USG Flex 200H: AD user authentication over VPN

fschenckel Posts: 3  Freshman Member
First Comment Sixth Anniversary


I need to authenticate the VPN (IPSec) users using Windows AD. I could join the domain server, this part seems OK and I can see the Zywall in our Computers OU.

But when I test a user in the configuration validation, I get each time a "Invalid DN syntax" answer.

What can I do to check what's wrong (Again USG is in the domain) ?

Using an switch internal user to open the VPN is OK, but then the domain resources are not available !!

I really need to authenticate over the domain. Our previous Zywall VPN 100 did the job without problem…

What did I wrong ?

Thanks !

Best regards

All Replies

  • Zyxel_Melen
    Zyxel_Melen Posts: 2,941  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate
    edited March 5

    Hi @fschenckel,

    Could you help collect the diagnostic info file so I can help check the configuration and related logs? Here is the FAQ about the diagnostic info collection:

    USG FLEX H Series - Download Diagnostic Files from GUI — Zyxel Community

    Please collect it after the VPN connection fails. In addition, you can send the diagnostic info file, need to zip it since the Zyxel community platform does not accept .bz2 file, to me via private message.

    Zyxel Melen

  • fschenckel
    fschenckel Posts: 3  Freshman Member
    First Comment Sixth Anniversary

    Hello Zyxel_Melen,

    Thanks for your help, I've started the diagnostic collect (Clic on 'Collect now'), but clicking on 'Stop' doesn't produce any file. What's wrong ?

    Thanks !

    Best regards
