Site to site zone not saving in config

Options
PeterUK
PeterUK Posts: 4,738
250 Answers 2500 Comments Friend Collector Ninth Anniversary
image  Guru Member
edited September 27 in USG FLEX H Series

USG FLEX 700H V1.39(ABZI.0)ITS-26WK36-m12745

So at first I though this was some other bug then I looked at the config for site to site Zywall110V4 zone and it was set at none which is odd because I know I would of set that so changed it back to IPSec_VPN and save the config. But I could not put my finger on it as to why...so I looked I the config to find where its stored under
/ object zone-object zone "IPSec_VPN" ike "child-sa"

/ object zone-object zone "IPSec_VPN"
/ object zone-object zone "IPSec_VPN" "description" "Default IPSec_VPN zone"
/ object zone-object zone "IPSec_VPN" ike "child-sa" "sec_policy1_Zywall110V1"
/ object zone-object zone "IPSec_VPN" ike "child-sa" "sec_policy1_Zywall110V2"
/ object zone-object zone "IPSec_VPN" ike "child-sa" "sec_policy1_Zywall110V3"
/ object zone-object zone "IPSec_VPN" ike "child-sa" "Zywall110V5test_sp1"
/ object zone-object zone "IPSec_VPN" ike "child-sa" "Tuneltoflex60W_test_sp1"
/ object zone-object zone "IPSec_VPN" ike "child-sa" "Tuneltoflex60W_local_sp2"
/ object zone-object zone "IPSec_VPN" ike "child-sa" "Tuneltoflex60W_local_sp1"
/ object zone-object zone "IPSec_VPN" ike "child-sa" "test"

but where is

/ object zone-object zone "IPSec_VPN" ike "child-sa" "sec_policy1_Zywall110V4”

Hmm so test looks to be what should be "sec_policy1_Zywall110V4” but was named test vs the other sec_policy1_Zywall110V#

Screenshot 2026-09-27 160858.png

but still not sure why zone was set to none…

looking back of my backups I can see:

model: USG FLEX 700H
date: 2026-05-25 23:05:22 (UTC+00:00)
firmware version: 1.38(ABZI.0)ITS-26WK16-m11228

has

/ object zone-object zone "IPSec_VPN" ike "child-sa" "test"

then

model: USG FLEX 700H

date: 2026-06-15 10:21:33 (UTC+00:00)

firmware version: 1.38(ABZI.0)ITS-26WK16-m11228

has it missing?

All Replies

  • Zyxel_Melen
    Zyxel_Melen Posts: 5,116
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate
    image  Zyxel Employee
    Options

    Hi @PeterUK

    May you share the configuration file with us to check this issue?

    Zyxel Melen


  • PeterUK
    PeterUK Posts: 4,738
    250 Answers 2500 Comments Friend Collector Ninth Anniversary
    image  Guru Member
    Options

    files sent

  • Zyxel_Melen
    Zyxel_Melen Posts: 5,116
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate
    image  Zyxel Employee
    Options

    Hi @PeterUK

    I noticed that the VPN phase 2 policy name is test, which is as same as one of your zone. In order not to cause system issue, please change the name first.

    We will investigate this issue further. (I think I reproduce this issue after applying your config. But strange that after I add the VPN tunnel to IKE zone and reboot, the VPN tunnel Zone is still IKE zone.)

    Zyxel Melen


  • PeterUK
    PeterUK Posts: 4,738
    250 Answers 2500 Comments Friend Collector Ninth Anniversary
    image  Guru Member
    Options

    Ok thanks for the update I have remove zone test and made a new policy with new name

  • mMontana
    mMontana Posts: 1,509
    Zyxel Certified Network Administrator - Security Zyxel Certified Network Administrator - Switch 50 Answers 1000 Comments
    image  Guru Member
    Options

    "In order not to cause system issue, please change the name first."

    @Zyxel_Melen in documentation of Flex H devices is specified to have unique names for all the objects?