Recovery Steps for USG FLEX/ATP Series Application Patrol Signature Issue (Jan. 2025)

13

Comments

  • Zyxel_Tobias
    Zyxel_Tobias Posts: 208  Zyxel Employee
    5 Answers First Comment Friend Collector Sixth Anniversary

    @DavideMauri
    Application Signature Download is separated between partitions. The affected Partition is the Running Partition first. If you follow the SOP, then you´ll "Reset" on Running, you´ll do FTP Upgrade on Running with Weekly to fix it, so NO NEED to do anything on Standby Partition.

    But we have some customer sharing solutions (recovery) which are NOT following the SOP shared. For example you can "switch partition" by Console or also Reboot to other partition. As these partition never download a wrong signature, their are unaffected, so no need to do anything. However this will NOT fix the "Standby Partition" in this case (once role changed to Standby Partition) the "previously affected Running partition, is now Standby" and here is the gap, this partition, still stored the wrong Application Version which need Console CLI recovery, or some process like Online Upgrade (which will be apply by default to Standby, to keep roll-back scenario) can´t work.

    So we suggest everyone, to follow SOP. Yes, there are ways to bring device back online by Reset, Partition Swap or other scenarios, may also remote, but it doesn´t help you in the future, if you not follow the SOP we shared before.

    I hope this makes it a bit more clear.

  • Zyxel_Tobias
    Zyxel_Tobias Posts: 208  Zyxel Employee
    5 Answers First Comment Friend Collector Sixth Anniversary

    @mocr

    Bot Versions are good and you can enable Auto Update. Only Version "123" in the end was affected. You have "102" in the end of both, so fine.

  • Zyxel_Tobias
    Zyxel_Tobias Posts: 208  Zyxel Employee
    5 Answers First Comment Friend Collector Sixth Anniversary

    @USG_User

    There is nothing planned and also no need. The V5.39(ABWD.1)-sig-20250124 only assist in removing the bad signature from partition, that´s it. Once this is done, you can keep this firmware or you can install last official current FCS. As the issue was NEVER firmware related, there is no need to plan a Patch 2 for this issue. Only the signature needs to be removed, which this firmware can assist with.

    Thanks.

  • USG_User
    USG_User Posts: 379  Master Member
    5 Answers First Comment Friend Collector Seventh Anniversary

    @Zyxel_Tobias

    Thanks Tobias. We are missing such important information.

    Then we will switch back to standard V5.39(ABWD.1) to remove the "a new firmware is available" popup everytime when logging-in.

  • Zyxel_Tobias
    Zyxel_Tobias Posts: 208  Zyxel Employee
    5 Answers First Comment Friend Collector Sixth Anniversary

    @USG_User

    No Problem. You can switch back to Patch 1 or keep the Signature Version. The Signature Version is build on our latest Weekly from Bug-Fix Level, so a bit better on fix level as Patch 1. However, the next release on ZLD is planned around end of March and will be 5.40.

    Thanks.

  • Agor76
    Agor76 Posts: 44  Freshman Member
    First Comment Friend Collector Seventh Anniversary

    Hi Tobias,

    I should mention that I couldn't get ikev2 remote clients to connect to the USG while the signature version was running. Switching back to patch 1 solved the problem.

    regards

  • AndB
    AndB Posts: 3  Freshman Member
    First Comment
    edited January 29

    Cannot enter debug mode here; pressing keys while on “Press any key to enter debug mode within 3 seconds” do nothing.

    Ticket 485158

    Changed cable, now it works.

  • JGaidula
    JGaidula Posts: 2  Freshman Member
    First Comment Friend Collector Sixth Anniversary

    This method also worked for me. Driving to the customer site and plugging in a cable wasn't an option.

  • AndB
    AndB Posts: 3  Freshman Member
    First Comment
    edited January 29

    How to remove App-Patrol version 20250123 from a well-working Flex500?

    I need to do it before activate HA with a recovered Flex500.

    Please publish a new working App-Patrol version on the cloud, so we can download it automatically overwriting 20250123.

    Regards

  • Zyxel_Melen
    Zyxel_Melen Posts: 2,708  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate

    Hi @AndB,

    The date code firmware will help to remove the issue of the Application patrol signature version 20250123. Are you still can't enter the debug mode? Have you tried using Tera Term and keep pressing any keys when booting up?

    If you continue to encounter difficulties or need additional support, please do not hesitate to reach out to our support team at cso_security@zyxel.com.tw or leave the detail comment here with your region(country), model information (S/N) and contact info. We'd like to have contact with you to assist and resolve the issue caused by the signature incident.

    Thank you for your understanding and continued support.

    Zyxel Melen