Missing app and traffic counters inside "Firewall network applications" widget
Hello everyone,
remembering this thread:
I'm doing a new backup -with another ORG- that has multiple sites: to be exact these examples are from a massive backup from Site1 to Site2.
Both have Zyxel appliances, Site1 an ATP200 while Site2 a SCR50AXE.
As you can see in this moment (Italy time, 2026/04/12 13.00 ca.) from Site1:
to Site2:
I'm missing about 522 GB (!) of traffic inside Site1 widget.
I know this traffic it's safe because it is a backup, made with Synology products, but in this scenario I could have a massive data leak without noticing it at least as "unknown" traffic as it is shown with a really basic SCR50AXE.
This is very strange, I consider it as a bug.
As per your documentation:
Firewall network application widget should record and show only WAN traffic, in this scenario I have 522 gigs of WAN traffic that I miss in that widget for Site1 (these data are going outbound from Site1 to Site2).
As per your documentation:
Inside the Firewall Clients by Usage widget I see no trace about those gigs too (LAN+WAN):
As shown I have about 106 MBs for a NAS.
Nothing about 522 GBs from Site1 to Site2.
I would suggest a revision for "unknown" traffic on Site2, with HyperBackup app signature.
I would like to understand how to solve the problem with ATP200 on Site1, because it seems that Nebula from the update 19.30 is not able to identify properly for Flex and ATP all the traffic passing via the firewalls.
All Replies
-
Hi @GiuseppeR,
First of all, we would like to clarify that the unknown traffic is not because Nebula cannot recognize it. Instead, it is related to the firewall's identification capabilities.
After our initial confirmation, we've confirmed that the issue you're encountering is likely due to differences in how ATP200 firewall process and handle data. This results in inconsistent traffic statistics and display on NCC compared to other sites with different gateway devices.
To proceed, we'll need packet captures for the relevant team to analyze further. I also noticed that in a similar previous case, Zyxel_Melen had already asked you to assist with packet captures—if you have the opportunity to provide them, we can start analysis with that.
In addition, please enable Zyxel Support Access in case we need to review your org/site. Thank you!
Zyxel Tina
0
Categories
- All Categories
- 442 Beta Program
- 3K Nebula
- 223 Nebula Ideas
- 129 Nebula Status and Incidents
- 6.6K Security
- 625 USG FLEX H Series
- 351 Security Ideas
- 1.7K Switch
- 84 Switch Ideas
- 1.4K Wireless
- 54 Wireless Ideas
- 7K Consumer Product
- 298 Service & License
- 491 News and Release
- 92 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 4.8K FAQ
- 34 Documents
- 88 About Community
- 108 Security Highlight
Guru Member





Zyxel Employee