FW V1.39 – Issue with SSL-VPN in combination with IPsec
Freshman Member
Since the update to version 1.39, strange issues have arisen with connections to the back-office that route through SSL-VPN followed by IPsec-VTI-VPN.
To clarify the setup:
Site A (USG FLEX 100 H, FW 1.39), Site B (USG FLEX 200 H, FW 1.39), Site C (USG FLEX 200 H, FW 1.38).
All sites are interconnected via IPsec VTI VPN. If a user connects via SSL-VPN to Site A or B and attempts to access a service at the other site (via IPsec), it fails. However, if a user connects via SSL-VPN to Site C and attempts to access a service at Site A or B (via IPsec), it works.
Everything worked perfectly prior to version 1.39. Has something changed that requires me to make adjustments? Or is this a bug?
It appears that the firewall is not forwarding traffic from the IPsec-VTI-VPN back to the SSL VPN.
All Replies
-
Hi @weite ,
Here is some diagnostic direction to help narrow down why the firewalls (Sites A and B) are not forwarding SSL-VPN traffic over the IPsec VTI tunnels:
- Verify Security Policies and Zones: Ensure there are explicit security policies allowing bidirectional traffic between the SSL-VPN zone (or your SSL-VPN client pool) and the VTI/IPsec VPN zone on Sites A and B.
- Check Policy / Static Routing: Verify that policy or static routing rules are correctly in place on Site A and Site B to route the SSL-VPN client subnet over the VTI interface toward the other sites. Conversely, ensure the remote sites have return routes for the SSL-VPN client subnet pointing back through the VTI tunnel.
- Compare VTI Interface States: Confirm that standard LAN-to-LAN traffic across the IPsec VTI tunnels between all sites is still passing successfully, isolating the issue specifically to the transit traffic originating from SSL-VPN clients.
Information Request
To help us investigate this further, could you please provide us with the following details:
- Routing Configuration: How are the routes configured to guide the SSL-VPN IP pool traffic into the IPsec VTI tunnels (e.g., static routes, policy routes)?
- Firewall Rules: Are there specific security policies allowing traffic from the SSL-VPN zone to the VTI/IPsec zone?
Zyxel Melen0 -
We use policy-based routing for the connection between the SSL VPN and the IPsec
Yes, we have specific rules for the SSL- and IPSEV VPN. I can also see in the logs that the requests are being forwarded rather than blocked. Nothing has changed compared to before.
Question. Is a easy rollback to the old 1.38 version possible?
0 -
Hi @weite
If you need the VPN work imminently, please help with these steps:
- Backup all of your firewall's startup-config.conf and share with us. This allows us to replicate this issue in our lab. You may send the config file with me via private message.
- Follow this FAQ to switch running partition: https://community.zyxel.com/en/discussion/18647/how-to-switch-running-partition-in-usg-flex-h-series
Zyxel Melen0 -
So if site A goes back to V1.38 it works? you tested it not because Site C works with V1.38?
0 -
With one location I rollback to FW 1.38 and it works directly.
0 -
Hi @weite
Thanks for your feedback. We are checking on this issue now. I will update once I get further result.
Zyxel Melen0 -
Hi @weite
Our team has addressed this issue, and it will be fixed in the next firmware release.
Zyxel Melen0
Categories
- All Categories
- 442 Beta Program
- 3.1K Nebula
- 237 Nebula Ideas
- 6.8K Security
- 740 USG FLEX H Series
- 376 Security Ideas
- 1.8K Switch
- 87 Switch Ideas
- 1.5K Wireless
- 58 Wireless Ideas
- 7.2K Consumer Product
- 319 Service & License
- 512 News and Release
- 99 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 5.3K FAQ
- 34 Documents
- 91 About Community
- 119 Security Highlight
Zyxel Employee
Guru Member