IKEv2 causes USG to crash

Nikriaz
Nikriaz Posts: 5  Freshman Member
First Comment Friend Collector

We’ve been running several USG devices (110 and 210) without issues for years. However, our USG110 recently started hanging every three days. By "hang," I mean it completely stops responding and becomes inaccessible by any means.

To rule out hardware or configuration issues, we replaced it with a brand-new USG210 from our stock (including a new power adapter) and manually configured it from scratch—no imports, no old configs. Unfortunately, the issue persisted with the same 3-day freeze cycle.

Findings from Investigation:
We identified that the freezes always happen during IKEv2 rekeying. The issue started when a new remote user (Windows 10 native IKEv2 VPN client) joined. While this user is legitimate, their probably poor network conditions or MTU issues cause a lot of repeated warnings:
- "Replay detected"
- "Network congestion"
- IKEv2 rekeying every 2-3 minutes instead of the configured 8 hours.
[a reason why it's happening is a separate question]

This strongly resembles CVE-2023-33009 and CVE-2023-33010, which were patched in firmware 4.73. I suspect that the fix introduced a new bug even for legitimate users.

I understand that USG110/210 are EOL, but these firmware issues are severe enough that they shouldn't be ignored. 

This is IKE debug-level log of the crash moment. System resources within 1 second before crash were generous (CPU < 5%, Memory < 40% etc.)

2025-03-20 20_16_36-All_2025-3-11-21_31_25.xlsx - Excel.png

All Replies

  • Zyxel_Melen
    Zyxel_Melen Posts: 3,149  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate

    Hi @Nikriaz,

    Please be aware that the USG 110 and 210 have reached their End of Life (EOL) status, which means our support for this model will be limited. However, I checked with our team, and the USG FLEX H series doesn't have this issue. We recommended migrating to the USG FLEX H series.

    Zyxel Melen


  • mMontana
    mMontana Posts: 1,425  Guru Member
    50 Answers 1000 Comments Friend Collector Fifth Anniversary

    Latest firmware for USG ZLD 4.x version is V4.73(AAKY.2)ITS-23WK23-r109633 (this for USG60 but also available as Lab Firmware for the whole range).

    I don't know if will help to ease the issue, but I'd give it a shot while deceiding your next step.