FLEX H: SSL VPN and SNAT after config update

Options
fedebros
fedebros Posts: 19 image  Freshman Member
First Comment Friend Collector

Hello, I am writing this post to report an issue on a USG FLEX 500H.

I had configured an SSL VPN by setting the client network to a subnet within the LAN. Unlike ATP/USG devices running ZLD, this configuration does not work on uOS.

I then modified the subnet by creating a new one and applied the changes. At that point, the VPN started working, but only for internal routing. I was able to ping all hosts on the LAN, but I could not access the Internet, even though the configuration was set to "Internet and Local Networks (Full Tunnel)" with "Auto SNAT" enabled.

I then disabled Auto SNAT, applied the changes, re-enabled it, and applied the changes again. After that, Internet access through the VPN started working as expected.

Could you please verify whether it would be possible to address this issue by, for example, restarting the SSL VPN service whenever configuration changes are applied, or by implementing any other mechanism that would automatically resolve the Full Tunnel issue?

All Replies

  • Zyxel_Judy
    Zyxel_Judy Posts: 2,626 image  Zyxel Employee
    Zyxel Certified Network Engineer Level 2 - Nebula Zyxel Certified Network Engineer Level 2 - Switch Zyxel Certified Network Engineer Level 2 - Security Zyxel Certified Network Engineer Level 1 - Nebula
    Options

    Hi @fedebros ,

    Based on your description, this appears to be a system execution issue where the routing and SNAT rules did not apply correctly after the initial configuration change, only taking effect after a manual disable/enable. Because the setup works after toggling Auto SNAT, we assume your configuration itself is correct, but there may be an issue in how the system updates its internal states.

    To help us investigate this behavior and escalate it to our development team, in case you faced the symptom again, please follow these steps:

    • Collect Diagnostic Info & Configuration: Collect the diaginfo file along with your startup configuration. You can refer to this guide on how to gather these files:
      How to collect diaginfo on H-series.
    • Enable Zyxel Support Access: Provide the Nebula organization & site name and enable Zyxel support

    Zyxel_Judy