Site to site zone not saving in config
Guru Member
USG FLEX 700H V1.39(ABZI.0)ITS-26WK36-m12745
So at first I though this was some other bug then I looked at the config for site to site Zywall110V4 zone and it was set at none which is odd because I know I would of set that so changed it back to IPSec_VPN and save the config. But I could not put my finger on it as to why...so I looked I the config to find where its stored under
/ object zone-object zone "IPSec_VPN" ike "child-sa"
/ object zone-object zone "IPSec_VPN" / object zone-object zone "IPSec_VPN" "description" "Default IPSec_VPN zone" / object zone-object zone "IPSec_VPN" ike "child-sa" "sec_policy1_Zywall110V1" / object zone-object zone "IPSec_VPN" ike "child-sa" "sec_policy1_Zywall110V2" / object zone-object zone "IPSec_VPN" ike "child-sa" "sec_policy1_Zywall110V3" / object zone-object zone "IPSec_VPN" ike "child-sa" "Zywall110V5test_sp1" / object zone-object zone "IPSec_VPN" ike "child-sa" "Tuneltoflex60W_test_sp1" / object zone-object zone "IPSec_VPN" ike "child-sa" "Tuneltoflex60W_local_sp2" / object zone-object zone "IPSec_VPN" ike "child-sa" "Tuneltoflex60W_local_sp1" / object zone-object zone "IPSec_VPN" ike "child-sa" "test"
but where is
/ object zone-object zone "IPSec_VPN" ike "child-sa" "sec_policy1_Zywall110V4”
Hmm so test looks to be what should be "sec_policy1_Zywall110V4” but was named test vs the other sec_policy1_Zywall110V#
but still not sure why zone was set to none…
looking back of my backups I can see:
model: USG FLEX 700H
date: 2026-05-25 23:05:22 (UTC+00:00)
firmware version: 1.38(ABZI.0)ITS-26WK16-m11228
has
/ object zone-object zone "IPSec_VPN" ike "child-sa" "test"
then
model: USG FLEX 700H
date: 2026-06-15 10:21:33 (UTC+00:00)
firmware version: 1.38(ABZI.0)ITS-26WK16-m11228
has it missing?
All Replies
-
-
files sent
0 -
Hi @PeterUK
I noticed that the VPN phase 2 policy name is test, which is as same as one of your zone. In order not to cause system issue, please change the name first.
We will investigate this issue further. (I think I reproduce this issue after applying your config. But strange that after I add the VPN tunnel to IKE zone and reboot, the VPN tunnel Zone is still IKE zone.)
Zyxel Melen1 -
Ok thanks for the update I have remove zone test and made a new policy with new name
0 -
"In order not to cause system issue, please change the name first."
@Zyxel_Melen in documentation of Flex H devices is specified to have unique names for all the objects?
0
Categories
- All Categories
- 442 Beta Program
- 3.1K Nebula
- 241 Nebula Ideas
- 6.8K Security
- 755 USG FLEX H Series
- 380 Security Ideas
- 1.8K Switch
- 87 Switch Ideas
- 1.5K Wireless
- 58 Wireless Ideas
- 7.2K Consumer Product
- 321 Service & License
- 512 News and Release
- 99 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 5.3K FAQ
- 34 Documents
- 90 About Community
- 119 Security Highlight

Zyxel Employee