Recovery Steps for USG FLEX/ATP Series Application Patrol Signature Issue (Jan. 2025)

1235»

Comments

  • MikeForshock
    MikeForshock Posts: 44  Freshman Member
    First Comment Friend Collector Fourth Anniversary

    Sure would be nice to be able to roll-back these updates to signatures as a separate process

  • MikeForshock
    MikeForshock Posts: 44  Freshman Member
    First Comment Friend Collector Fourth Anniversary

    Incase this issue is still lingering for others. This process recovered two of our units, but does not follow this guide exactly and your mileage may vary.

    Reboot router
    Login via webui
    Download config and enable FTP (quickly, before it locks up!)
    Reboot router again
    FTP into the router, upload the date firmware provided to the root folder
    Router should reboot automatically.
    Login, force signature updates (DO NOT UPDATE FIRMWARE IF PROMPTED)
    Reboot the router
    Confirm signatures are updated to new (will NOT match the article dates!)
    Save another copy of the config (cant be too safe)
    Go to running firmware, use cloud update (or local copy of most recent firmware; NOT THE DATE FIRMWARE)
    Router will restart
    Login, verify all your settings.
    Now you have a working device again.

    One thing NOT mentioned in the support post is that VPN does NOT work with the date signature firmware provided! Took a few hours to diagnose that and was finally confirmed by support a day later, and there is no fix except to use the official release firmware.

    Luckily we stagger all of the auto-updates across our deployments and only had a few units that got the update. If we had every unit that had gotten the update it would have been an absolute disaster, and it was already!

    This has now happened two times in about a year with the USG FLEX, dev team really needs to test better.

  • ThomasTakt
    ThomasTakt Posts: 2  Freshman Member
    Network Detective-New Adventure Badge First Comment First Anniversary

    I checked in on a USG Flex 200 I have for testing, and noticed that I it had this issue. I tried to follow the instructions baut failed on the Download. The Firmware Download links lands on a 404 File Not Found-page.

    How do I get hold on an up to date firmware image?

  • Zyxel_Melen
    Zyxel_Melen Posts: 3,176  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate

    Hi @ThomasTakt

    The link has been updated, please try to download again.

    Zyxel Melen