USG20W-VPN Update FW 5.39 to 5.43 Setup 2FA Day Before Stopped Working

Options
SierraTech
SierraTech image  Ally Member
First Comment Friend Collector Eighth Anniversary

Yesterday updated a USG20W-VPN Update FW 5.39(ABAR.1) to 5.43(ABAR.0) different Partition.

I successfully setup 2FA with Microsoft Authenticator APP, but when I went to log in a day later it wants me to setup 2FA again. The setup fails with the following error message:

Screenshot 2026-08-14 151407.png

I can skip the setup, but apparently it fails every time I try to add in Microsoft Authenticator which works fine on two other ZYXEL USG FLEX100Ax units.

Any Suggestions how I can get this resolved?

I tried switching Partitions and then Back different browser, same issue!

All Replies

  • Zyxel_Luna
    Zyxel_Luna image  Zyxel Employee
    5 Answers First Comment Friend Collector
    edited August 18
    Options

    Hi @SierraTech ,

    One possible cause of this error message is that while Google Authenticator is linked to the login account, "Enable Two-Factor Authentication for Admin Access" is not enabled in Configuration > Object > User/Group. Consequently, the login "Security Best Practices Wizard" still to guide to Set up Google Authenticator, and submitting the code via "Verify Codes" triggers the error message.

    Please follow these steps on V5.43(ABAR.0) partition:

    Step 1. Skip the initial setup wizard upon login.

    image.png

    Step 2. Go to Configuration > Object > User/Group in the web management interface and edit your user account.

    image.png

    Step 3. Under the [Two-Factor Authentication] section, check [Enable Two-Factor Authentication for Admin Access] to display the configuration options.

    image.png

    Step 4. Verify that Google Authenticator is indeed linked. Make sure "[Enable two-factor authentication with admin access]" remains selected, and then click "[OK]" in the bottom right corner to save the settings.

    Note. Please remember to record the backup code below first.

    image.png

    Step 5. To ensure Google Authenticator is enabled upon login, please make sure that [Enable] is checked under Configuration > Object > Auth.Method > “Two-Factor Authentication” > “Admin Access”

    image.png

    Also, make sure the system time on the USG20W-VPN is properly synchronized in Configuration > System > Date/Time.
    *TOTP is highly sensitive to time discrepancies. Any clock drift could cause 2FA generation and validation failure.

    Hope this helps! Please let us know if you have any questions. Have a wonderful day!