FLEX 100H firewall zone bug

p4_greg
p4_greg Posts: 31  Freshman Member
Network Detective-New Adventure Badge First Comment Friend Collector Third Anniversary

We ran into some odd behavior that appears to be a bug on a FLEX 100H running latest 1.32 firmware.

We have a firewall rule which blocks NetBIOS packets from ANY-to-WAN, and another rule which allows all packets from LAN-to-IPSec. For some reason, the ANY-to-WAN rule is blocking packets that are supposed to be sent over the VPN.

We can work around this issue if we reverse the order of these rules so the IPSec rule is above the ANY-to-WAN rule.

Why is the ANY-to-WAN rule blocking destination IPs which should be in the IPSec zone?

See screenshots below.

any-wan.png lan1-ipsec.png firewall-blocked.png firewall-blocked1.png ipsec-policy.png

All Replies

  • PeterUK
    PeterUK Posts: 3,946  Guru Member
    100 Answers 2500 Comments Friend Collector Seventh Anniversary
  • Zyxel_Melen
    Zyxel_Melen Posts: 3,635  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate

    Hi @p4_greg

    Could you enable the Zyxel support access for this site on Nebula and share an account for us to check this issue? I will send you a private message for the account info.

    I did a local test that my policy rules are same as yours, but didn't see this issue.

    image.png image.png
    Zyxel Melen


  • p4_greg
    p4_greg Posts: 31  Freshman Member
    Network Detective-New Adventure Badge First Comment Friend Collector Third Anniversary

    @Zyxel_Melen Is your test using Policy-based IPSec VPN or Route-based(VTI)?

    We have seen this same issue on 2 different networks/routers using FLEX 100H on both sides of a Policy-based VPN.

    These routers/networks are in production at our client's locations, so if you truly cannot re-create this issue in your lab I will likely have to set up some test units for you to look at.

  • PeterUK
    PeterUK Posts: 3,946  Guru Member
    100 Answers 2500 Comments Friend Collector Seventh Anniversary
    edited June 25

    Can confirm this is still a issue

    Screenshot 2025-06-25 162038.png Screenshot 2025-06-25 162200.png Screenshot 2025-06-25 162247.png

    tested on two different subnets with both being /28

    If I disable the NetBIOS block rule 1 it connects fine then when enabled blocks NetBIOS but its for to WAN2 which is not true as it is going down the VPN not out ge2 WAN2

  • p4_greg
    p4_greg Posts: 31  Freshman Member
    Network Detective-New Adventure Badge First Comment Friend Collector Third Anniversary

    Hi Melen,

    I set up a test environment, confirmed this is still an issue, enabled Zyxel Support Access setting on the organization and created a local firewall user for you to check.

    I messaged you the details as requested.

  • PeterUK
    PeterUK Posts: 3,946  Guru Member
    100 Answers 2500 Comments Friend Collector Seventh Anniversary

    Can also setup test environment by test PC over teamviewer if needed too.

  • PeterUK
    PeterUK Posts: 3,946  Guru Member
    100 Answers 2500 Comments Friend Collector Seventh Anniversary

    This is still a problem in V1.35 firmware

  • P4Colin
    P4Colin Posts: 28  Freshman Member
    First Comment Friend Collector Second Anniversary

    @Zyxel_Melen - Your last PM to my coworker @p4_greg on 7/16 contained a video showing these issues and I believe this was going to be escalated to development. As @PeterUK stated, we also confirmed this behavior is still present in 1.35. Please advise on a status or what else is needed from us.

  • Zyxel_Melen
    Zyxel_Melen Posts: 3,635  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate

    Hi @P4Colin @p4_greg

    Sorry for the delayed reply. We have addressed this issue, the police-based VPN traffic might be misrecognized as to WAN zone traffic and hit the security policy ANY to WAN. I will provide a date code firmware with you for 100H soon.

    Hi @PeterUK

    I will also provide you with the date code firmware for 200H, since the remote VPN issue is similar to this issue.

    Zyxel Melen


  • P4Colin
    P4Colin Posts: 28  Freshman Member
    First Comment Friend Collector Second Anniversary

    Messaged back. We are still in the same situation and this is not resolved.