An honest question from a 10-year USG user about where the FLEX H line is going...
All Replies
-
Hi all, thank you for the replies.
A few points from my side.
Of course a forum skews towards problems. People post when something hurts and stay quiet when things simply work. That is universal, not specific to Zyxel - I spend my own share of time troubleshooting kit from a certain fruit-branded vendor, with close to zero feedback from the manufacturer when a patch breaks something.
So to be clear about where my post came from: it was not based on the forum. It was based on the release notes.
I have been reading the uOS firewall release notes for quite a while now - not the threads here, the vendor's own change log. The question that gradually formed was never "are people complaining". It was: do I want to buy a platform whose published fix list still reads like "fixed basic functionality"?
I'd say: just look for the evidence yourselves in the release notes published here. A few examples: v1.21 (July 2024) fixed "the device becomes unresponsive and stop(s) processing traffic". v1.30 Patch 1 (November 2024) fixed upgrades that rolled back or reset the configuration to factory default after a reboot. v1.37 (January 2026) fixed a DoS prevention rule scoped to the WAN interface that was also filtering traffic from the IPsec tunnel. These are Zyxel's own words, with ticket numbers, in the official release notes.
That seems a fair question to ask before spending money, and it is answered from Zyxel's own documentation rather than from anyone's bad day.
I would still rather be corrected than proven right.
0 -
So, your point is:
based on the release notes of the firmware, there are some fix about bug on "basis" functionalities.
It's like saying: we've solved a problem with packet transmission between two ports. It's such a basic feature that theoretically everything should have been working perfectly for years.
Is the way I interpreted it correct? If you consider that nothing is perfect, and that what seems to have been consolidated for years is, in some way, never consolidated. I've worked both as a programmer and as a bug tester, and I can tell you that it's difficult to keep up with new releases while also keeping the previous part intact; some bug always slips out or is always introduced. But this applies to everyone, one above all being the recalls for malfunctions in cars, one among many relating to airbags that deployed late or even if you hit a pothole. In every sector, there's always some bug or some unexpected situation, even in things that have worked for years.
But this doesn't mean you shouldn't buy a car anymore; hopefully, any manufacturer knows how to put together a steering wheel, four wheels, and an engine, but sometimes even engines seize up and break, even in the most expensive cars.0 -
I hope that @Maverick87 will consider interesting what I'm about to write.
At uOS devices I started to read a lot of forum posts about features, stability, performances. And what flabbergasted me was that a "brand new generation" of products was, for several features, lacking compared to stale old (philosophically) firmware 4.x or 5.x versions. Don't get me wrong, probably for some more value added options (read: pay) is a nice step forward but currently these are not seen as interesting for my customers. More on that: at the beginning "nebula" for appliances was a "cloud only" scenario, which did not work in any way to me (if the connection to internet is severed in my opinion is important that i can connect to the device with a local user).
Few old 4.x devices were replaced, and at that time my standard pitch was "Migrate to 5.x is faster, easier, with less risks. Probably we'' need to replace sooner the hardware, but currently there's no gain in go for uOS".
For starting a new branch (which is rolling in these days) at march i looked for the price status and the OS status for uOS. At that time, there were so little price difference between uOS and ZLD. Also, ZLD already had expire date on it and it was 2030.
Therefore I suggested my customer to consider the higher price for more time getting in touch with the newer generation and discover if Zyxel was a interesting canditate, or of the branch was worth the time for being used as evaluation for other products.
I toyed a little with uOS 1.38 and I found it "enough" for the needs. On one hand is a bit more clicky in a lot of steps, and the menu structure could be vastly reworked for being perceived as real improvement. I found also some quirks in the environment I'm managing, but currently and for "simple" things the device shows to be not so bad. However… while the philosophy is the same that Zyxel had, with some improvements in the user interface (1 page for the VPN, not splitting anymore between gateway and connection), IDK if a really skilled CLI grinder will evaluate "as good as" ZLD 5.
