[Firewall Configuration Converter v6.2] flex50w -> flex50h convert error
Master Member
i try convert flex50w to flex50h config on new Firewall Configuration Converter.
the ipsec and PR don't migrate in new config. they all empty.
in log all good
[INFO] line 1025 [success] ikev2 policy vpn_dis_test
[INFO] line 1026 [success] activate
[INFO] line 1027 [success] local-ip ip 0.0.0.0
[INFO] line 1028 [success] peer-ip 10.0.0.55 192.168.55.100
[INFO] line 1029 [success] authentication pre-share
[INFO] line 1030 [success] local-id type ip 172.21.153.100
[INFO] line 1031 [success] peer-id type any
[INFO] line 1032 [success] fall-back-check-interval 300
[INFO] line 1033 [success] lifetime 86400
[INFO] line 1034 [success] group1
[INFO] line 1035 [success] transform-set des-md5
[INFO] line 1036 [success] dpd-interval 30
[INFO] line 1037 [success] encrypted-keystring $random_secure_string
in november 2025, i already convert same config, and all was good.
All Replies
-
Hi @alexey
Please share me the configuration file that you used this time and the converted file, so we check this issue.
I have sent you the message for the files.
Zyxel Melen0 -
Update:
This issue is because:
- USG FLEX H doesn't support DH1 group.
- Pre-share key length.
To resolve this, please change on the source device as a workaround:
- DH1 group to DH2.
- shorten the pre-share key to 64 characters.
We will fix the converter issue in the future.
Zyxel Melen0
Categories
- All Categories
- 442 Beta Program
- 3.1K Nebula
- 234 Nebula Ideas
- 6.7K Security
- 706 USG FLEX H Series
- 369 Security Ideas
- 1.8K Switch
- 87 Switch Ideas
- 1.4K Wireless
- 56 Wireless Ideas
- 7.1K Consumer Product
- 313 Service & License
- 512 News and Release
- 99 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 5.2K FAQ
- 34 Documents
- 89 About Community
- 116 Security Highlight
Zyxel Employee