Skip to main content
DevicesHow TosNext-Gen FirewallsZyxel

Set up IKEv2 VPN for a Zyxel USG Flex Firewall

By GabrielleJuly 26, 2023August 8th, 2023No Comments

Zyxel USG Flex series are sophisticated firewall solutions for small business and home office users, all the way up to larger enterprises. With support for both IKEv1 and IKEv2 VPN, as well as SSL VPN, users can easily set up secure remote access to their home or company network.

Configure VPN for Zyxel USG Flex

In this guide, we take you through the ins and outs of configuring IKEv2 VPN for a Zyxel USG Flex firewall, plus how to set up secure remote access in VPN Tracker for Mac, iPhone and iPad.

Create a new IKEv2 tunnel for Zyxel USG Flex

Setting up VPN on your Zyxel USG Flex device is easy, thanks to the step-by-step wizard. To access the wizard, log in to the user interface of your USG Flex and click on the magic wand icon:

Click the magic wand icon to access the wizard


You will now see the Quick Setup window. Choose Remote Access VPN Setup to start setting up VPN:

Open the Remote Access setup for VPN


For scenario, choose IKEv2 IPSec Client:


You now have the option to choose your network traffic configuration. As a default, the USG Flex will tunnel all internet traffic through the VPN (full tunnel / host-to-everywhere.) For faster performance and better compatibility with local network resources, use split tunnelling to specify exactly which networks are to be used with the VPN tunnel.

To enable split tunnelling, check the box next to Split Tunnel and choose your LAN network from the dropdown:

Choose Split Tunnel for more efficient VPN


Next, go to IP Address Pool. Choose Custom to specify the remote network you are connecting to via the VPN:

Enter the remote network range for the VPN

Important: The network range you enter here needs to lie outside of your LAN network, otherwise the connection will not work.

In this step, you also have the option to specify DNS (Domain Name Server) settings for the VPN. Remember the DNS settings you select will have to be entered into the VPN client later.


Once you have configured your network settings, you can start adding VPN users. Click to add a new user, then fill out the fields as prompted:

Click to add a new VPN user


Fill out the user information


Once a new contact has been added to your available users, click the right-pointing arrow to move them to the member list for the new VPN connection:

The new user will appear under "available users"


Click to move the new user to the member list for the connection


Finally, you will be shown a summary of your new connection details. If you are happy with the setup, click Save to exit the wizard:

Check over your connection details and save

Connect to Zyxel USG Flex VPN on Mac & iOS

In order to connect to your new Zyxel IKEv2 VPN tunnel, you will need a VPN client. VPN Tracker is the leading VPN client for macOS and iOS, so you can get secure remote access on all your devices.

The VPN Tracker setup wizard for Zyxel USG Flex enables you to get connected to your VPN in seconds. Simply enter your gateway's IP address, login with your user credentials and go!

Follow the steps in the wizard to set up your Zyxel IKEv2 connection

Your VPN Tracker benefits

  • Secure remote access to your company network, home office, and Smart Home - all in one app
  • Use your own VPN gateway
  • Ready-made profiles for 300+ VPN devices
  • Configuration wizard for a smooth and fast setup
  • For Mac, iPhone, iPad
  • Discover all features
connect to IPsec vpn on iOS
0 0 votes
Article Rating
Notify of
Inline Feedback
View all comments
Privacy-Settings / Datenschutz-Einstellungen
Feedback or improvements? Let us know!x