USG FLEX H V1.35 - IPSec connectivity check

p4_greg
p4_greg Posts: 31  Freshman Member
Network Detective-New Adventure Badge First Comment Friend Collector Third Anniversary

According to the release notes, Connectivity Check for IPSec VPN was implemented in this new firmware.

How can I configure this? I am not seeing it under the IPSec VPN settings.

Best Answers

  • Zyxel_Tina
    Zyxel_Tina Posts: 175  Zyxel Employee
    Zyxel Certified Network Administrator - Security Zyxel Certified Network Administrator - Switch 50 Answers First Comment
    Answer ✓

    Hi @p4_greg and @PeterUK,

    Regarding the Connectivity Check feature for USG FLEX H Series devices, please note that it is not intended for configuration purposes. However, you can locate the “Connectivity Check” menu under VPN Status > IPSec VPN > Site to Site VPN to check the connection to a remote client through the VPN tunnel.

    image.png image.png

    Zyxel Tina

  • Zyxel_Tina
    Zyxel_Tina Posts: 175  Zyxel Employee
    Zyxel Certified Network Administrator - Security Zyxel Certified Network Administrator - Switch 50 Answers First Comment
    edited August 6 Answer ✓

    Hi @p4_greg,

    Sorry for the late reply!

    After double confirmation, the USG FLEX H series does not support direct configuration of connectivity check like the USG FLEX (ZLD) does.

    To achieve a similar function, the current workaround is to use a route-based VPN with a VTI interface to perform peer probing. However, if you use a policy-based VPN, connectivity check configuration is not available.

    For how to create VTI, please refer to this FAQ. After creating the interface, navigate to Network > Interface > Advanced Settings > VTI and select Edit to configure its connectivity check.

    image.png image.png

    Zyxel Tina

All Replies

  • PeterUK
    PeterUK Posts: 3,983  Guru Member
    100 Answers 2500 Comments Friend Collector Seventh Anniversary

    Yes I see this too can't find it.

  • Zyxel_Tina
    Zyxel_Tina Posts: 175  Zyxel Employee
    Zyxel Certified Network Administrator - Security Zyxel Certified Network Administrator - Switch 50 Answers First Comment
    Answer ✓

    Hi @p4_greg and @PeterUK,

    Regarding the Connectivity Check feature for USG FLEX H Series devices, please note that it is not intended for configuration purposes. However, you can locate the “Connectivity Check” menu under VPN Status > IPSec VPN > Site to Site VPN to check the connection to a remote client through the VPN tunnel.

    image.png image.png

    Zyxel Tina

  • p4_greg
    p4_greg Posts: 31  Freshman Member
    Network Detective-New Adventure Badge First Comment Friend Collector Third Anniversary

    That explains why I could not find it….I assumed the release notes were referring to the Connectivity Check which was previously available in the VPN Connection settings on the non-H/ZLD-based firewalls.

    It has been helpful in the past when the connection gets 'stuck' and traffic does not flow over the VPN, which sometimes happens after one side of the VPN connection experiences internet issues. The connectivity check feature available on previous would automatically detect this and reset the VPN connection, which usually restored connectivity.

    Are there any plans to add this feature back?

    Screenshot from VPN Connection settings on an old VPN100:

    image.png
  • Zyxel_Tina
    Zyxel_Tina Posts: 175  Zyxel Employee
    Zyxel Certified Network Administrator - Security Zyxel Certified Network Administrator - Switch 50 Answers First Comment
    edited August 6 Answer ✓

    Hi @p4_greg,

    Sorry for the late reply!

    After double confirmation, the USG FLEX H series does not support direct configuration of connectivity check like the USG FLEX (ZLD) does.

    To achieve a similar function, the current workaround is to use a route-based VPN with a VTI interface to perform peer probing. However, if you use a policy-based VPN, connectivity check configuration is not available.

    For how to create VTI, please refer to this FAQ. After creating the interface, navigate to Network > Interface > Advanced Settings > VTI and select Edit to configure its connectivity check.

    image.png image.png

    Zyxel Tina