An honest question from a 10-year USG user about where the FLEX H line is going...

Options
Zyxel_USG_User
Zyxel_USG_User Posts: 131 image  Ally Member
First Comment First Answer Friend Collector Second Anniversary
edited July 30 in USG FLEX H Series

After more than ten years on a USG20W-VPN, I did not want to be writing this.

That little box has been rock solid. ZLD has been predictable, boring in the best sense, and it has done exactly what I asked of it for a decade. When my current licences run out (soon), my honest first instinct was simple: stay with Zyxel, buy the successor, carry on.

I wanted to give you my money.

Then I looked at what the successor actually is.

The natural upgrade path from a ZLD USG is the FLEX H line on uOS, and the forums here tell a story that is hard to ignore.

Memory bugs, GUIs that stop responding, SSH that goes dead, units that lose connectivity after a power cycle and do not come back.

People returning hardware and going back to their old USGx0s because the new platform is missing features the old one had years ago.

I do not doubt the hardware is capable. But firmware maturity is the whole game for a firewall, and right now the honest reading is that uOS is still being finished in production, on customers.

So I did what anyone would do and looked here and elsewhere. I considered and dropped:

  • A…
  • B…
  • The FLEX H itself - dropped because of the firmware state above; I am not willing to be an unpaid beta tester on my own perimeter.

And here is the part I will be blunt about, because someone at Zyxel should hear it: I am now looking hard at vendors whose products are certified and actually deployed in secure and regulated environments - the kind with formal state-level security validation. Those cost considerably more than a SOHO Zyxel.

I am prepared to pay it.

That is how far the current situation has pushed a loyal, long-term customer.

I am not writing this to burn a bridge. I am writing it because competition and pressure are what keep vendors honest and products good.

Ten years ago Zyxel had a mature, dependable platform and I happily recommended it.

I want that Zyxel back.

I would genuinely rather be corrected than proven right, so if I have misjudged the current state of uOS, tell me - I am listening.

I am also curious whether this gets any reaction at all.

«1

All Replies

  • e_mano_e
    e_mano_e Posts: 121 image  Ally Member
    First Answer First Comment Friend Collector Sixth Anniversary
    Options

    I am using Zyxel firewalls for a long time now.

    I know the ZLD firewalls (ATP100 was my favorite model) and I know the new uOS models.
    uOS is a great improvement regarding usability and visibility.

    I'm now using a USG Flex200H in my business, there are the new FlexH series out at the customer sites and some are still using the old ATP100.

    I'm totally happy with using all of the mentioned models.
    I do not have any problems with them (mainly using VPN for home work users).

    From my perspective and for the way I use them, the firewalls are absolutely secure and rock solid.

    Just bear in mind that on forums there are mainly people complaining about things.
    The majority of users will not take time to write that they are happy.

  • Maverick87
    Maverick87 Posts: 211 image  Master Member
    5 Answers First Comment Friend Collector
    Options

    I think that this is a community support so is normal that users that have specific bug/specific requests going here to have a solution.

    And probably precisely because this community is centering about this, you not found here negative or positive comments about hardware and software

    Also, I found in Zyxel quality and professionality about solve problem, found and release fix. Found in Zyxel the "customer first" that other brands not have.

    I personally have found a series of bug, but I could always count on their timely support and in a short time I got fixes accessing to the beta/preview firmware (I thing that other brands not release this type of firmware)

    You need to try to find numbers about how many people/company buy zyxel, comparated to other brands…

    And… if you find a bug you can always raise a ticket.

