Firmware 1.39 - secondary WAN IP
Ally Member
Did something change with firmware 1.39 when having a secondary WAN IP? Now it seems that all outbound trafic is using the secondary WAN IP and not the primary WAN. IP on the default TRUNK. Is that normal behavior?
Policy route is not an option.
I have one VPN connection that requires the secondary WAN IP.
All Replies
-
There is a bug in the release with TRUNK but that for User-Defined Trunk but your issue is your using default TRUNK which mean all external are active and with Policy route the LAN with use either by WRR.
however I think the bug for User-Defined Trunk is that it ignores Policy route on failed WAN where you only want traffic going out the given WAN even if failed.
so make a User-Defined Trunk with your two WAN and set one to active and on passive and set it by User-Defined Trunk.
But really you need to use Policy route for more control it should not impact VPN connection
0 -
@DanniKool We have the same issue here (500H). With 1.39 firmware If you set "outgoing-interface" in a policy route and you have configured additional IPs on the wan interface, the device uses the last additional IP configured on the wan interface
We have opened a ticket to local support.
0 -
I did a reconfiguration on all site-to-site VPN's from policy-route to policy-based. Added a Policy route to LAN and all VLAN's with next-hop TRUNK outgoing address translation. Re-added the secondary WAN IP under ge1. Now that single site-to-site VPN connection that needed the secondary IP for outgoing is working again and all outgoing trafic on our LAN is using the primary WAN IP….
0 -
Hi @DanniKool
May you share your VPN configuration (Network > My Address)? If your configuration is "Interface ge*(WAN)", the connecting IP address might not your primary address. This is not because of firmware but an OS layer behavior. The order of the interface IP address will not same as you set when every time boot up the firewall.
Please select "Domain Name/IP" option and fix your primary IP address.
Zyxel Melen0 -
@Zyxel_Melen I was already using the Domain Name / IP field with the secondary WAN IP as My Address. That's not the issue as it was working perfectly on both 1.38 and 1.39.
The issue is that with a secondary WAN IP added to ge1, all outgoing trafic on LAN (not configured with Policy route/next hop>trunk/SNAT) are using the secondary WAN IP and not the Primary static WAN IP address on firmware 1.39.
0 -
Hi @DanniKool
Thanks for your update. I have replicated this issue, and we are investigating on it. I will update once I get further information.
Zyxel Melen0 -
Hi @DanniKool
This issue has been addressed and will be fixed in future firmware release.
Zyxel Melen1 -
Hi,
I would like to report a serious WAN trunk issue on the USG FLEX 100H, which appeared after upgrading to firmware 1.39.
My WAN trunk configuration is very simple:
- WAN1: Active
- WAN2: Passive
Before firmware 1.39, this configuration worked perfectly: traffic used WAN1, while WAN2 was used only for failover.
Since firmware 1.39, the behaviour has changed. Even when WAN1 is fully operational, the USG FLEX 100H sends some connections through WAN1 and others through WAN2, despite WAN2 being configured as Passive. The interface selection appears unpredictable.
This has caused a considerable waste of time troubleshooting routing, NAT, policy routes and other configuration settings before identifying the trunk as the source of the problem.
At the moment, the only reliable workaround I have found is to remove the WAN trunk completely and route directly through the WAN interface. This restores predictable routing, but obviously means losing automatic WAN failover.
Considering the cost of the USG FLEX 100H, this is very disappointing. I would expect a basic feature such as an Active/Passive WAN trunk to work reliably, particularly since exactly the same configuration worked correctly before firmware 1.39.
For now, I am forced to operate without WAN failover until Zyxel releases a firmware fix for this issue.
I hope this regression can be identified and resolved as soon as possible.
0 -
0
-
I also having same issue with 700H on V1.39(ABZI.0). Using WRR on (WAN3 and WAN4) Trunk. Almost 99% of traffic is using WAN4.
0
Categories
- All Categories
- 442 Beta Program
- 3.1K Nebula
- 237 Nebula Ideas
- 6.8K Security
- 740 USG FLEX H Series
- 376 Security Ideas
- 1.8K Switch
- 87 Switch Ideas
- 1.5K Wireless
- 58 Wireless Ideas
- 7.2K Consumer Product
- 319 Service & License
- 512 News and Release
- 99 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 5.3K FAQ
- 34 Documents
- 91 About Community
- 119 Security Highlight
Guru Member
Zyxel Employee

Freshman Member