[USG Flex H] - Tailscale VPN - every reboot Default SNAT not working

Options
Maverick87
Maverick87 Posts: 138 image  Ally Member
First Answer First Comment Friend Collector
edited April 20 in USG FLEX H Series

Hello everyone,
every time that I reboot of my USG Flex 200HP, the Tailscale exit node not working anymore.

I've enabled the exit node from the Tailscale configuration, and enabled the Default SNAT rule. All works fine, until I reboot the firewall; by default this rule is enabled (reload the last setting) but seems not working anymore.

The first time that the firewall is rebooted, the Default SNAT is enabled (reload last configuration) and If I try to surfing the web, no pages are loaded neighter if I try to PING 8.8.8.8 no PING succedeed; if I disable the Default SNAT option —> save the config —> re-enable the option —> save the config, in this case all works fine, the PING eighter the surfing.

Thank you

All Replies

  • Zyxel_Judy
    Zyxel_Judy Posts: 2,388 image  Zyxel Employee
    Zyxel Certified Network Engineer Level 2 - Nebula Zyxel Certified Network Engineer Level 2 - Switch Zyxel Certified Network Engineer Level 2 - Security Zyxel Certified Network Engineer Level 1 - Nebula

    Hi @Maverick87 ,

    We're looking into this and will follow up with an update shortly.

    Zyxel_Judy

  • Maverick87
    Maverick87 Posts: 138 image  Ally Member
    First Answer First Comment Friend Collector

    Hi @Zyxel_Judy,

    Thank you, please prioritize if possible, as for now, is impossible to use the service.

    Thank you

  • Zyxel_Judy
    Zyxel_Judy Posts: 2,388 image  Zyxel Employee
    Zyxel Certified Network Engineer Level 2 - Nebula Zyxel Certified Network Engineer Level 2 - Switch Zyxel Certified Network Engineer Level 2 - Security Zyxel Certified Network Engineer Level 1 - Nebula

    Hi @Maverick87 ,

    We have a fix ready for this issue, which will be included in the next official firmware release planned for July, as well as the weekly firmware update scheduled for next Thursday.

    In the meantime, please continue using the workaround of disabling and re-enabling DNAT as you mentioned.

    Zyxel_Judy