  • Matthew
    Matthew Posts: 27 image  Freshman Member
    First Comment First Answer Friend Collector Eighth Anniversary
    Options

    I too have used Zyxel for over 10 years (USG 50, USG60/110/210, ATP200/500, Flex 200, and now Flex 200H) across a dozen customer sites. I definitely feel they released the H series way to early and I waited about a year or so before upgrading to the H series. I feel that they are now pretty much at feature parity with the older USG/ATP/Flex line so I would have no worries about upgrading to the H series unless you are doing some very unique network stuff. Mostly it has been very stable for me and I have not run into the vast majority of problems reported here.
    Had some minor GUI bugs that were fixed in the next firmware release but they were an annoyance and did not break functionality. Not good but not disruptive to operations.
    Had a bug with IKEv2 VPN authentication with active directory but a call to support got a workaround in place. Plus to be fair Zyxel has had a bug in the older USG/Flex series with AD 2022+ VPN authentication for a while.
    Their rollout was botched in my opinion that has long since been corrected and I feel the feature set of the H series is better than the older ones now.

    I originally went with Zyxel routers years ago solely due to their support. I could pick up the phone and the first person I got was native English speaker (or very close) who asked three things: what is your name, what model, what is the problem. Their first tier support was very knowledgeable and didn't waste time with scripts. When they didn't know, they went to talk to an engineer right then. I've not seen support like that from any other major vendor.

    Like other people have said, most of the people on these forums are here to report problems rather than report positives (I'm just looking into the new 1.39.0 release today). So definitely something to consider but not the whole story. Also the majority of the bug reports are from a few years ago rather than recently.

  • Tommy_TEK
    Tommy_TEK Posts: 2 image  Freshman Member
    First Comment
    Options

    This comment is pretty much spot on. I've been a Zyxel SOHO customer since the P312 — that's 2001 era — through now. I must say that the 50H throughput performance is really good, but …

    > no IPv6 support? (the "preview" enable via the CLI is worthless and crashes — my USG Flex 100 had the necessary support and generally worked fine). This is the biggest missing functionality for me.

    >The USB port recognizes a only couple of my memory sticks — regardless of format, even a new Sandisk — but it does recognize an ancient NOR flash based Intel stick. Quite useless. I generated a bug report for this, but heard nothing back.

    Fortunately I don't use VPN functionality any more and general stability on 1.38 FW has been good after flushing anything in the config file that was related to IPv6. I hope that I won't get an unexpected surprise when I reboot for some reason.

    However, there's other roughness that is annoying… Like:

    >It appears the Dashboard Security summary is only for the previous 24 hours. 7 days would much better. I don't want to consult Nebula every time for a quick check. The previous Flex series kept totals until one told it to reset them or rebooted the box.
    >DHCP lease expiration times are missing for reserved entries. This is useful information for network debug.

    >It would be nice if the reserved DHCP entries didn't get erased if DHCP was temporarily turned off on a LAN.

    While the hardware plus licenses were a good deal for me as my licenses also were close to expiration, I am somewhat shocked at how rough around the edges the FW is given my previous experience with Zyxel.

  • Maverick87
    Maverick87 Posts: 211 image  Master Member
    5 Answers First Comment Friend Collector
    Options

    DHCP lease expiration times are missing for reserved entries. This is useful information for network debug. 

    I think that a reservation is never expired… or I missing somethings?

    If an address expires it's deleted from the list, so is not reserved.

  • Zyxel_Melen
    Zyxel_Melen Posts: 4,992 image  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate
    Options

    Thank you all for the detailed and balanced input on this thread — we want to respond to the original question and to several of the points raised below.

    Hi @Zyxel_USG_User

    Thank you for sharing this so openly. We understand your concern, especially after relying on the USG20W-VPN and ZLD for more than ten years. ZLD earned trust through long-term stability and predictability, and we fully understand why you would expect the same confidence from its successor.

    To be transparent, uOS is not just ZLD under a new name. It was redesigned with a new software architecture to support newer hardware, long-term scalability, and future feature development. Because of this transition, some behaviors and features were not identical to ZLD in the early stage, and it has taken time to close those gaps.

    We also understand that customers should not feel they are helping finish a firewall platform in production. That feedback is valid, and we take responsibility for addressing issues as quickly as possible.

