Where is SNAT?

Options

Our US suppliers are showing that the only available units are this new H series. We purchased one thinking it was simply "hardware only" because otherwise everything is bundled with licenses. What we found is this new cut down interface with critical features missing.
Calling in to the support line was even less helpful - the tech could not provide any information on what else was removed, simply saying "If you don't see it, its not there, we might add it in the future"
What is going on with this model line and is it fully replacing the non H series in the US?

Accepted Solution

  • SecureTechInovations
    Answer ✓
    Options

    Sale engineer confirmed:
    currently the USG FLEX H doesn't support SNAT/DNAT functions on the VPN as of yet. This is something that will be added in the next major firmware update in April. 

All Replies

  • PeterUK
    PeterUK Posts: 2,770  Guru Member
    First Anniversary 10 Comments Friend Collector First Answer
    Options

    If all goes to plan it may have features the current models have in a year or two

    I think Zyxel aim was to get it out the door being the 2.5Gb and 10Gb hype

    https://support.zyxel.eu/hc/en-us/articles/14774976400530-USG-FLEX-H-Series-Firewall-Comparison-Operating-System-Feature-Table-ZLD-V-S-uOS

  • mMontana
    mMontana Posts: 1,304  Guru Member
    First Anniversary 10 Comments Friend Collector First Answer
    Options

    So zyxel products are ruled out until won't have these features. At least… for my opinion.

  • I should expand that its SNAT over VPN that we need out of the unit.
    I was pointed to this document:
    https://download.zyxel.com/USG_FLEX_100H/user_guide/USG%20FLEX%20100H_V1.10_Ed2.pdf

    We can create a route-based VPN tunnel, set the VTI and it auto-creates the static route using the VTI, but you can't seem to set any SNAT there.
    Inside Policy Route, there is a very clear and simple SNAT option, but I can't select the VTI created by the route-based VPN.
    Selecting Policy-based VPN does not even expose the VTI creation and going into VTI under Interfaces there is no add button to create one.

    Am I crazy, misunderstanding or is this feature just really not available right now?

  • SecureTechInovations
    Answer ✓
    Options

    Sale engineer confirmed:
    currently the USG FLEX H doesn't support SNAT/DNAT functions on the VPN as of yet. This is something that will be added in the next major firmware update in April. 

  • Zyxel_James
    Zyxel_James Posts: 618  Zyxel Employee
    First Anniversary 10 Comments Friend Collector First Answer
    Options

    Yes, the next version V1.20 will support routed-based VPN for policy routes.