OAuth2 do works on FLEX H series?

Fabio_Dangelo
Fabio_Dangelo Posts: 21  Freshman Member
First Comment Friend Collector First Anniversary
edited August 26 in USG FLEX H Series

hello everyone

I have sold some USG Flex H (200 and 500) and I'm unable to configure OAuth2.0.

Just one of them works.

Everything seems to look fine (valid token acquired) but when the firewall try to send an e-mail it gets "msmtp: authentication failed (method XOAUTH2)".

please help! 😥

All Replies

  • Zyxel_Tina
    Zyxel_Tina Posts: 222  Master Member
    Zyxel Certified Network Administrator - Security Zyxel Certified Network Administrator - Switch 50 Answers First Comment

    Hi @Fabio_Dangelo,

    To help us investigate further, could you please provide the configuration files of the USG FLEX 200H & 500H via private message?

    • Navigate to Maintenance > Firmware/File Manager > Configuration File to download the startup-config file.
    image.png

    We will help check if this is due to a configuration error.

    Zyxel Tina

  • Fabio_Dangelo
    Fabio_Dangelo Posts: 21  Freshman Member
    First Comment Friend Collector First Anniversary

    done

    waiting for your reply.

    thank you Tina

  • Fabio_Dangelo
    Fabio_Dangelo Posts: 21  Freshman Member
    First Comment Friend Collector First Anniversary

    hello Tina

    any idea?

  • Zyxel_Tina
    Zyxel_Tina Posts: 222  Master Member
    Zyxel Certified Network Administrator - Security Zyxel Certified Network Administrator - Switch 50 Answers First Comment

    Hi @Fabio_Dangelo,

    Thank you very much for your patience. We are still investigating the issue. We appreciate your understanding and will keep you updated as soon as we have any news.

    Zyxel Tina

  • Zyxel_Tina
    Zyxel_Tina Posts: 222  Master Member
    Zyxel Certified Network Administrator - Security Zyxel Certified Network Administrator - Switch 50 Answers First Comment

    Hi @Fabio_Dangelo,

    Thank you for providing the information.

    Upon reviewing your case, since the token status shows as Valid, it means the firewall was able to obtain the token correctly, and the configuration on the firewall device should be fine.

    To further confirm, could you please try clicking the "Refresh Token Status" button and then check the token status again?

    If the refreshed status still shows as Valid but sending email continues to fail, this indicates the issue is likely related to the server-side configuration.

    In that case, we kindly recommend reviewing the Azure settings once again by following our FAQ, or re-configuring it to ensure all required permissions are correctly applied.

    Please let us know the results after following the above instructions.

    Zyxel Tina

  • Fabio_Dangelo
    Fabio_Dangelo Posts: 21  Freshman Member
    First Comment Friend Collector First Anniversary

    I did it many times from scratch with the same result. It doesn't works.

    I have many customers with H series firewalls and different tenants. Just one do works, the others don't.

    What I have to check on Azure?

    I'm the only one with this issue?

  • Zyxel_Tina
    Zyxel_Tina Posts: 222  Master Member
    Zyxel Certified Network Administrator - Security Zyxel Certified Network Administrator - Switch 50 Answers First Comment

    Hi @Fabio_Dangelo,

    Sorry for the late reply!

    To assist you further, could you please

    • Help us enable Zyxel Support Access on your Nebula and provide us with the Org & Site name via private message so that we can check the configuration directly?
    • Confirm that if the Azure registration settings match the steps in our FAQ guide?

    Regarding your question “Am I the only one with this issue?” — at the moment, you are the only customer who has reported this behavior.

    Zyxel Tina

  • Fabio_Dangelo
    Fabio_Dangelo Posts: 21  Freshman Member
    First Comment Friend Collector First Anniversary

    Hello Tina

    I have many H series firewall and different tenants but just one do works.

    Azure registration match your guide.

    I don't use nebula to configure my firewalls.

    Can I configure remote access for you instead of nebula access?

  • Zyxel_Tina
    Zyxel_Tina Posts: 222  Master Member
    Zyxel Certified Network Administrator - Security Zyxel Certified Network Administrator - Switch 50 Answers First Comment

    Hi @Fabio_Dangelo

    Yes. To enable our team to conduct a thorough investigation, please follow these steps to configure your device to allow access from Zyxel HQ IP addresses:\

    118.163.48.105

    61.222.75.14

    image.png

    image.png

    You can refer to the below link to see how to configure it:

    Then providing the device access URL or IP address, login account with admin privilege, login password to us. I will send you a private message for these information.

    Zyxel Tina