Known Issue: Web GUI Unreachable and HTTPS Connectivity Issues on Certain USG FLEX, ATP, VPN, and USG Firewalls

Zyxel has identified the root cause of an issue affecting certain USG FLEX, ATP, and VPN Series firewalls managed in on-premises mode.

Note: USG FLEX H Series and USG LITE Series are NOT affected

The issue may cause the following symptoms:

  • Web GUI is inaccessible.
  • SSH access may also become unavailable on some devices.
  • HTTPS traffic from the LAN to the Internet is not working.
  • Other network services continue to operate normally.

Resolution Options

If your firewall is affected by this issue, choose one of the following recovery options.

Before You Begin: If your firewall is still accessible, we strongly recommend backing up the configuration and any custom files before performing a firmware upgrade or recovery procedure.

Situation Recommended Action
The firewall is still accessible and firmware upgrade is possible. Option 1 – Upgrade to the Fixed Firmware
Use this procedure only if the Web GUI is inaccessible, FTP recovery is not possible. Option 2 – Recovery Procedure

Option 1 – Upgrade to the Fixed Firmware (Recommended)

If your firewall Web GUI is still accessible or FTP access from the LAN is available, install the fixed firmware.

Model Firmware ID Fixed Firmware
USG FLEX 50 / USG20-VPN ABAQ Download
USG FLEX 50W / USG20W-VPN ABAR Download
USG FLEX 50AX ACGB Download
USG FLEX 100 ABUH Download
USG FLEX 100W ABWC Download
USG FLEX 100AX ACFN Download
USG FLEX 200 ABUI Download
USG FLEX 500 ABUJ Download
USG FLEX 700 ABWD Download
ATP100 ABPS Download
ATP100W ABRW Download
ATP200 ABFW Download
ATP500 ABFU Download
ATP700 ABTJ Download
ATP800 ABIQ Download
VPN50 ABHL Download
VPN100 ABFV Download
VPN300 ABFC Download
VPN1000 ABIP Download

For detailed instructions, refer to: How to Update the Firmware via FTP

Important: After the firmware upgrade is complete

  • Change all administrator and user passwords.
  • Enable 2FA for all administrator accounts.

Option 2 – Recovery Procedure

Use this procedure only if the Web GUI is inaccessible, FTP recovery is not possible, and the firewall is running firmware 5.37P3 or later.

  • Step 1 – Disconnect the WAN Port

Disconnect the WAN cable from the firewall to prevent any further impact.

  • Step 2 – Back Up the Configuration and Custom Files

Important: Before cleaning the file system, back up your configuration and custom files.

Connect to the firewall using SSH or the Console and run:

debug backup custom file

Then connect to the firewall using FTP (LAN) and download:

/ tmp/customize_backup.zip
  • Step 3 – Clean the File System

Run the following commands:

configure terminal
debug clean file system

  • Step 4 – Reboot the Firewall

Run:

reboot
  • Step 5 – Restore the Configuration
  1. Extract customize_backup.zip.
  2. Open the conf folder.
  3. Rename Startup-config.conf (for example, to bckStartup-config.conf).
  4. Upload the configuration file via:

Configure → Maintenance → File Manager → Configuration File

  1. Click Apply.
  • Step 6 – Secure the Firewall

After the recovery is complete:

  • Change all administrator and user passwords.
  • Enable 2FA for all administrator accounts.

If the Issue Persists

If the issue persists after completing the recovery procedure, please contact Zyxel Support and provide the following information.

  • CLI Output

Run the following commands and include the output:

show version
show serial-number
show username

Additional Information

Please provide the following information about the device status by the time the issue happened:

  • Is GUI or SSH reachable from the Local LAN?Is the firewall providing internet access to LAN clients?

  • Is there a firewall rule opened from the WAN? 

  • Especially for HTTPs?Is HTTPS configured with the default TCP 443 port?

  • if not, which port?When was the last time the admin password was changed?

  • Is the firewall running the latest firmware? 

  • If not which firmware is running and when was this upgraded?

  • Is the firewall managed via Nebula Cloud or On-premise?

  • What's the system uptime from the device?If possible, are you able to provide the TeamViewer session?

  • If so, please provide it. If possible, include TeamViewer access in your support request to help Zyxel Support perform additional troubleshooting.

 

Articles in this section

Was this article helpful?
0 out of 0 found this helpful
Share

Comments

0 comments

Please sign in to leave a comment.