bridge Mode show 0.0.0.0 as IP Address into port status
Hello, as per title, if I've an interface in bridge mode, into the port status I not see the assigned IP Thank you
-
Del dhcp request domain-name-servers does not always work
USG FLEX 200H V1.39(ABWV.0) So I get the idea you don't want to change the DHCP client Discover/Request and for good reason but do like: turns out it does remove domain-name-servers from Discover/Request del vrf main interface ethernet Backup_4G ipv4 dhcp request domain-name-servers thereby removing it in config to show /…
-
IPSec VPN Setup
I have a FLEX 200H that I am trying to setup IPsec VPN on. For the life of me cannot get it to work. I am have a old FLEX 200 and it was simple. Now have my options are gone. I am trying to set it up inside the network of the FLEX 200 so that it is read when I do cut over with minimal down time. I also use the web…
-
Firmware 1.39 - secondary WAN IP
Did something change with firmware 1.39 when having a secondary WAN IP? Now it seems that all outbound trafic is using the secondary WAN IP and not the primary WAN. IP on the default TRUNK. Is that normal behavior? Policy route is not an option. I have one VPN connection that requires the secondary WAN IP.
-
Apple Configurator for VPN configs
Hello, Is there any instructions anywhere, how to use Apple Configurator- app to modify the IPSec VPN profile in iPhone? I would like to modify parameters what iOS by default only accepts, like DH14 to DH19. And the initial proposal to be based on AES-GCM. I assume, there is no other way with iPhones to improve the default…
-
Network tool tracetcp now does not work
USG FLEX 700H V1.39(ABZI.0)ITS-260800953 or V1.39(ABZI.0)ITS-26WK32-m12287 seem there was a big changes in V1.39 such as slower throughput but now this tool does not work https://simulatedsimian.github.io/tracetcp.html In either a SNAT or bridge setup but in bridge if you turn off policy control then tracetcp works. My…
-
[USG Flex 500H] - Fans seems noisy
Hello, I have an 500H that have fans that seems noisy. Actually seems that rotates between 4600rpm and 5600rpm (SNMP sensor value). I also have a Raspberry PI with the active cooler fan (original) that rotate to 4500rpm and don't produce any eccessive noisy. There is a way to open/unmount the 500H for trying to clean and…
-
ATP800 to USG Flex 700H Issues
Hello, We just picked up a 700H to replace an ATP800. Happened to find the migration website and tried converting the config. Got nothing usable out of it. The CONF output is all commented out. Granted the config could be considered slightly complex, so I tried an ATP200 config which is as basic as it gets. One interface,…
-
[USG Flex H] - Max wattage PoE budget
Hello, As per datasheet, all the USG Flex H PoE models have max 30W as PoE budget. I think is clear, but just to confirm, the max wattage (30W) is shared between ports (so between port P3 and P4, the PoE budget must be less than 30W) or is per port (so max 30W on port P2 and max 30W on port P3)? Thank you
-
[USG Flex H - V1.39(ABZH.0)ITS-260800686] - User Custom DDNS effective IP not appear
Hello, I've configured multiple DDNS service: 2 NO-IP and 1 Dynu account. For the No-IP, all works but for Dynu account, seems that the effective IP not appear also if the result is SUCCESS. The Dynu entry is the HomeOrbit profile name, and it is custom because, if I use the Dynu Basic DDNS Type, the update fails: Update…
-
Domain join | AAA Server
Good morning / Hi everyone, I have a 200 Flex H firewall and I would like to allow VPN access via SSL only to certain domain users (domain on Windows Server 2025). In the past I was able to configure this type of setup, but with this new customer I can’t get it to work. Is there something that no longer works after the…