[2026 February Spotlight]📡USG FLEX 700H Validated for Use with Starlink Satellite Internet

Options
Zyxel_Avani
Zyxel_Avani Posts: 34 image  Zyxel Employee
First Anniversary
edited January 26 in Security Highlight

As satellite internet becomes an increasingly practical option for business connectivity, organizations are asking a critical question:
Can enterprise security firewalls operate reliably over satellite networks like Starlink?

With USG FLEX 700H, the answer is yes.

Starlink-Ready: Designed for Modern Connectivity Scenarios

Starlink, developed by SpaceX, delivers internet access via low-Earth-orbit (LEO) satellites, enabling connectivity in locations where traditional wired networks are unavailable or unreliable. It is commonly used for:

  • Remote and rural offices
  • Temporary or mobile sites
  • Construction and industrial environments
  • Business continuity and disaster recovery

USG FLEX 700H is fully capable of operating in these scenarios, making it an ideal security gateway for Starlink-enabled networks.

📋Test Environment Overview

To validate Starlink’s behavior in an enterprise networking environment, the following setup was used:

  • Firewall: USG FLEX 700H
  • WAN1 (Primary): AT&T (wired ISP)
  • WAN2 (Backup): Starlink Mini
  • LAN: Connected via a switch to a client PC

The firewall was configured in a failover (active/passive) WAN topology, where WAN1 served as the primary connection and WAN2 (Starlink) acted as the backup.

🔍Test 1: WAN Failover Behavior

The first test focused on WAN resiliency.

While WAN1 (AT&T) was actively handling traffic, the primary link was physically disconnected. The objective was to observe whether Starlink could automatically and quickly assume the role of the primary WAN.

Result:
Upon WAN1 failure, the firewall successfully detected the outage and rapidly promoted WAN2 (Starlink) to the primary WAN. Network connectivity was restored without manual intervention, confirming that Starlink can function reliably as a backup internet connection in a failover scenario.

image.png

🔍Test 2: Security Services with Starlink Active

Failover alone is not sufficient for enterprise environments. Security enforcement must remain intact regardless of which WAN link is active.

To validate this, the firewall was configured with the following security policies:

  • A LAN-to-ANY security policy with:
    • Content Filtering enabled
    • Application Patrol enabled
  • LAN clients received public DNS servers via DHCP
  • The firewall’s global DNS forwarder was also set to public DNS

With Starlink operating as the active WAN, a LAN client attempted to access websites categorized under Alcohol and Tobacco, such as us.budweiser.com and marlboro.com.

Result:
Access to the target websites was successfully blocked. This confirmed that content filtering and application-level security services continued to function correctly, even when traffic was routed through the Starlink satellite connection.

💡Key Takeaways

This validation demonstrates several important points:

  • Starlink can serve as a reliable backup WAN in an enterprise firewall deployment.
  • WAN failover from a traditional ISP to Starlink occurs smoothly and automatically.
  • Security services remain fully operational when Starlink is the active internet connection.
  • The use of public DNS does not compromise content filtering effectiveness in this scenario.

💭Share Your Thoughts

Have you used Starlink in your network deployments or considered it as a backup connection? We would love to hear your thoughts and any insights from your experience.