USG FLEX H Series - V1.39 not stable has some issues

Options
PeterUK
PeterUK Posts: 4,608 image  Guru Member
250 Answers 2500 Comments Friend Collector Eighth Anniversary
edited July 27 in USG FLEX H Series

Not sure if its my config or if it need redoing but its not good.

I think there is one good thing about it which is real DMZ V1 now works like ZLD but the UI is slow give errors like when editing firewall rules

error code 10017

show object address-object fqdn wildcard IP192168500

Screenshot 2026-07-27 202542.png

which IP192168500 is not a fqdn!

remote VPN for users to use the internet now only works if firewall rule is from any to any when you normally do from zone remote_VPN to to zone WAN2

User-Defined Trunk not working correctly with routing rules

like you have

VLAN443 active

WAN2 passive or active

if you have a router rule

incoming LAN

next hop WAN2

if you remove WAN2 connection it goes out VLAN443

if Default Trunk is set then traffic stick to

router rule

incoming LAN

next hop WAN2

and fails if you remove WAN2 connection

And for address-objects for FQDN the IPv4 Cache List takes some time to load but Expire cache by TTL shows on in UI when off in config for a given FQDN

Screenshot 2026-07-28 003101.png Screenshot 2026-07-28 003151.png

All Replies

  • Zyxel_Melen
    Zyxel_Melen Posts: 4,992 image  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate
    Options

    Hi @PeterUK

    Thanks for reporting it. May I know if we can modify the first case, edit security policy "test2", to further check this issue?

    Zyxel Melen


  • PeterUK
    PeterUK Posts: 4,608 image  Guru Member
    250 Answers 2500 Comments Friend Collector Eighth Anniversary
    edited July 28
    Options

    Hi

    yes you can modify the rule "test2" like change to deny  

    My FLEX 200H seems to not have this issue so thinking the FLEX 700H is setup with many FQDN around 600 I think but not in use by policy control

  • PeterUK
    PeterUK Posts: 4,608 image  Guru Member
    250 Answers 2500 Comments Friend Collector Eighth Anniversary
    edited August 1
    Options

    update on the remote VPN problem link to if user is set to a user so it does work if you do a rule from zone remote_VPN to zone WAN2 but user must be any however this only applies to the internet for VPN users where as before you select what users have access to the internet but LAN side can still be locked down by user by VPN.

  • PeterUK
    PeterUK Posts: 4,608 image  Guru Member
    250 Answers 2500 Comments Friend Collector Eighth Anniversary
    Options

    Looking better with new firmware only a small bug to do with Expire cache by TTL shows on in UI when off in config for a given FQDN

  • Asgatlat
    Asgatlat Posts: 134 image  Ally Member
    First Comment Friend Collector Eighth Anniversary
    Options

    My flex200h still say that 1.38 is the latest FW. Is that normal ?

  • PeterUK
    PeterUK Posts: 4,608 image  Guru Member
    250 Answers 2500 Comments Friend Collector Eighth Anniversary
    Options

    Its to do with "Latest" and "Stable" so if you want it you can get it at https://portal.myzyxel.com/

    download other then the issues I was having it runs fine but if you do run into issues you can load the standby firewire.

  • Zyxel_Melen
    Zyxel_Melen Posts: 4,992 image  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate
    Options

    Hi @PeterUK

    The Expire cache by TTL display issue will be fixed in the next official firmware release.

    Zyxel Melen