Remote Access VPN and Site-to-site VPN broke with firmware 5.43 on ATP200
Customer 1:
Remote Access VPN, Nebula configured with Nebula cloud authentication server and 2FA enabled does not work anymore with SecuExtender VPN client.
VPN client console report: 3 attempts with no response.
It was last working friday july 31.
Configuration status in NCC report: Not up to date - tried rebooting ATP200 several times.
Customer 2:
Site-to-site VPN broke with firmware 5.43 - it connects to a USG Flex 700H.
Tried recreating the VPN on both ends without success.
Configuration status in NCC report: Not up to date - tried rebooting ATP200 several times.
All Replies
-
Hi @DanniKool
Could you help to enable Zyxel support access and share the organisation's name with us to clarify?
Zyxel Melen0 -
Just send you a PM
0 -
Just a curiosity: firmware level on 700H? I have a similar enviroment with multiple Flex and ATP and on the main site a 200HP, but with firmware 1.38. Firmware 1.39 look too crude to be used in production at this time…
0 -
Sandro_ACP: Firmware level on 700H is 1.39
Zyxel_Melen: Sorry, customer 2 is using a USG Flex 200, not ATP2000 -
DanniKool: I wait a 1.39.1 relase before upgrading, I read too many bugs…Just to your knowledge I have a client with 2 100H (firmware 1.38), I (and Zyxel support…) was unable to form a site-to-site IPSEC (SSL VPN works like a charm…), I replaced temporary one of the two 100H with a Flex100, site-to-site is up since then…
Zyxel_Melen: when a 1.39.1 relase to fix all the new bugs/instability in the 1.39?
0 -
I upgraded my FLEX 200 to V5.43 with some site-to-site tunnels for USG60W and VPN300 all fine here
0 -
Update:
Customer 1: Did a manual ftp firmware update of firmware bank1 (standby) to 5.43 and after a reboot status in NCC shows up to date. Remote Access VPN is working again! Funny as the issue suddenly started on firmware 5.42 sometime during the weekend and updating to firmware 5.43 yesterday didn't fixed it.
I will do the same on Customer 2 (USG Flex 200) later tonight…..
0 -
Update:
Customer 2: Tried doing a ftp firmware update of standby firmware - it did a timeout, twice. Rebooted the device. Still timeout on ftp firmware upload.
But after the reboot, NCC now show up to date in status and the site-to-site VPN tunnel has build successfully. That's weird, because i did a device reboot 2 times yesterday after the firmware update to 5.43…..
0 -
Hi @DanniKool
Thank you so much for sharing all the updates and details along the way! Just to double confirm — it sounds like both Customer 1's Remote Access VPN and Customer 2's Site-to-site VPN are now up and working fine, is that correct?
If either issue happens to come back or you notice anything unusual again, please don't hesitate to share with us.
Hi @Sandro_ACP
Thanks for sharing your experience and insights! If you get the chance to try out the current latest firmware version (1.39) down the line and run into any issues, please create a new post with the details — we'd be glad to take a closer look and assist from there.
Zyxel Tina
0 -
@Zyxel_Tina
Correct, everything is now working correctly0
Categories
- All Categories
- 442 Beta Program
- 3.1K Nebula
- 234 Nebula Ideas
- 6.7K Security
- 706 USG FLEX H Series
- 369 Security Ideas
- 1.8K Switch
- 87 Switch Ideas
- 1.4K Wireless
- 56 Wireless Ideas
- 7.1K Consumer Product
- 313 Service & License
- 512 News and Release
- 99 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 5.2K FAQ
- 34 Documents
- 89 About Community
- 116 Security Highlight
Ally Member
Zyxel Employee
Freshman Member
Guru Member