USG Flex H - Home Office User should authenticate to USG Flex H via Login to access RDP
Hello!
When a user in the home office (no zyxel firewall) tries to login to a company USG Flex H the "login denied" appears.
When an adminitrative user tries to log in - ok
Situation:
User in Home Office (no zyxel firewall) should authenticate via WAN to a USG Flex H via webinterface, to access a RDP-Connection on the LAN (via NAT)
What changed in comparison to a USG Flex (pre H)?
Best regards,
MJR
Accepted Solution
-
Hi @mjr,
On the USG FLEX H series, this behavior is expected.
The USG FLEX H series follows the same principle as ZLD-based firewalls, where WAN access to the Web GUI requires an explicit security policy. However, unlike ZLD, starting from uOS firmware v1.32, only administrator accounts are allowed to log in from the WAN interface on the H series, which is an additional security restriction introduced in uOS.
USG FLEX H Series - V1.32Patch 0 Firmware Release — Zyxel Community
Therefore, using the WAN Web GUI for user authentication and then accessing internal RDP services via NAT is not supported on the H series. For remote users who need access to internal resources, please use a Remote Access VPN instead.
Zyxel Tina
0
All Replies
-
Set up a VPN, easiest way of accessing anything on the corporate network after just clicking "connect" on the VPN policy. Any OS can do that.
0 -
Sometimes you need a solution that doesn't conflict with any other requirement.
For example: a different VPN client, missing admin rights and so on.
Best regards,
MJR0 -
Yeah, but it's 2025, and VPN clients are embedded in every OS. No need to install a client.
0 -
So dose the setup work if you do it by admin?
0 -
Hi @mjr,
On the USG FLEX H series, this behavior is expected.
The USG FLEX H series follows the same principle as ZLD-based firewalls, where WAN access to the Web GUI requires an explicit security policy. However, unlike ZLD, starting from uOS firmware v1.32, only administrator accounts are allowed to log in from the WAN interface on the H series, which is an additional security restriction introduced in uOS.
USG FLEX H Series - V1.32Patch 0 Firmware Release — Zyxel Community
Therefore, using the WAN Web GUI for user authentication and then accessing internal RDP services via NAT is not supported on the H series. For remote users who need access to internal resources, please use a Remote Access VPN instead.
Zyxel Tina
0
Categories
- All Categories
- 441 Beta Program
- 2.9K Nebula
- 208 Nebula Ideas
- 127 Nebula Status and Incidents
- 6.4K Security
- 529 USG FLEX H Series
- 333 Security Ideas
- 1.7K Switch
- 84 Switch Ideas
- 1.3K Wireless
- 51 Wireless Ideas
- 6.9K Consumer Product
- 292 Service & License
- 461 News and Release
- 90 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 4.7K FAQ
- 34 Documents
- 86 About Community
- 99 Security Highlight
Freshman Member
Zyxel Employee

Master Member
Guru Member