Same 2FA Google Autheticator in USG for both boot images

Options
Kv3
Kv3 Posts: 21
First Comment Friend Collector Eighth Anniversary
image  Freshman Member

Hello,
I have a Zyxel USG Flex 500 and in firmware 1 and 2 I have version V5.43(ABUJ.0).

I keep the same configuration in both configurations (for both firmware 1 and firmware 2). I have set up a VPN with 2FA (Google Authenticator).
In configuration 1 I revoked user1 and set up Google Authenticator again and tested that logging into the VPN works without a problem. However, his new settings were not transferred to configuration 2, when I try to 2FA it says "Message: Invalid verification code for user1".

The instructions https://community.zyxel.com/en/discussion/30278/one-2fa-google-autheticator-in-usg-for-both-boot-images#latest didn't help either.

How do I transfer the changed 2FA settings to the second firmware?

Tagged:

Accepted Solution

  • Zyxel_Luna
    Zyxel_Luna Posts: 98
    5 Answers First Comment Friend Collector
    image  Zyxel Employee
    Answer ✓
    Options

    Hi @Kv3,

    Google Authenticator does not automatically sync between the two partition. However, during the upgrade process, the Google Authenticator data on the currently running partition will be synced to the new running partition (the original standby partition).

    The upgrade process is as follows:

    Upload the upgrade file to the standby partition (P2).

    After rebooting, the Google Authenticator data on the previously running partition (P1) will be synced to the standby partition (P2), which is now the active running partition.

    Please let us know the results. If you have any questions, please feel free to contact us, thank you.

All Replies

  • Zyxel_Luna
    Zyxel_Luna Posts: 98
    5 Answers First Comment Friend Collector
    image  Zyxel Employee
    Answer ✓
    Options

    Hi @Kv3,

    Google Authenticator does not automatically sync between the two partition. However, during the upgrade process, the Google Authenticator data on the currently running partition will be synced to the new running partition (the original standby partition).

    The upgrade process is as follows:

    Upload the upgrade file to the standby partition (P2).

    After rebooting, the Google Authenticator data on the previously running partition (P1) will be synced to the standby partition (P2), which is now the active running partition.

    Please let us know the results. If you have any questions, please feel free to contact us, thank you.

  • Zyxel_Luna
    Zyxel_Luna Posts: 98
    5 Answers First Comment Friend Collector
    image  Zyxel Employee
    edited September 14
    Options

    Regarding this post:

    One 2FA Google Autheticator in USG for both boot images. — Zyxel Community

    We have confirmed with the relevant team that, in the current version, the Google Authenticator configuration is not stored in the startup-config.conf file. Therefore, importing the startup-config.conf file from P1 into P2 will not synchronize the Google 2FA settings. We sincerely apologize for any confusion this may have caused and will update the content accordingly.

  • Kv3
    Kv3 Posts: 21
    First Comment Friend Collector Eighth Anniversary
    image  Freshman Member
    Options

    Hello,
    thanks for the instructions, after reinstalling the same firmware to the standby partition the configuration was transferred.