FW V1.39 – Issue with SSL-VPN in combination with IPsec

Options
weite
weite image  Freshman Member
First Comment Eighth Anniversary

Since the update to version 1.39, strange issues have arisen with connections to the back-office that route through SSL-VPN followed by IPsec-VTI-VPN.

To clarify the setup:

Site A (USG FLEX 100 H, FW 1.39), Site B (USG FLEX 200 H, FW 1.39), Site C (USG FLEX 200 H, FW 1.38).

All sites are interconnected via IPsec VTI VPN. If a user connects via SSL-VPN to Site A or B and attempts to access a service at the other site (via IPsec), it fails. However, if a user connects via SSL-VPN to Site C and attempts to access a service at Site A or B (via IPsec), it works.

Everything worked perfectly prior to version 1.39. Has something changed that requires me to make adjustments? Or is this a bug?

It appears that the firewall is not forwarding traffic from the IPsec-VTI-VPN back to the SSL VPN.

All Replies

  • Zyxel_Melen
    Zyxel_Melen image  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate
    Options

    Hi @weite ,

    Here is some diagnostic direction to help narrow down why the firewalls (Sites A and B) are not forwarding SSL-VPN traffic over the IPsec VTI tunnels:

    1. Verify Security Policies and Zones: Ensure there are explicit security policies allowing bidirectional traffic between the SSL-VPN zone (or your SSL-VPN client pool) and the VTI/IPsec VPN zone on Sites A and B.
    2. Check Policy / Static Routing: Verify that policy or static routing rules are correctly in place on Site A and Site B to route the SSL-VPN client subnet over the VTI interface toward the other sites. Conversely, ensure the remote sites have return routes for the SSL-VPN client subnet pointing back through the VTI tunnel.
    3. Compare VTI Interface States: Confirm that standard LAN-to-LAN traffic across the IPsec VTI tunnels between all sites is still passing successfully, isolating the issue specifically to the transit traffic originating from SSL-VPN clients.

    Information Request

    To help us investigate this further, could you please provide us with the following details:

    1. Routing Configuration: How are the routes configured to guide the SSL-VPN IP pool traffic into the IPsec VTI tunnels (e.g., static routes, policy routes)?
    2. Firewall Rules: Are there specific security policies allowing traffic from the SSL-VPN zone to the VTI/IPsec zone?
    Zyxel Melen


  • weite
    weite image  Freshman Member
    First Comment Eighth Anniversary
    Options

    We use policy-based routing for the connection between the SSL VPN and the IPsec

    Yes, we have specific rules for the SSL- and IPSEV VPN. I can also see in the logs that the requests are being forwarded rather than blocked. Nothing has changed compared to before.

    Question. Is a easy rollback to the old 1.38 version possible?

  • Zyxel_Melen
    Zyxel_Melen image  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate
    Options

    Hi @weite

    If you need the VPN work imminently, please help with these steps:

    1. Backup all of your firewall's startup-config.conf and share with us. This allows us to replicate this issue in our lab. You may send the config file with me via private message.
    2. Follow this FAQ to switch running partition: https://community.zyxel.com/en/discussion/18647/how-to-switch-running-partition-in-usg-flex-h-series
    Zyxel Melen


  • PeterUK
    PeterUK image  Guru Member
    250 Answers 2500 Comments Friend Collector Eighth Anniversary
    Options

    So if site A goes back to V1.38 it works? you tested it not because Site C works with V1.38?

  • weite
    weite image  Freshman Member
    First Comment Eighth Anniversary
    Options

    With one location I rollback to FW 1.38 and it works directly.

  • Zyxel_Melen
    Zyxel_Melen image  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate
    Options

    Hi @weite

    Thanks for your feedback. We are checking on this issue now. I will update once I get further result.

    Zyxel Melen


  • Zyxel_Melen
    Zyxel_Melen image  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate
    Options

    Hi @weite

    Our team has addressed this issue, and it will be fixed in the next firmware release.

    Zyxel Melen