-
[Trade-Up Program] 🔄 Time to Trade Up: Say Goodbye to Legacy USG, Hello to Next-Level Securi…
Time to Trade Up: Upgrade Your Legacy USG and Unlock a Powerful New Experience.
-
Recovery Steps for USG FLEX/ATP Series Application Patrol Signature Issue (Jan. 2025)
Symptom: The App Patrol signature release V1.0.0.20250123.0 may create parsing error on device for On-premises mode, application patrol daemon will not work well after updating this new signature though the rest of UTM features keep running. However, the worst case is that device may get stuck if device did rebooting…
-
Zyxel USG FLEX and ATP series – Upgrading your device and ALL credentials to avoid hackers' attack
Zyxel team has been tracking the recent activity of threat actors targeting Zyxel security appliances that were previously subject to vulnerabilities and admin passwords have not been changed since then. Users are advised to update ALL administrators accounts for optimal protection. Based on our investigation, the threat…
-
Important Reminder for your Content Filter Service
At Zyxel, we are committed to providing you with the most advanced and secure services possible. In line with this commitment, we continuously enhance our Content Filter service to ensure top-notch security detection from Trellix. To ensure your service running stable and efficiently, please upgrade firmware to the latest…
-
How to solve the issue "ZTP is already enabled" on VPN series?
Symptom: Unable to access the web GUI. Access the web GUI but the page "ZTP is already enabled" appears. The device is on-premises mode and never deployed using ZTP. Q1. What are the impact model and version for this issue? Affected model Affected version VPN50 5.00 through 5.36(ABHL2)C0 VPN100 5.00 through 5.36(ABFV.2)C0…
-
What should I do if the device failed to be upgraded to the latest firmware?
Please follow the procedure to upgrade the firmware Step 1. Make sure you have on-site local support that able to reach the device Step 2. Unplug all WAN connections. Step 3. Access the device via LAN IP. Step 4. Copy startup-config.conf to recover.conf. Download "recover.conf" to your PC. Step 5. Switch to standby…
-
USG Flex 700 - Password change recommendation window - cannot be disabled
We're just commissioning our new USG Flex 700 (v5.35 ABWD.0), taking-over all settings from our USG110. Lot of typing work since a converter from USG110 to USG Flex 700 is not available. But anyway, this is not the problem. On each login the USG Flex is showing a password change recommendation window which contains a…
-
Problem to connect ftp with 1990 port - USG Flex 100
Hello i'm try to connect an ftp server with port 1990 but not works. It works with statandard port and works if i connect form other lan not connect to firewall I not set any limitations form lan to wan Thanks
-
Can you please send me 404XZ0D0.bin - ZyWALL 2 Plus
Can you please send me a copy of latest firmware for ZyWALL 2 Plus which is apparently 404XZ0D0.bin in a PM ? Those boxes are not in production but for training for the junior IT students. Thank you, Marc Dumont
-
ZLD 5.x firmware development status
According to this page https://support.zyxel.eu/hc/en-us/articles/360005438274-Weekly-Firmware-Support-Version-Lab-Version latest pubblication of Lab Firmware for ZLD 5.x is dated november 2024, 1 month after 5.39P1, roughly 20 weeks ago. Is there a new way for access Lab Firmwares? Is Lab Firmware release suspended? Is…
-
USG FLEX 500 FIREWALL FREEZES AND REBOOTS
I'm having issues with two USG FLEX 500s in HA (High Availability). Every 2 to 4 days, they freeze (PWR+SYS LEDs off and port LEDs blinking)." The tests I have performed are: Shut down the passive firewall and leave only the master active. Shut down the master firewall and leave only the passive one, promoted to master The…
-
VPN client-to-site settings for MacOS 15 (Sequoia)
Hi, I'm currently using these settings for a working VPN connection from Windows native clients: Gateway: - SA Lifetime: 86400 - Negotiation mode: Main - Proposal (enc/auth): 3DES/SHA1 - Key Group: DH2 Connection: - SA Lifetime: 3600 - Active Protocol: ESP - Encapsulation: Transport (L2TP/IPSec) or Tunnel (IKEv2) -…
-
Interpreting the DNS Threat Filter report
Please help me understand what the following report means and how I can fix the problem. The client IP address in the report is the address of our internal domain controller DNS server. It is set as the primary DNS address on the client computers. Both the endpoints and the servers have endpoint-side antivirus. Where do I…
-
Why is FLEX H being advertised as an upgrade?
