-
Trunk and remote access VPN issue
USG FLEX 200H V1.21(ABWV.0)ITS-24WK35-0813-240800592 So bit of a problem for my setup to work WAN2 must not be in the User-Defined Trunk but when its not in the trunk then remote access VPN does not work In other words not having WAN in trunk works better but for VPN to work WAN must be in trunk So can you get VPN to work…
-
A success in moving from Zywall 110 to the new FLEX200H
So their where some changes I had to do to get here but seems to be up and running with real DMZ type 2.1 working well it has some advantages and disadvantages over type 1. I did find a problem of NAT port the SYN, ACK not being sent out due the truck not having the interface but due to problem adding it to the trunk I…
-
Best Practices
Hello Zyxel Team, I would like to ask for your recommendations and best practices for our network. We are currently still utilizing our VPN50 firewall router behind our ISP’s basic router, with a 500 Mbps fiber subscription. Our network has 60 network devices including 30 IP cameras, NVRs, Zyxel managed and unmanaged…
-
OpenVPN, can we combine password+otp in same question ?
Hello, My customers use OpenVPN with Flex H and OTP to connect on remote system. It's working fine, but it is tricky to use. For customer it is very complicate to open web page to send OTP value especially from a mobile device. Is it possible to add OTP value with password ? like this password + otp value P.S. We choose…
-
OpenVPN use client certificate
Hello, is it possible to use client certificate with OpenVPN for better security ? Best regards Luc
-
usg flex 700H
external port P2 gest stuck after power off/on. We have tu unplug/plug the cable on P2 to get it working again. since this port is the 'wan port' for us, the customer can't access Internet without a manual action on premise. Very disappointing
-
Help with setup testing of type 2 real DMZ
I have found a type 3 setup of real DMZ that works fine has made me happy but means more hardware to setup but wanted to see if this type 2 could be made to work better So its looking like my 1st type real DMZ will no longer be supported on newer models (which I might be wrong but thats what I think) due to its…
-
NAT ports over a bridge
Things I really want want the new H models to do that say my USG40 can do which is to change port coming in to the bridge to map to others. I hope this will be possible in updates to come
-
Ping over VTI Destination unreachable over time
USGFLEX200HV1.21(ABWV.0) Setup is USG60W LAN2 192.168.254.9 255.255.255.248 VLAN 55 192.168.55.1 255.255.255.0 VTI_test IP 192.168.254.10 Pre-Shared Key 12345678 Phase 1 AES128 SH256 DH2 SA Life Time 300 Phase 2 AES128 SH1 DH2 SA Life Time 180 VTI IP 192.168.255.43 255.255.255.240 FLEX200H Ge3 WAN3 192.168.254.10…
-
How does the H Series handle ADP?
I have an USG FLEX 100 running at a customer location that logs about 35 ADP alerts per day. I installed a 200H at a different customer location and enabled DoS Prevention w/ the default DOS_PREVENTION_PROFILE. The 200H generates no alerts and if I look at Log/Events, the DoS Prevention log is empty. Both of these…
-
SSL VPN via SecuExtender v7.7
Hello, It seems with this box (Flex 500H) they want us to use their Nebula cloud. I would rather keep this a standalone box and I can't even get out of the gate! The firewall seems configured (except the security policy where I locked myself out of the box three times now trying to set a security policy) and the client…
-
Interface disable longer then lease will then not when re-enable work
USG FLEX 200H V1.21(ABWV.0) P3 config as a WAN set to DHCP connected to DHCP server with a lease for 3 minutes. When you disable P3 WAN for 5 minutes then re-enable the WAN does not work. Workaround unplug the Ethernet and back in or change port Negotiate to trigger and DHCP restart.
-
are there IKEv2 problems with the USG Flex 100H router?
I have a system of 2 USG Flex 100H, 1 VPN100, 1 x USG40 and 1 USG Flex 200. To get IPSec VPN to all routers I had to reconfigure to IKEv1. I need SSL VPN to the Flex100H's and it works to 1, and not to the other. What coult get wrong, In the log I see that the public IP address is blocked through the default rule despite…
-
When will IPv6 be supported?
IPv6 should be standard for a flagship appliance like the USG Flex H Series. And I mean not just 6-to-4 translation but full support. When can we expect this feature to be added to the devices?
-
VPN IP from internal LAN range
I need to setup remote access IPSEC for some users, but I need them to get an IP address on the internal LAN range so it routes traffic correctly down a VPN connection. Is this possible?
-
Static IP adrress reservation on USGFLEX 200H
Hi there, on the new 200H, i cannot find any option to make a static IP reservation same as on the former models/software. In firmeware 5.x you could select the network interface, give it an DHCP address range and confige static IUP adresses, which could be out of the DHCP range. Than activate the setting "Enable IP/MAC…
-
Out of memory Zyxel Flex 700H
Good morning, I wanted to ask why lately the Zyxel Flex 700H device runs out of memory in a very short time, the problem is that when it reaches 98% or 99% the device freezes and you have to restart it manually, it is totally inefficient to restart the device daily. I hope for your prompt help. Greetings.
-
AD Authentication: Invalid DN syntax
Hello. Just update to 1.20 firmware to enable AD authentication. The firewall FLEX500H is allready joined to AD and I can see it as Computer in Active Directory users and computers. When I try to test the configuration I get the error "Invalid DN syntax". What's wrong? thank you
-
SSL Inspection not running well
USG FLEX 200H V1.21(ABWV.0) Only some sites run well many others load slowly or not at all
-
USG FLEX 100H crashing/freezing problem
I have been using USG FLEX 100 H. It has been crashing/freezing every 3-4 days. I cannot reach/ping the firewall. DHCP stops running and wont assign any ip s. Only restarts solves the problem. I have the latest firmware. Can you please help me to solve this huge problem. Thanks