[2026 February Spotlight]📡USG FLEX 700H Validated for Use with Starlink Satellite Internet
Zyxel Employee
As satellite internet becomes an increasingly practical option for business connectivity, organizations are asking a critical question:
Can enterprise security firewalls operate reliably over satellite networks like Starlink?
With USG FLEX 700H, the answer is yes.
Starlink-Ready: Designed for Modern Connectivity Scenarios
Starlink, developed by SpaceX, delivers internet access via low-Earth-orbit (LEO) satellites, enabling connectivity in locations where traditional wired networks are unavailable or unreliable. It is commonly used for:
- Remote and rural offices
- Temporary or mobile sites
- Construction and industrial environments
- Business continuity and disaster recovery
✨USG FLEX 700H is fully capable of operating in these scenarios, making it an ideal security gateway for Starlink-enabled networks.
📋Test Environment Overview
To validate Starlink’s behavior in an enterprise networking environment, the following setup was used:
- Firewall: USG FLEX 700H
- WAN1 (Primary): AT&T (wired ISP)
- WAN2 (Backup): Starlink Mini
- LAN: Connected via a switch to a client PC
The firewall was configured in a failover (active/passive) WAN topology, where WAN1 served as the primary connection and WAN2 (Starlink) acted as the backup.
🔍Test 1: WAN Failover Behavior
The first test focused on WAN resiliency.
While WAN1 (AT&T) was actively handling traffic, the primary link was physically disconnected. The objective was to observe whether Starlink could automatically and quickly assume the role of the primary WAN.
Result:
Upon WAN1 failure, the firewall successfully detected the outage and rapidly promoted WAN2 (Starlink) to the primary WAN. Network connectivity was restored without manual intervention, confirming that Starlink can function reliably as a backup internet connection in a failover scenario.
🔍Test 2: Security Services with Starlink Active
Failover alone is not sufficient for enterprise environments. Security enforcement must remain intact regardless of which WAN link is active.
To validate this, the firewall was configured with the following security policies:
- A LAN-to-ANY security policy with:
- Content Filtering enabled
- Application Patrol enabled
- LAN clients received public DNS servers via DHCP
- The firewall’s global DNS forwarder was also set to public DNS
With Starlink operating as the active WAN, a LAN client attempted to access websites categorized under Alcohol and Tobacco, such as us.budweiser.com and marlboro.com.
Result:
Access to the target websites was successfully blocked. This confirmed that content filtering and application-level security services continued to function correctly, even when traffic was routed through the Starlink satellite connection.
💡Key Takeaways
This validation demonstrates several important points:
- Starlink can serve as a reliable backup WAN in an enterprise firewall deployment.
- WAN failover from a traditional ISP to Starlink occurs smoothly and automatically.
- Security services remain fully operational when Starlink is the active internet connection.
- The use of public DNS does not compromise content filtering effectiveness in this scenario.
💭Share Your Thoughts
Have you used Starlink in your network deployments or considered it as a backup connection? We would love to hear your thoughts and any insights from your experience.
Categories
- All Categories
- 442 Beta Program
- 2.9K Nebula
- 219 Nebula Ideas
- 127 Nebula Status and Incidents
- 6.5K Security
- 589 USG FLEX H Series
- 344 Security Ideas
- 1.7K Switch
- 84 Switch Ideas
- 1.4K Wireless
- 52 Wireless Ideas
- 7K Consumer Product
- 298 Service & License
- 478 News and Release
- 91 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 4.8K FAQ
- 34 Documents
- 87 About Community
- 105 Security Highlight
