IPSEC VPN - AD link broken with special caracters
Freshman Member
Hi,
We found a bug in usg flex 100h last firmware concerning ipsec vpn.
The authentication doesnt work if the username OR password contain "é" or "è".
We are using a standard microsoft ad, and i think a standard configuration on the firewall.
The work around is changing name and password but its kinda annoying.
Thanks
All Replies
-
Hi @Rdmusr
Thank you for taking the time to report this.
After investigating, this is actually expected behavior rather than a firmware bug. Microsoft itself recommends using only standard ASCII (pure English) characters for Active Directory user accounts, as diacritic characters such as "é" or "è" can cause compatibility issues across various systems and protocols.
You can find more details in Microsoft's own documentation here:
Our IPSec VPN implementation follows this same guideline, which is why authentication fails when usernames or passwords contain accented characters.
The recommended solution is to ensure that AD accounts used for VPN authentication only contain standard English (ASCII) characters in both the username and password. We understand this may be inconvenient if many accounts are affected, but aligning with Microsoft's best practices will ensure the most reliable experience across all connected systems.
Zyxel Melen0
Categories
- All Categories
- 442 Beta Program
- 2.9K Nebula
- 220 Nebula Ideas
- 128 Nebula Status and Incidents
- 6.5K Security
- 606 USG FLEX H Series
- 344 Security Ideas
- 1.7K Switch
- 84 Switch Ideas
- 1.4K Wireless
- 52 Wireless Ideas
- 7K Consumer Product
- 299 Service & License
- 482 News and Release
- 92 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 4.8K FAQ
- 34 Documents
- 87 About Community
- 105 Security Highlight
Zyxel Employee