Zyxel 700H Firmware 1.36 Patch 0, Error IPSec remote access VPN
Freshman Member
Hello,
Are there any updates or changes I need to make if I already have an IPSec remote access VPN configured? The problem is that after updating from version V1.35 (ABZI.2) to V1.36 (ABZI.0), the VPN isn't working correctly. The VPN connects to the Zyxel 700h using the Windows 11 VPN option, but if I ping an internal IP address, it doesn't work. If I revert to the previous firmware version, V1.35, everything works correctly, as I can ping and connect. Thank you for your help.
Regards, SY
Accepted Solution
-
Is tunnel connection up?
The iusse could be the same as this.
If you have routeing rules like LAN to WAN you need to Exclude the remote access VPN IP pool in Destination Address so that USG routes the VPN IP pool back down the VPN tunnel
0
All Replies
-
Is tunnel connection up?
The iusse could be the same as this.
If you have routeing rules like LAN to WAN you need to Exclude the remote access VPN IP pool in Destination Address so that USG routes the VPN IP pool back down the VPN tunnel
0 -
Hi @PeterUK,
You're right, it's the same problem. My question is, is it temporary? I'm worried this might create a vulnerability. Will Zyxel be aware of it and fix it?, since it's working correctly up until this new firmware version, v1.36?Thanks for your help.
Regards,
SY0 -
There no vulnerability caused by this I think the routeing rules are more strict in that they don't look at the IP pool of remote VPN to go down tunnel first and so the routeing rule with Destination any is applied strictly.
But what I want to see is next hop remote VPN tunnel in the routing rules that way you can do
rule 1
incoming LAN
Destination Address 192.168.50.0/24
next hop remote VPN tunnel
SNAT nonerule2
incoming LAN
Destination Address any
next hop WAN
SNAT outgoing interface0 -
Hi @YanShadowGT,
Thank you for your feedback. The issue you observed is due to a change in the packet flow processing order in firmware v1.36, which may affect your policy routing. To assist you better, could you please send us a private message with remote access or diagnostic file?
Zyxel Tina
0
Categories
- All Categories
- 439 Beta Program
- 2.8K Nebula
- 202 Nebula Ideas
- 127 Nebula Status and Incidents
- 6.3K Security
- 515 USG FLEX H Series
- 328 Security Ideas
- 1.7K Switch
- 84 Switch Ideas
- 1.3K Wireless
- 49 Wireless Ideas
- 6.9K Consumer Product
- 288 Service & License
- 458 News and Release
- 90 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 4.3K FAQ
- 34 Documents
- 85 About Community
- 97 Security Highlight
Guru Member
Zyxel Employee