USG Flex H series - Remote VPN no longer works since v1.36
Freshman Member
I have upgraded a flex200H to 1.36 and now remote VPN via windows client no longer works as intended. It seems to be a routing issue as the VPN will connect and i can access and ping the USG but no local resources. Split tunneling also does not work so I have a VPN that can only access the USG and nothing else.
There have been changes to the routing in the firmware update mainly with how policy based VPN routes are set, I am thinking along the lines of the remote VPN needs an option for the next hop much like on the old flex and USG series.
has anyone else run into this problem if so any workarounds while I wait for Zyxel support to assist?
Accepted Solution
-
Thanks Boss, alternatively not having a default outbound rule seems to fix the routing such as your link.
0
All Replies
-
Hi @Amcomp,
I understand you're encountering an issue with remote VPN access after upgrading your USG FLEX 200H to firmware v1.36, specifically that while the VPN connects, you can only access and ping the USG itself, and local resources are unreachable. This indicates a routing problem, and split tunneling also isn't functioning as expected.
Based on the changes in routing for policy-based VPNs in the USG FLEX H series, particularly with firmware updates, here are some steps and considerations to help resolve this:
Initial Solution:
Policy Route Configuration for VPN Tunnels: For policy-based VPNs, the USG FLEX H series requires defining policy routes with VPN tunnel interfaces as the next hop. Ensure these are correctly configured for your remote VPN clients.
- Navigate to
Network>Routing>Policy Route. - Add a new policy route and select the VPN Interface (VTI) as the next hop interface.
- If you're using a conventional subnet for your VTI, ensure it's not a link-local address (like 169.254.X.X), as these can cause routing issues.
- Navigate to
Policy Control Rules: In firmware v1.36, additional policy control rules are needed to allow traffic through the VPN tunnel.
- Go to
Security Policy>Policy Control. - Add rules to allow the VPN source/destination subnets. This is crucial because encrypted traffic might otherwise be blocked by the default deny rule.
- Go to
Split Tunneling Configuration:
- For IPSec VPN, when setting up the remote access VPN, ensure "Split Tunnel" is selected and the allowed local network resources are correctly specified.
- If you're using the Zyxel VPN Client (TGB Client), when configuring RemoteAccess, ensure Split Tunnel is picked and the accessible networks are specified.
- If using OpenVPN, and if you are using full tunnel mode and require split tunnel, you may need to modify the
.ovpnfile by removing the "redirect-gateway" directive and adding specific routes for your desired split tunnel destination IP ranges. - For Windows native VPN clients, you can modify the VPN configuration file to enable multiple split tunnels by setting
SplitTunneling=$Trueand adding multiple destination subnets.
VPN Zone Security: Ensure your VPN tunnel is correctly assigned to its respective security zone. If a tunnel is not correctly assigned to a zone, traffic will not be allowed.
Information Collection Guide:
To further assist you, please provide the following details:
- Firmware Version: While you mentioned v1.36, please confirm the exact firmware version (e.g., v1.36(ABFH.0)).
- Network Topology: A simple diagram or description of your network setup, including where the USG FLEX 200H is located and the subnet of your local resources.
Screenshots:
- Your current Remote Access VPN configuration (IPSec VPN settings).
- Screenshots of your
Policy Routeentries, especially those related to the VPN. - Screenshots of your
Security Policy>Policy Controlrules. - The routing table from a connected VPN client (
route printcommand on Windows).
VPN Client Details: What specific Windows VPN client are you using (e.g., Zyxel SecuExtender, native Windows IKEv2 client, OpenVPN client)?
- Zyxel Support Access (Nebula): If your USG FLEX 200H is managed by Nebula, please enable Zyxel Support Access.
- Navigate to
Help>Support Requestin the Nebula console. - Please provide your Organization and Site name. This will allow the Zyxel support team to directly view your cloud environment configuration, significantly shortening troubleshooting time.
- Navigate to
This AI response aims to provide initial troubleshooting steps and identify information needed for further diagnosis. Feel free to share additional details based on the suggestions above — this will help community members offer more targeted assistance.
If you have feedback or idea about this AI assistant, share them in Community Feedback.0 -
-
Hi @Amcomp
- Is your issue remote VPN IPSec remote VPN?
- Could you download the script again to remove the old profile and install again?
I tested in my lab with the script from V1.36, I can access the internal switch via remote access VPN (full tunnel).
Zyxel Melen0 -
Thanks Boss, alternatively not having a default outbound rule seems to fix the routing such as your link.
0
Categories
- All Categories
- 442 Beta Program
- 2.9K Nebula
- 216 Nebula Ideas
- 127 Nebula Status and Incidents
- 6.4K Security
- 570 USG FLEX H Series
- 342 Security Ideas
- 1.7K Switch
- 84 Switch Ideas
- 1.4K Wireless
- 52 Wireless Ideas
- 6.9K Consumer Product
- 295 Service & License
- 471 News and Release
- 90 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 4.7K FAQ
- 34 Documents
- 87 About Community
- 102 Security Highlight
Zyxel Community Virtual Assistant
Guru Member