2FA Remote Access VPN (Flex 200H V1.32(ABWV.0) )

Options
Danee
Danee Posts: 8  Freshman Member
First Comment Friend Collector
edited June 3 in Security

Hi!

My client has a Flex 200H V1.32(ABWV.0) firewall and we - the network administrators - are using/enabling IPSec VPN for the networks users to access the network remotely.
(Also using SSL VPN with OpenVPN.)
From the beginnings we used "native clients built into Windows" in win10/11 for "home office" users.
They are downloadable (from the firewall GUI) configurations for windows and macOS. It needs user name and password after the VPN is installed as the 1st authentication.
Without the 2nd authentication nor internet, nor the client's intranet worked for anyone who did the 1st authentication, except for an intranet site (firewall LAN address plus port number: 192.168.X.X:XXXX) was available for the 2nd authentication.
After the 2nd authentication both internet and full intranet became available.

But since yesterday (2025.06.02.) the 1st authentication enables both the internet and the intranet without the 2nd authentication.
How is this possible?

2fa_not_working_1.PNG 2fa_not_working_2.PNG

All Replies

  • PeterUK
    PeterUK Posts: 3,893  Guru Member
    100 Answers 2500 Comments Friend Collector Seventh Anniversary
    edited June 3

    It does look like it should not be possible

    if you go to VPN status > IPSec VPN > remote access VPN can you disconnect everyone? then test again

  • Danee
    Danee Posts: 8  Freshman Member
    First Comment Friend Collector
    edited June 4

    I can/could disconnect anyone from there, and they can/could reconnect the same - non 2FA - way
    with access to both inter- and intranet.

  • Zyxel_Melen
    Zyxel_Melen Posts: 3,529  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate

    Hi @Danee,

    I can replicate this issue in my lab. We are investigating this issue, and I will update once I get further information.

    Zyxel Melen


  • Zyxel_Melen
    Zyxel_Melen Posts: 3,529  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate

    Hi @Danee,

    After checking, the 2FA authentication for remote access VPN requires to enable security policy. May I know if you disable the security policy?

    image.png

    If not, could you share your configuration so we can have further checking for this issue?

    Zyxel Melen