[USG FLEX H]Intranet traffic have issue need to disable secure-policy as workaround.

Options
Zyxel_Kevin
Zyxel_Kevin Posts: 958  Zyxel Employee
Zyxel Certified Network Administrator - Security Zyxel Certified Sales Associate 100 Answers 500 Comments

Symptom:

There's an access issue between LANs or VLANs; ping and UDP traffic is working, only TCP have problem.

Solution:

Typically, this is because the connection did not establish on Firewall. The SYN-ACK reply isn't being observed on the firewall interface.

We can't disable this mechanism. This behavior is unusual for most security devices, please check your network topology/routing

Checking:

1)Enable debug level of "Security Policy Control"

image.png

2)You will see lots of log "Invalid state detected DROP" regarding to your source /destination