Lost UDP natting after 1.38 upgrade on Flex 700H

Options
Delta69
Delta69 Posts: 13 image  Freshman Member
First Comment Friend Collector Second Anniversary

Hello,
I have a couple of Flex 700H upgaded from 1.36 to 1.38, with multiple public IP addresses on each of them.
I natted some services managed by appliances connected on the DMZ, among them a SSL VPN working with both TCP and UDP connections on port 443 on one of the public IPs.
Since the upgrade, tunnels using UDP sessions are not working anymore, whereas the TCP ones work fine.
Any idea ?
Thanks.

Accepted Solution

  • Delta69
    Delta69 Posts: 13 image  Freshman Member
    First Comment Friend Collector Second Anniversary
    edited May 18 Answer ✓

    Hello Judy / Peter,

    I can confirm that everything is back to normal after disabling the QUIC protocol.

    Thank you for your help.
    Regards

All Replies

  • PeterUK
    PeterUK Posts: 4,487 image  Guru Member
    250 Answers 2500 Comments Friend Collector Eighth Anniversary
    edited May 14

    Not seeing this problem but I'm on V1.38(ABZI.0)ITS-26WK16-m11228

    setup as
    Client > VPN server Zywall 110 > tunnel FLEX 700H > Server

    The Client can DNS by UDP to server over the tunnel fine with routeing rule to SNAT from FLEX 700H LAN gateway IP

    Its a bit unclear of your setup to go on

  • Delta69
    Delta69 Posts: 13 image  Freshman Member
    First Comment Friend Collector Second Anniversary

    Thanks for your reply,

    On our side we are using firmware V1.38(ABZI.0) | 2026-04-09 08:23:09

    Sorry if I was a bit unclear, the issue is not related to DNS but it's related to SSL VPN tunnels based on UDP that are now failing to establish.

    Regards

  • PeterUK
    PeterUK Posts: 4,487 image  Guru Member
    250 Answers 2500 Comments Friend Collector Eighth Anniversary
    edited May 15

    I don't think FLEX H supports the SSL VPN by openVPN over UDP for the tunnel…

  • Delta69
    Delta69 Posts: 13 image  Freshman Member
    First Comment Friend Collector Second Anniversary

    Well, SSL VPN is done by an appliance on the DMZ. The firewall is just passing the traffic (and it was working perfectly until v1.38 firmware upgrade).

  • PeterUK
    PeterUK Posts: 4,487 image  Guru Member
    250 Answers 2500 Comments Friend Collector Eighth Anniversary

    just to be clear your talking about this setting

    Screenshot 2026-05-15 102038.png
  • Delta69
    Delta69 Posts: 13 image  Freshman Member
    First Comment Friend Collector Second Anniversary

    There shouldn't be any connection with the firewall's OpenVPN module, which isn't being used (and is disabled): the firewall is simply redirecting TCP and UDP network traffic to a third party VPN server in the DMZ.
    Thank you very much for your help.

    Capture d'écran 2026-05-15 113844.png
  • PeterUK
    PeterUK Posts: 4,487 image  Guru Member
    250 Answers 2500 Comments Friend Collector Eighth Anniversary
    edited May 15

    hmm so what happens if you change the SSL VPN port on FLEX H that your not using?

    or is SSL VPN port 10443 and you need 443 what the FLEX H has for UI?

    It might be caused by this


    however the setting is a bit buggy to disable in system > advanced disable Block QUIC Protocol

  • Delta69
    Delta69 Posts: 13 image  Freshman Member
    First Comment Friend Collector Second Anniversary

    Yes, maybe it's the same bug, IMHO it's on the NATing side because the rule is not triggered anymore in the Network Policies… (0 hits since the FW upgrade).
    BTW, we are using port 443 and the embedded SSL VPN server has 10443 configured.

  • Zyxel_Judy
    Zyxel_Judy Posts: 2,467 image  Zyxel Employee
    Zyxel Certified Network Engineer Level 2 - Nebula Zyxel Certified Network Engineer Level 2 - Switch Zyxel Certified Network Engineer Level 2 - Security Zyxel Certified Network Engineer Level 1 - Nebula

    Hi @Delta69 ,

    Could you share with us the SSL VPN tunnels based on UDP worked as expected if you disable Block QUIC Protocol?

    By the way, could you provide the Nebula Organization and site name, and enable Zyxel support access for our checking?

    Zyxel_Judy

  • Delta69
    Delta69 Posts: 13 image  Freshman Member
    First Comment Friend Collector Second Anniversary
    edited May 18 Answer ✓

    Hello Judy / Peter,

    I can confirm that everything is back to normal after disabling the QUIC protocol.

    Thank you for your help.
    Regards