I am not happy with the latest FLEX H model and the "trade in" promotion will certainly bring in more disappointed users. The firmware is not feature complete versus the FLEX The converter will not convert all config data, in fact almost none 1-2 year feature requests for missing functions of the FLEX Someone really messed…
-
IPSec VPN does not work with latest MacOS, restoring a configuration does NOT reinstall the VPN part
Hi all, I have seen the instructions posted in the VPN section and followed them to install IPSec VPN on the newest MacBook with newest MacOS. Older MacOS and notebooks worked fine with the IPSec VPN. Before: IPSec VPN works for Androids and Windows and older MacOS, but does not work with the newest MacBooks with newest…
-
Cannot send mail to two-factor authentication for SSL VPN
Hi, I would like to use two-factor authentication for SSL VPN access but from the logs I see this error and I can't understand what I should do. Thanks Max
-
Where is all the documentation for SecuExtender?
I bit the bullet and bought licenses for MacOS and Win11. I use the StrongSwan for Android and the Win11 clients and settings created by the Zyxel firewall wizard, and they work automatically just fine. Now, I need to know where to look after what on the firewall, in order to configure the SecuExtender VPN client. Where is…
-
USG Flex 200H: ipsec vpn - peer gateway BACKUP address
I have a question. On our old USG 310, we were able to set up a primary and a secondary IP address for the IPSEC VPN "peer gateway address." It's now missing, and I don't know why. Is there another solution for a fallback? I couldn't find. Thank you for your help!
-
Zyxel USG Flex series - any way to send DEBUG system log through e-mail?
Is there any way to send DEBUG system log through e-mail? No option in the settings, only NORMAL and ALERT.
-
Nebula GEO IP Blocking
In Nebula if you wished to use the GEO IP Blocking feature, it used to restrict you to only inputting 10 countries per rule. However I am now finding that it allows me to add more than 10 countries in a sigle GEO IP Filtering rule. Has the 10 country limit been removed entirely? Or has it been raised to a higher number of…
-
no link in P1 port, in Flex200H device
Our company has a Flex200 firewall, and the service provider device is FiberHome AN5506-02-FG GPON Modem Router (configured PPPoE connection). We receive a Flex200H device for testing, to which, if we replace our own device, there is no link on anymore the WAN (P1) port It is plugged into any other device there is physical…
-
IPSec sessions on the firewall not terminated after a while of being idle?
I have the following scenario: I manually connect with a device (smartphone or notebook) and via IPSec VPN client (the ones generated by the USG-20W-VPN), StrongSwan resp. Win1x Client from outside. Now, when I take the device(s) again in WiFi range, they reconnect to the WiFi ergo the IPSec tunnel is not used anymore.…
-
USG Flex - extending a broadcast domain for WoL magic pakets?
We have running a server in one subnet, which is able to send magic WoL pakets into the own subnet in order to wake-up computers. Such magic paket will not be routed into other subnets. But now we've extended our network with an additional subnet (VLAN) and would like to wake-up computers from that new subnet as well, but…
-
USG110 upgrade
-
Routing public class c over VPN Tunnel
Hello, Here is our setup. Location A has public class C (1.1.1.0/24). Location B has a single public IP. Loc B has internal IPs 192.168.5.1/24. Both locations have ATP800 and are connected to each other VPN tunnel. Loc A vti IP 10.10.20.10. Loc B vti IP 10.10.20.20. On Loc A ATP, we have policy route to route 1.1.1.5 -…
-
multiple site to site vpn accessing the same resources.
This is not the typical vpn access that i usually setup and it has me a bit stumped. I have a site to site vpn that was setup to access a set of devices on the network. I'll try and explain this best I can. ips are just examples and there are 4 devices that need to be accessed. VPN-1 Site A (devices vlan…