OpenVPN support for USG router ?

purelight01
purelight01 Posts: 5  Freshman Member
First Comment
edited April 2021 in Security
Hello,

The USG router (USG40 for my case) supports L2TP, IpSec, and SSL VPN out of the box.
It does not seem to support OpenVPN.

Is there a way to add OpenVPN to it? Any plan from Zyxel to support it in the future ?

thanks
-antony
«1345

All Replies

  • Zyxel_Emily
    Zyxel_Emily Posts: 1,396  Zyxel Employee
    Zyxel Certified Network Administrator - Security Zyxel Certified Sales Associate 100 Answers 1000 Comments
    Hi @purelight01,

    Currently ZyWALL/USG doesn't support OpenVPN.

    Thanks for your suggestion and we will evaluate it in the future if it is beneficial.

  • kyssling
    kyssling Posts: 107  Ally Member
    First Comment First Answer Friend Collector Sixth Anniversary
    Hi, is possible use any other VPN client (than SecuExtender) ?
  • Zyxel_Emily
    Zyxel_Emily Posts: 1,396  Zyxel Employee
    Zyxel Certified Network Administrator - Security Zyxel Certified Sales Associate 100 Answers 1000 Comments
    edited October 2019
    Hi @kyssling,

    The VPN client software which are officially verified by Zyxel are ZyWALL IPSec VPN client and SecuExtender SSL VPN client.

    Other VPN client software/App could probably be used for VPN connection with ZyWALL/USG. However, these VPN client software/App from third party are not officially verified by Zyxel and there may be some interoperability issues.
  • MAD
    MAD Posts: 8  Freshman Member
    First Comment Friend Collector First Anniversary

    Many VPN sollutions today supports openVPN. So could you plz take this into more concideration.

  • Zyxel_Jerry
    Zyxel_Jerry Posts: 1,283  Zyxel Employee
    Zyxel Certified Network Administrator - Security Zyxel Certified Sales Associate 50 Answers 1000 Comments

    Hi @MAD

    Currently ZyWALL/USG doesn't support OpenVPN.

    Thanks for your suggestion and we will evaluate it in the future if it is beneficial.

    Share your feedback through our survey, make your voice heard, and win a WiFi 7 AP!
    https://bit.ly/2024_Survey_Community

  • MAD
    MAD Posts: 8  Freshman Member
    First Comment Friend Collector First Anniversary
    edited March 2020
    Is it possible to config a VPN Passthrough for open VPN?? In thath case I can buy a router that can handle the VPN and keep my netwrok config on the Zyxel ??
  • Zyxel_Vic
    Zyxel_Vic Posts: 282  Zyxel Employee
    25 Answers First Comment Friend Collector Seventh Anniversary

    Hi @MAD

    Yes, the IPSec/L2TP VPN passthrough is supported. If you got any problem when passing through the VPN traffic, you may check on the log to understand if any rule you set blocked it.

  • MAD
    MAD Posts: 8  Freshman Member
    First Comment Friend Collector First Anniversary
    edited March 2020

    Great @Zyxel_Vic now another question.

    when setting up Ipsec IKEv2 VPN, I have a cetrificate provided by my VPN service provider, I cant manage to get it in under My Certifacates. Under Trusted no problems, but from there I cant select it.

    Then under the IKEv2 config (Client role). I have a username ( email adress ). I cant change this as the VPN provider has this as optional. The @ seems not to be valid in your username field, is there a walkaround this.


    plz PLZ help Meeeeee

  • Zyxel_Vic
    Zyxel_Vic Posts: 282  Zyxel Employee
    25 Answers First Comment Friend Collector Seventh Anniversary

    Hi @MAD

    Unfortunately the special character in the IKEv2 User Name field is not supported currently. We will evaluate if this will be supported in the future.

  • MAD
    MAD Posts: 8  Freshman Member
    First Comment Friend Collector First Anniversary
    edited March 2020

    @Zyxel_Vic Thanks for your help in this matter. And hopfully this new update will be soon

    AND how about the certificate ?? The certificate i got fron my VPN provider is just a siple text file.

    (-----BEGIN CERTIFICATE-----

    xxxx

    -----END CERTIFICATE----- )

    Is there any way for me to use it on the USG60 ?? As i said above ther is no problems to load it in under Trusted certificates, but from there i cant select it when setting up the IKEv2 VPN client.

Security Highlight