-
USG FLEX 200H DHCP reserved IP edit error (bug)
USG FLEX 200H, firmware V1.21(ABWV.0) Network Status → DHCP Table When I try to edit reserved IP entry I get the warning: This IP address is not included in the DHCP pool. This happens when editing any field, that is Host Name, IP Address, MAC Address and Description. The workaround is to remove the reserved IP (Unreserve)…
-
Unlocking several portals when using CIP
Hi! I use the built-in Children's Internet Protection policy. I use this policy in education. This is a very nice thing, but I would like to unblock Facebook, YouTube, and Vimeo. The problem with YouTube and Vimeo is that a message related to HSTS appears. I would like to add these two services to exceptions, but I cannot…
-
using two wan ports
hello, is it possible to use 2 wan ports at the same time? hardware used is a USG FLEX 200 idea: one port for the internet second port is for voip each port is connected to a seperate ISP connection.
-
Connectivity Check limitation
USG FLEX 200H V1.21(ABWV.0)ITS-24WK35-0813-240800592 in other models you can have the routeing Connectivity Check ping local interface IP subnet without a gateway and External or Internal but on the FLEX H you can only ping if the interface has a gateway and External. can this be changed thanks
-
Secondary IP addresses on interface problem
USG FLEX 200H V1.21(ABWV.0)ITS-24WK35-0813-240800592 Howto add secondary IP address on interface? — Zyxel Community There is no primary so I have / vrf "main" interface ethernet "ge4" ipv4 address "192.168.255.235/26" / vrf "main" interface ethernet "ge4" ipv4 address "192.168.255.253/26" / vrf "main" interface ethernet…
-
How to set up Link Aggregation group on a USG FLEX 700H
Hei, Received the new firewall and want to setup the 10G ports in a LAG, which connect to the Cisco router/internal network. (LACP) Compared to the UGS FLEX 700, I am unable to locate the LAG setup in the Network→ interface section. Anyone know how to approach this? Mvh, RET
-
Trunk and remote access VPN issue
USG FLEX 200H V1.21(ABWV.0)ITS-24WK35-0813-240800592 So bit of a problem for my setup to work WAN2 must not be in the User-Defined Trunk but when its not in the trunk then remote access VPN does not work In other words not having WAN in trunk works better but for VPN to work WAN must be in trunk So can you get VPN to work…
-
A success in moving from Zywall 110 to the new FLEX200H
So their where some changes I had to do to get here but seems to be up and running with real DMZ type 2.1 working well it has some advantages and disadvantages over type 1. I did find a problem of NAT port the SYN, ACK not being sent out due the truck not having the interface but due to problem adding it to the trunk I…
-
Best Practices
Hello Zyxel Team, I would like to ask for your recommendations and best practices for our network. We are currently still utilizing our VPN50 firewall router behind our ISP’s basic router, with a 500 Mbps fiber subscription. Our network has 60 network devices including 30 IP cameras, NVRs, Zyxel managed and unmanaged…
-
OpenVPN, can we combine password+otp in same question ?
Hello, My customers use OpenVPN with Flex H and OTP to connect on remote system. It's working fine, but it is tricky to use. For customer it is very complicate to open web page to send OTP value especially from a mobile device. Is it possible to add OTP value with password ? like this password + otp value P.S. We choose…
-
OpenVPN use client certificate
Hello, is it possible to use client certificate with OpenVPN for better security ? Best regards Luc
-
usg flex 700H
external port P2 gest stuck after power off/on. We have tu unplug/plug the cable on P2 to get it working again. since this port is the 'wan port' for us, the customer can't access Internet without a manual action on premise. Very disappointing
-
Help with setup testing of type 2 real DMZ
I have found a type 3 setup of real DMZ that works fine has made me happy but means more hardware to setup but wanted to see if this type 2 could be made to work better So its looking like my 1st type real DMZ will no longer be supported on newer models (which I might be wrong but thats what I think) due to its…
-
NAT ports over a bridge
Things I really want want the new H models to do that say my USG40 can do which is to change port coming in to the bridge to map to others. I hope this will be possible in updates to come
-
Ping over VTI Destination unreachable over time
USGFLEX200HV1.21(ABWV.0) Setup is USG60W LAN2 192.168.254.9 255.255.255.248 VLAN 55 192.168.55.1 255.255.255.0 VTI_test IP 192.168.254.10 Pre-Shared Key 12345678 Phase 1 AES128 SH256 DH2 SA Life Time 300 Phase 2 AES128 SH1 DH2 SA Life Time 180 VTI IP 192.168.255.43 255.255.255.240 FLEX200H Ge3 WAN3 192.168.254.10…
-
How does the H Series handle ADP?
I have an USG FLEX 100 running at a customer location that logs about 35 ADP alerts per day. I installed a 200H at a different customer location and enabled DoS Prevention w/ the default DOS_PREVENTION_PROFILE. The 200H generates no alerts and if I look at Log/Events, the DoS Prevention log is empty. Both of these…
-
SSL VPN via SecuExtender v7.7
Hello, It seems with this box (Flex 500H) they want us to use their Nebula cloud. I would rather keep this a standalone box and I can't even get out of the gate! The firewall seems configured (except the security policy where I locked myself out of the box three times now trying to set a security policy) and the client…
-
Interface disable longer then lease will then not when re-enable work
USG FLEX 200H V1.21(ABWV.0) P3 config as a WAN set to DHCP connected to DHCP server with a lease for 3 minutes. When you disable P3 WAN for 5 minutes then re-enable the WAN does not work. Workaround unplug the Ethernet and back in or change port Negotiate to trigger and DHCP restart.
-
are there IKEv2 problems with the USG Flex 100H router?
I have a system of 2 USG Flex 100H, 1 VPN100, 1 x USG40 and 1 USG Flex 200. To get IPSec VPN to all routers I had to reconfigure to IKEv1. I need SSL VPN to the Flex100H's and it works to 1, and not to the other. What coult get wrong, In the log I see that the public IP address is blocked through the default rule despite…
-
When will IPv6 be supported?
IPv6 should be standard for a flagship appliance like the USG Flex H Series. And I mean not just 6-to-4 translation but full support. When can we expect this feature to be added to the devices?