SSL VPN 2FA problem

Options
Michał
Michał Posts: 5 image  Freshman Member
First Comment Fourth Anniversary

Hi,

I have configured (step by step) 2FA on my SSL VPN with instruction (USG Flex500):

https://support.zyxel.eu/hc/en-us/articles/360009877491-Two-Factor-Authentication-per-Mail-on-Zywall-USG

Everything looks fine, I receive mail with authorization link but when I click on it nothing happen- request timed out as you can see in attach. Any ideas why it happen? no matter if firewall is on or off.

Thanks in advance,

MR

2FA.png
2FA.png 23.1K

All Replies

  • PeterUK
    PeterUK Posts: 4,608 image  Guru Member
    250 Answers 2500 Comments Friend Collector Eighth Anniversary
    Options

    Are you clicking on the receive mail with authorization link by other device then the device connecting by VPN?

  • Michał
    Michał Posts: 5 image  Freshman Member
    First Comment Fourth Anniversary
    Options

    Not, on the same machine, for a test I tried on phone and result is the same.

    All tested devices have the same problem also from different locations/countries

  • Zyxel_Judy
    Zyxel_Judy Posts: 2,626 image  Zyxel Employee
    Zyxel Certified Network Engineer Level 2 - Nebula Zyxel Certified Network Engineer Level 2 - Switch Zyxel Certified Network Engineer Level 2 - Security Zyxel Certified Network Engineer Level 1 - Nebula
    Options

    Hi @Michał ,

    When configuring 2FA via email link on the USG FLEX 500, a request timeout typically occurs because the firewall is blocking the traffic on the specific authentication port (e.g.,8008 as default) or because of routing restrictions before the 2FA is fully authorized.

    Please check the following:

    1. Security Policy – Go to Configuration > Security Policy > Policy Control and confirm the WAN-to-Device rule allows the 2FA port (default 8008). If it's missing, add a service object for port 8008 and allow it in that rule.
    2. Double NAT – If the Flex500's WAN port is connected behind another router/modem, that device also needs a port-forward rule for port 8008 to the Flex500's WAN IP.
    3. Authorize Link URL – Go to Configuration > Object > Auth. Method > Two-factor Authentication > VPN Access and confirm the "Authorize Link URL Address" uses your correct public WAN IP (or FQDN) — not a LAN IP.

    Zyxel_Judy

  • Michał
    Michał Posts: 5 image  Freshman Member
    First Comment Fourth Anniversary
    Options

    Hi Judy,

    port from point 1 was missing, I added my custom port and now everything works.

    Thanks for your help.

    MR