Zyxel has identified the root cause of an issue affecting certain USG FLEX, ATP, and VPN Series firewalls managed in on-premises mode.
Note: USG FLEX H Series and USG LITE Series are NOT affected
The issue may cause the following symptoms:
- Web GUI is inaccessible.
- SSH access may also become unavailable on some devices.
- HTTPS traffic from the LAN to the Internet is not working.
- Other network services continue to operate normally.
Resolution Options
If your firewall is affected by this issue, choose one of the following recovery options.
Before You Begin: If your firewall is still accessible, we strongly recommend backing up the configuration and any custom files before performing a firmware upgrade or recovery procedure.
| Situation | Recommended Action |
|---|---|
| The firewall is still accessible and firmware upgrade is possible. | Option 1 – Upgrade to the Fixed Firmware |
| Use this procedure only if the Web GUI is inaccessible, FTP recovery is not possible. | Option 2 – Recovery Procedure |
Option 1 – Upgrade to the Fixed Firmware (Recommended)
If your firewall Web GUI is still accessible or FTP access from the LAN is available, install the fixed firmware.
| Model | Firmware ID | Fixed Firmware |
|---|---|---|
| USG FLEX 50 / USG20-VPN | ABAQ | Download |
| USG FLEX 50W / USG20W-VPN | ABAR | Download |
| USG FLEX 50AX | ACGB | Download |
| USG FLEX 100 | ABUH | Download |
| USG FLEX 100W | ABWC | Download |
| USG FLEX 100AX | ACFN | Download |
| USG FLEX 200 | ABUI | Download |
| USG FLEX 500 | ABUJ | Download |
| USG FLEX 700 | ABWD | Download |
| ATP100 | ABPS | Download |
| ATP100W | ABRW | Download |
| ATP200 | ABFW | Download |
| ATP500 | ABFU | Download |
| ATP700 | ABTJ | Download |
| ATP800 | ABIQ | Download |
| VPN50 | ABHL | Download |
| VPN100 | ABFV | Download |
| VPN300 | ABFC | Download |
| VPN1000 | ABIP | Download |
For detailed instructions, refer to: How to Update the Firmware via FTP
Important: After the firmware upgrade is complete
- Change all administrator and user passwords.
- Enable 2FA for all administrator accounts.
Option 2 – Recovery Procedure
Use this procedure only if the Web GUI is inaccessible, FTP recovery is not possible, and the firewall is running firmware 5.37P3 or later.
- Step 1 – Disconnect the WAN Port
Disconnect the WAN cable from the firewall to prevent any further impact.
- Step 2 – Back Up the Configuration and Custom Files
Important: Before cleaning the file system, back up your configuration and custom files.
Connect to the firewall using SSH or the Console and run:
debug backup custom file
Then connect to the firewall using FTP (LAN) and download:
/ tmp/customize_backup.zip
- Step 3 – Clean the File System
Run the following commands:
configure terminal
debug clean file system
- Step 4 – Reboot the Firewall
Run:
reboot
- Step 5 – Restore the Configuration
- Extract customize_backup.zip.
- Open the conf folder.
- Rename Startup-config.conf (for example, to bckStartup-config.conf).
- Upload the configuration file via:
Configure → Maintenance → File Manager → Configuration File
- Click Apply.
- Step 6 – Secure the Firewall
After the recovery is complete:
- Change all administrator and user passwords.
- Enable 2FA for all administrator accounts.
If the Issue Persists
If the issue persists after completing the recovery procedure, please contact Zyxel Support and provide the following information.
- CLI Output
Run the following commands and include the output:
show version
show serial-number
show username
Additional Information
Please provide the following information about the device status by the time the issue happened:
Is GUI or SSH reachable from the Local LAN?Is the firewall providing internet access to LAN clients?
Is there a firewall rule opened from the WAN?
Especially for HTTPs?Is HTTPS configured with the default TCP 443 port?
if not, which port?When was the last time the admin password was changed?
Is the firewall running the latest firmware?
If not which firmware is running and when was this upgraded?
Is the firewall managed via Nebula Cloud or On-premise?
What's the system uptime from the device?If possible, are you able to provide the TeamViewer session?
If so, please provide it. If possible, include TeamViewer access in your support request to help Zyxel Support perform additional troubleshooting.

Comments
0 commentsPlease sign in to leave a comment.