USG310 - Web Configurator slow to unusable over SSH tunnel
We always used to remotely administrer our beloved USG300 with Web Configurator interface tunneled over an SSH connection.
Client PC with Firefox (https) --> SSH --> LAN server --> USG300
We just powered up the USG310, did initial setup and connected it to the LAN. HTTPS Web interface works smoothly from a LAN client. On the other hand, it is deadly slow when connecting from a remote PC over the same SSH tunnel we use for USG300.
Opening the login form takes ages but, once pressed the LOGIN button, the page load stucks forever and no Web Configurator interface is ever shown.
All Replies
-
Hi @Rafff
You can check if the SSH service is enabled on the device.
In the default setting, SSH is not allow to the device.
Go to Configuration > Object > Service > Service Group > select the Default_Allow_From_WAN_To_ZyWALL > click Edit
Add SSH into the Default_Allow_From_WAN_To_ZyWALL
0 -
SSH?? The problem was with HTTPS not with SSH! As per my previous message, the SSH tunnel is created to a LAN Server, not to the USG310. The HTTPS works well over LAN.
Anyway, the problem looks solved now that one WAN interface on the USG310 has been activated. In my opinion the problem had something to do with eventual reverse DNS resolution performed by Zyxel on HTTPS requests, maybe for logging purposes, who knows. I do not have time to investigate now, but I've seen similar behaviour before on other appliances and was related to server DNS resolution timeout failure on client connection requests (e.g. security reverse lookups in vsftpd)
0 -
Hi @Rafff
Thanks for your feedback,
If there is any related issue happens again, feel free to contact us in private message so that we can help on it directly.
0 -
Hi @Zyxel_Jerry, i've the same issue with gs1900-8hp, i use ssh tunneling to access on the webui.
On the ssh tunneling it's ok with HTTP but with HTTPs it's very slow…
Equipment informations:
Model Name:
GS1900-8HP
Revision:
A1
Firmware Version:
V2.70(AAHI.5) | 02/08/2023
It's OK in HTTPs with others devices.
Best regards,
Kris
0
Categories
- All Categories
- 415 Beta Program
- 2.4K Nebula
- 149 Nebula Ideas
- 96 Nebula Status and Incidents
- 5.7K Security
- 263 USG FLEX H Series
- 271 Security Ideas
- 1.4K Switch
- 74 Switch Ideas
- 1.1K Wireless
- 40 Wireless Ideas
- 6.4K Consumer Product
- 249 Service & License
- 387 News and Release
- 84 Security Advisories
- 29 Education Center
- 10 [Campaign] Zyxel Network Detective
- 3.5K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 85 About Community
- 73 Security Highlight