Custom Source IP for Connectivity Checks

Options
Zyxel_Claudia
Zyxel_Claudia Posts: 194 image  Zyxel Employee
Network Detective-New Adventure Badge Network Detective Badge First Comment Friend Collector

In our latest firmware update, USG FLEX H Series Firewalls has an important enhancement for connectivity and route monitoring - the ability to set a custom source IP address for connectivity checks.

The Challenge

Some ISPs assign:

  • Private IP addresses for PPPoE interface negotiation
  • Public IP addresses for actual traffic forwarding

Connectivity check defaults to using the interface IP as the source, in this case, the PPPoE interface cannot access the Internet so ping fails.

The Solution: Define Source IP for Connectivity Checks

With this new feature, you can now explicitly specify the source IP used for reachability tests (ICMP ping) on both:

  • Interfaces (e.g., PPPoE)
  • Policy Route

Where to Configure

1. On Interfaces

  • Navigate to: Network > Interface > Select interface (e.g., PPPoE)
  • Under Connectivity Check, there is a new field for Source IP
  • Enter the public IP address (assigned by the ISP)
    image.png

This tells the firewall:“Use this IP instead of the interface’s primary IP when sending ping packets.”

2. On Policy Route

The same setting is also available in the policy route health check.