Firmware 1.39 - secondary WAN IP

Options

Did something change with firmware 1.39 when having a secondary WAN IP? Now it seems that all outbound trafic is using the secondary WAN IP and not the primary WAN. IP on the default TRUNK. Is that normal behavior?

Policy route is not an option.

I have one VPN connection that requires the secondary WAN IP.

«1

All Replies

  • PeterUK
    PeterUK image  Guru Member
    250 Answers 2500 Comments Friend Collector Eighth Anniversary
    edited August 7
    Options

    There is a bug in the release with TRUNK but that for User-Defined Trunk but your issue is your using default TRUNK which mean all external are active and with Policy route the LAN with use either by WRR.

    however I think the bug for User-Defined Trunk is that it ignores Policy route on failed WAN where you only want traffic going out the given WAN even if failed.

    so make a User-Defined Trunk with your two WAN and set one to active and on passive and set it by User-Defined Trunk.

    But really you need to use Policy route for more control it should not impact VPN connection

  • Mk88_it
    Mk88_it image  Ally Member
    First Comment Friend Collector Fourth Anniversary
    edited August 7
    Options

    @DanniKool We have the same issue here (500H). With 1.39 firmware If you set "outgoing-interface" in a policy route and you have configured additional IPs on the wan interface, the device uses the last additional IP configured on the wan interface

    We have opened a ticket to local support.

  • DanniKool
    DanniKool image  Ally Member
    First Answer First Comment Friend Collector Eighth Anniversary
    Options

    I did a reconfiguration on all site-to-site VPN's from policy-route to policy-based. Added a Policy route to LAN and all VLAN's with next-hop TRUNK outgoing address translation. Re-added the secondary WAN IP under ge1. Now that single site-to-site VPN connection that needed the secondary IP for outgoing is working again and all outgoing trafic on our LAN is using the primary WAN IP….

  • Zyxel_Melen
    Zyxel_Melen image  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate
    Options

    Hi @DanniKool

    May you share your VPN configuration (Network > My Address)? If your configuration is "Interface ge*(WAN)", the connecting IP address might not your primary address. This is not because of firmware but an OS layer behavior. The order of the interface IP address will not same as you set when every time boot up the firewall.

    Please select "Domain Name/IP" option and fix your primary IP address.

    image.png
    Zyxel Melen


  • DanniKool
    DanniKool image  Ally Member
    First Answer First Comment Friend Collector Eighth Anniversary
    Options

    @Zyxel_Melen I was already using the Domain Name / IP field with the secondary WAN IP as My Address. That's not the issue as it was working perfectly on both 1.38 and 1.39.

    The issue is that with a secondary WAN IP added to ge1, all outgoing trafic on LAN (not configured with Policy route/next hop>trunk/SNAT) are using the secondary WAN IP and not the Primary static WAN IP address on firmware 1.39.

  • Zyxel_Melen
    Zyxel_Melen image  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate
    Options

    Hi @DanniKool

    Thanks for your update. I have replicated this issue, and we are investigating on it. I will update once I get further information.

    Zyxel Melen


  • Zyxel_Melen
    Zyxel_Melen image  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate
    Options

    Hi @DanniKool

    This issue has been addressed and will be fixed in future firmware release.

    Zyxel Melen


  • elektromassaMec
    elektromassaMec image  Freshman Member
    First Comment
    Options

    Hi,

    I would like to report a serious WAN trunk issue on the USG FLEX 100H, which appeared after upgrading to firmware 1.39.

    My WAN trunk configuration is very simple:

    • WAN1: Active
    • WAN2: Passive

    Before firmware 1.39, this configuration worked perfectly: traffic used WAN1, while WAN2 was used only for failover.

    Since firmware 1.39, the behaviour has changed. Even when WAN1 is fully operational, the USG FLEX 100H sends some connections through WAN1 and others through WAN2, despite WAN2 being configured as Passive. The interface selection appears unpredictable.

    This has caused a considerable waste of time troubleshooting routing, NAT, policy routes and other configuration settings before identifying the trunk as the source of the problem.

    At the moment, the only reliable workaround I have found is to remove the WAN trunk completely and route directly through the WAN interface. This restores predictable routing, but obviously means losing automatic WAN failover.

    Considering the cost of the USG FLEX 100H, this is very disappointing. I would expect a basic feature such as an Active/Passive WAN trunk to work reliably, particularly since exactly the same configuration worked correctly before firmware 1.39.

    For now, I am forced to operate without WAN failover until Zyxel releases a firmware fix for this issue.

    I hope this regression can be identified and resolved as soon as possible.

  • elektromassaMec
    elektromassaMec image  Freshman Member
    First Comment
    Options
  • phayze
    phayze image  Freshman Member
    First Comment Friend Collector Third Anniversary
    Options

    I also having same issue with 700H on V1.39(ABZI.0). Using WRR on (WAN3 and WAN4) Trunk. Almost 99% of traffic is using WAN4.