0 -
My first Zyxel device was the Flex 50H as entry level, I've never had the pleasure of playing with older ZLD devices, so I have no knowledge of older firmware or devices; furthermore, I only use the firewall for very basic things (Policy rules, Tailscale VPN, etc.).
In my opinion, there are several things that can definitely be improved, and I'm not afraid to point out that with every fix released, something breaks (I just filed a bug report because with the latest firmware, some SNMP OIDs that I used, now no longer work).
But again, this is perfectly normal, and I understand it.
In fact, I really appreciate that the Zyxel technical team is always on the ball and is here to help with even the smallest issues; and that's not something you can take for granted.0 -
I stayed 10 years with Zyxel, with its highs and lows. The competition's bar level rises.
I just don't want to buy a new device doing things like this:
Through my clients, I have recently finalised setting up a NAT0-restricted firewall, it costs more (hardware+licenses), it is more complex- but man, oh man- do these things work as intended! In a few weeks of complex architectures and configurations, using TPM on them, having the contract possibility for next day replacements service, using the latest safety measures and technologies (even post-quantum stuff inside already), looking and implementing relevant blocks from NIS2 and whatnot - I've encountered one or two configuration quirks which needed a bit of more brainwork for understanding and a bit of testing what works and what not. Nothing more. This is what others do, and this is what also counts in the comparison money versus functionalities, stability- the whole lot one is paying the money for.
I am still waiting since months for an answer about a UI/UX quirk on the 10-years old firewall, which is wearing my patience off daily by tens of times usage of 2FA sign-in, which accepts enter after entering the password but accepts only mouse-click on the OK button for the 2FA. That is used in the operations of firewalls on a daily basis! I understand that that is an old device, I understand that the marketing pushes to buying the new series- but, there are also other competitors outside which may do things easier for the admins- not worse, and they will be looked at.
I miss a lot the part of "making the life of admins easier", not worse.
I have tinkered along years with the IPSec VPNs on Zyxel more not working that working, doing all sorts of workarounds and reconfigurations- especially when the fruit-branded company pushed updates/patches and breaking the IPSec VPN functionalities on their devices on a constant basis. Here, on this other brand device I recently configured- it works as it should. activate, and works. disable, stops. As simple as that, as simple as it should - with all the complexity behind silently working. The rate of users accepting to toggle a button in their taskbars - and the thing just works in the background, without having to click several times elsewhere and around- is amazing. Keep it simple and working, and the users will use the safety measure.
If that's the deal, losing a ten-years old true customer over not fixing your stuff which annoys the heck out of an admin tens of times on a daily basis , so be it.
I for one am fed up with all of this and I'll buy another firewall brand from now on.
0 -
We put in 30 man hours the latest weeks and got help from zyxel support but nor we or they can get our dynamic ipsec tunnel to work on our new flex 500 as a replacement for our old vpn 100 model. The tunnels are up and we can http in to the endpoints and we can ping from both ways but the traffic is not normal and we cant use our rco passage system on port 1000 both ways from our endpoints system to our server on the flex500 side.
0 -
I had different weird things before, like win11 not being able to update via IPSec VPN. I read about windows internal services and processes being very sensitive to ipsec vpn environments ie some services won't work without 'direct connection to mothership', and can be theoretically both windows and firewall / IPSec VPN if win11 cannot update with an internet connection. But hey, I am on another firewall brand and voilà! all of a sudden, the win11 updates work. And Mac clients and iphones work as well which are known to be thrown down by their own mysteriously kept updates, or by firewalls and their protocols and suites.
0
Categories
- All Categories
- 442 Beta Program
- 3.1K Nebula
- 236 Nebula Ideas
- 6.8K Security
- 737 USG FLEX H Series
- 376 Security Ideas
- 1.8K Switch
- 87 Switch Ideas
- 1.5K Wireless
- 58 Wireless Ideas
- 7.2K Consumer Product
- 319 Service & License
- 512 News and Release
- 99 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 5.2K FAQ
- 34 Documents
- 91 About Community
- 119 Security Highlight
Ally Member
Master Member
Guru Member
Freshman Member