Remote Access VPN and Site-to-site VPN broke with firmware 5.43 on ATP200

Options
DanniKool
DanniKool Posts: 56 image  Ally Member
First Answer First Comment Friend Collector Eighth Anniversary

Customer 1:
Remote Access VPN, Nebula configured with Nebula cloud authentication server and 2FA enabled does not work anymore with SecuExtender VPN client.
VPN client console report: 3 attempts with no response.
It was last working friday july 31.
Configuration status in NCC report: Not up to date - tried rebooting ATP200 several times.

Customer 2:
Site-to-site VPN broke with firmware 5.43 - it connects to a USG Flex 700H.
Tried recreating the VPN on both ends without success.
Configuration status in NCC report: Not up to date - tried rebooting ATP200 several times.

All Replies

  • Zyxel_Melen
    Zyxel_Melen Posts: 4,992 image  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate
    Options

    Hi @DanniKool

    Could you help to enable Zyxel support access and share the organisation's name with us to clarify?

    Zyxel Melen


  • DanniKool
    DanniKool Posts: 56 image  Ally Member
    First Answer First Comment Friend Collector Eighth Anniversary
    Options

    Just send you a PM

  • Sandro_ACP
    Sandro_ACP Posts: 13 image  Freshman Member
    First Comment Friend Collector Fourth Anniversary
    Options

    Just a curiosity: firmware level on 700H? I have a similar enviroment with multiple Flex and ATP and on the main site a 200HP, but with firmware 1.38. Firmware 1.39 look too crude to be used in production at this time…

  • DanniKool
    DanniKool Posts: 56 image  Ally Member
    First Answer First Comment Friend Collector Eighth Anniversary
    Options

    Sandro_ACP: Firmware level on 700H is 1.39

    Zyxel_Melen: Sorry, customer 2 is using a USG Flex 200, not ATP200

  • Sandro_ACP
    Sandro_ACP Posts: 13 image  Freshman Member
    First Comment Friend Collector Fourth Anniversary
    edited August 4
    Options

    DanniKool: I wait a 1.39.1 relase before upgrading, I read too many bugs…Just to your knowledge I have a client with 2 100H (firmware 1.38), I (and Zyxel support…) was unable to form a site-to-site IPSEC (SSL VPN works like a charm…), I replaced temporary one of the two 100H with a Flex100, site-to-site is up since then…

    Zyxel_Melen: when a 1.39.1 relase to fix all the new bugs/instability in the 1.39?

  • PeterUK
    PeterUK Posts: 4,608 image  Guru Member
    250 Answers 2500 Comments Friend Collector Eighth Anniversary
    edited August 4
    Options

    I upgraded my FLEX 200 to V5.43 with some site-to-site tunnels for USG60W and VPN300 all fine here

  • DanniKool
    DanniKool Posts: 56 image  Ally Member
    First Answer First Comment Friend Collector Eighth Anniversary
    Options

    Update:

    Customer 1: Did a manual ftp firmware update of firmware bank1 (standby) to 5.43 and after a reboot status in NCC shows up to date. Remote Access VPN is working again! Funny as the issue suddenly started on firmware 5.42 sometime during the weekend and updating to firmware 5.43 yesterday didn't fixed it.

    I will do the same on Customer 2 (USG Flex 200) later tonight…..

  • DanniKool
    DanniKool Posts: 56 image  Ally Member
    First Answer First Comment Friend Collector Eighth Anniversary
    Options

    Update:

    Customer 2: Tried doing a ftp firmware update of standby firmware - it did a timeout, twice. Rebooted the device. Still timeout on ftp firmware upload.

    But after the reboot, NCC now show up to date in status and the site-to-site VPN tunnel has build successfully. That's weird, because i did a device reboot 2 times yesterday after the firmware update to 5.43…..

  • Zyxel_Tina
    Zyxel_Tina Posts: 933 image  Zyxel Employee
    Zyxel Certified Network Administrator - Security Zyxel Certified Network Administrator - Switch 100 Answers 500 Comments
    Options

    Hi @DanniKool

    Thank you so much for sharing all the updates and details along the way! Just to double confirm — it sounds like both Customer 1's Remote Access VPN and Customer 2's Site-to-site VPN are now up and working fine, is that correct?

    If either issue happens to come back or you notice anything unusual again, please don't hesitate to share with us.

    Hi @Sandro_ACP

    Thanks for sharing your experience and insights! If you get the chance to try out the current latest firmware version (1.39) down the line and run into any issues, please create a new post with the details — we'd be glad to take a closer look and assist from there.

    Zyxel Tina

  • DanniKool
    DanniKool Posts: 56 image  Ally Member
    First Answer First Comment Friend Collector Eighth Anniversary
    Options

    @Zyxel_Tina

    Correct, everything is now working correctly