cannot upgrade to ZLD4.62 because of problem with tunnel

Options
Chris_schmitten
Chris_schmitten Posts: 3
Friend Collector First Comment
edited April 2021 in Security
Hi,

i just got email from Zyxel that by end of april you should upgrade to zld4.62. i already was at 4.62 and after a few days a tunnel to a partner company stopped suddenly transmitting traffic. after a reboot it started working again but agani after 2 days no mor traffic. so i got adviced to downgrade to 4.39 until there was a bugfix release.
so i cannot upgrade but according to the email my service condition will be interrupted.
what do i need to do now?

thanks,
chris

All Replies

  • Zyxel_Can
    Zyxel_Can Posts: 342  Zyxel Employee
    Friend Collector First Answer First Comment
    Options

    Hi @Chris_schmitten,

     

    Can you please share some information with me;

     

    1- What's the model names and firmware versions for both devices?

    2- Who advised you to downgrade firmware to 4.39?

    3- Do you mean with 4.62 firmwares for both sites, VPN connection don’t send traffic?

    4- Did partner company changed any configuration or firmware version on their device?

    5- Does VPN connection work now with current firmwares?

     

     If you have concern about interrupting service, you can update the device's second partition to 4.62 and keep your stable configuration in the current partition.

    Best regards.


  • Chris_schmitten
    Options
    Hi,
    at 1) on my side it is a USG310, on the Partner side it is a fortigate (dont know the firmware).
    at 2) i was adviced from zyxel support (either Mr Piris or Mr Hermanns)
    at 3) i dont have control over the partner firmware, but i talked with the tech and he said, that he had tunnels with other partners (we are a skiing area) which connect to the same firewall and same services in the background that were sending data at the time our tunnel was down.
    at 4) no, as this is a production network there was no firmware change on their side.
    at 5) yes, with 4.39 tunnel works fine.

    thats what is currently running - 4.39 as primary and 4.62 is on the second partition. but when i downgraded last time i lost some changes i made shortly before the upgrade. and as we are still in operation right now i dont want to switch over right now. i can do this mid of april - then we close until may and i have some time to test.

    thanks,
    regards,
    chris
  • Zyxel_Can
    Zyxel_Can Posts: 342  Zyxel Employee
    Friend Collector First Answer First Comment
    Options

    Hi @Chris_schmitten,

      

    4.62 is still the recommended version due to security concern since we had leveraged some vulnerability patches. 


    There’s a 4.62 current release, perhaps you can install it to replace the original 4.62 formal release version and see if this symptom still exists.

    I will provide you download link by private message. Please kindly install that version.

     

    Best regards.
  • Chris_schmitten
    Options
    Hi @Zyxel_Can,

    thanks for this build. i will test it after April 5th as then we have closed for a few weeks then. will update the results then.

    thanks,
    chris

Security Highlight