Why Zyxel doesnt offer GeoIP Licence after the recent lack of USG security ?

Mitchch
Mitchch Posts: 1
Hi,

I manage approximatively 20 USG from USG20 to USG110 for small enterprises.
Recently, Zyxel discover a big hole into the USG security : Close SSL if possible, authorize IP through GeoIP etc.

So... Due to this security hole, could be possible to give to any user a 30 days licence for GeoIP to block China, Russia etc.. ? to have the time to remediate an new firmware????

So... be more reactiv and offer good solutions for your customers... It's not the first time we have such alerting... these last 6 months !!!

Regards,

Michel

Answers

  • Sconsulting
    Sconsulting Posts: 9
    +1 on this one, that would be a great and simple way to accomodate Zyxel clients while they figure out a solution. Being quiet and leaving their customers tapping in the dark is definitely not the way to handle this situation....
  • Sconsulting
    Sconsulting Posts: 9
    Correct me if I'm wrong, but what's even worse is that there doesn't seem to be a way to buy a Content Filter license online in real-time.  I have to order it through a local distributor, they procure it from Zyxel, print out the license key on paper and send it to me by postal mail, this takes approx. 5 days at least. For 2021 this distribution channel seems to be rather "dated".  I wouldn't even mind to buy some Content Filter licenses to activate the GeoIP functionality for my clients but there doesn't seem to be an option to do it instantly.
  • Sconsulting
    Sconsulting Posts: 9
    Correct me if I'm wrong, but what's even worse is that there doesn't seem to be a way to buy a Content Filter license online in real-time.  I have to order it through a local distributor, they procure it from Zyxel, print out the license key on paper and send it to me by postal mail, this takes approx. 5 days at least. For 2021 this distribution channel seems to be rather "dated".  I wouldn't even mind to buy some Content Filter licenses to activate the GeoIP functionality for my clients but there doesn't seem to be an option to do it instantly.
    Correcting myself, this seems to be possible on the Zyxel Marketplace:
    https://marketplace.zyxel.com/

    However, for someone who just wants to use the GeoIP feature EUR 353/year is a bit steep.
  • mMontana
    mMontana Posts: 429  Master Member
    IMVHO GeoIP should be built-in into firmware, no subscription-fee based. 
    Zyxel recently provided Best Practices
    Best Practices to Secure a Distributed Network Infrastructure — Zyxel Community
    and GeoIP is one of the options for reduce exposure footprint, but currently is not an option, but a pay...
  • Zyxel_Stanley
    Zyxel_Stanley Posts: 963  Zyxel Employee

    Hi @Mitchch @Sconsulting @mMontana  

    After upgrading to ZLD 4.64/ ZLD5.01, you’ll be able to use GeoIP feature.

    Please login to Myzyxel.com with your Myzyxel account and download the firmware to local PC to upgrade the firmware directly or you may use cloud update to upgrade your firmware on-line.

    (Maintenance > File Manager > Firmware Management)

Security Highlight