    That said, recent uOS firmware releases have significantly improved feature completeness and system stability. uOS has been continuously strengthened to cover the functions and reliability most users need, and the number of online uOS devices has now officially surpassed the number of online ZLD devices.

    We appreciate your loyalty and direct feedback. It is exactly the kind of feedback that matters.
    Let us know if you still have concerns or doubts. We’ll do our best to explain and support you.

    Zyxel Melen


  • Zyxel_Melen
    Zyxel_Melen Posts: 4,992 image  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate
    Options

    Hi @e_mano_e and @Maverick87

    You're right that forums naturally skew toward people reporting problems rather than satisfaction, and we don't take that context for granted. We're glad the Flex200H and current uOS units have been solid for you, and thank you for highlighting the support experience, including beta firmware access — that responsiveness is something we intend to keep.

    Zyxel Melen


  • Zyxel_Melen
    Zyxel_Melen Posts: 4,992 image  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate
    Options

    Hi @Matthew

    Your point that the H series launched too early is fair, and we take that seriously. It's encouraging to hear that, from your experience across a dozen sites, the platform is now close to feature parity with the older USG/ATP/Flex line, and that recent issues have been minor or resolvable through support.

    Zyxel Melen


  • Zyxel_Melen
    Zyxel_Melen Posts: 4,992 image  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate
    Options

    Hi @Tommy_TEK

    Thank you for the specific list: lack of IPv6 support beyond the CLI preview, USB drive recognition, and the 24-hour-only dashboard window. These are concrete, actionable items.

    About the IPv6 support, I will send you a private message to get your use case/scenario first.

    About the USB part, please share your report information with me. I will help to follow up this issue.

    About the 24-hour-only dashboard window, I will discuss with our product team first.

    About the DHCP reserved entries, it is a static DHCP entries, therefore, the expiration time should be less important. Could you share your debug experience with us?

    About the reserved DHCP entries been erased after disable DHCP server, this is more likely related with the function behavior. Could you share the reason of temporarily turned off DHCP server?

    Zyxel Melen


  • Tommy_TEK
    Tommy_TEK Posts: 2 image  Freshman Member
    First Comment
    Options

    Hello Zyxel Melen!

    I definitely appreciate the response. On a very positive note I will say the throughput performance on the 50H is really good. It appears to far exceed that of the older Flex 100. Except for two crashes when IPv6 was enabled, stability is also good (zero problems on 1.38 up solidly for more than month at a time).

    The only real shortcoming is lack of IPv6 support — functionality that worked pretty well on the non-H Flex 100 with prefix delegation configured. The necessity for IPv6 at this time is significantly debated, but is now rather widely supported.

    The USB not seeing some devices is a bug. It works on the few USB3 flash devices I have, but none of the USB2 I've tried - the exception being a really old Intel 64MB(!) flash stick. I have a screen shot of the debug log that shows a Sandisk device as being detected, identified, and attached as sda:, but it doesn't show up in the GUI. That's with 1.38. Are there any changes to this area in 1.39?

    As for the expiration time of reserved/static entries, it's something I came to expect from the non-H series and from Linux DHCP. It's useful for determining which entries may not be in use, or are misused. Again, not critical, but once one is accustomed to seeing it, it's missed.

    As for the reserved entries disappearing if DHCP is disabled. I observed that during initial installation and some network swapping. It was just a surprise, because a quick re-import of the table fixed it. Yet, it's important that information isn't lost if a port is temporarily disabled.

    An interesting behavior I've noticed is that the 50H NTP client polls the NTP server quite frequently. I've noticed at times it's polling every 64 seconds and sometimes every 128 seconds. That's not really a bug, but it is unusually frequent (the minimum allowed) when compared with other NTP clients. I suspect uOS doesn't have a clock discipline algorithm enabled. Certainly, not a problem with a server on the LAN.

    Again, I very much appreciate your response and efforts! -Tom