Mstlb Posted March 29, 2017 Posted March 29, 2017 Hi Does anyone use, or have experience of ZyXEL GS1900 managed switches? We currently have a flat network in school and use Netgear switches but have finally managed to get SLT to agree to managed switches. I have very limited network experience and these have been recommended to use because of the simple setup and management. However, as it's not a brand I've heard of I'm a little wary! Thanks Tracey
XiJ Posted March 29, 2017 Posted March 29, 2017 We've used them in primary schools. No issues yet with them. Although quite often they're coming from 10/100 dumb switches. Even hubs in some cases! 1
Meldrew Posted March 30, 2017 Posted March 30, 2017 We have quite a lot of ZyXel switches, been using them for about 5 years. Not had any problems with them and they seem good value. Configuration wise, at first we found them a bit awkward, but maybe that's just us. We've slowly moving to have all ZyXel network switched infrastructure. Meldrew 1
FN-GM Posted March 30, 2017 Posted March 30, 2017 When we had a DDOS attack last year I traced back a large number of the IP addresses. Every single one was from a ZyXEL device. Looks like they have vulnerabilities, it puts me off even for home use. 1
AlanD Posted April 1, 2017 Posted April 1, 2017 Any ddos attack is likely to come from a single weakness ... so you would expect if one of the traced back attacks was from a zyxel device...you could bet the others are. In this case, it's a switch in a school behind a firewall or gateway...and is not going to be greatly at risk. If it was a bank ...ok...I'd spend a lot more. Schools shouldn't buy a new BMW for teachers ..they need a ford mondeo. Value for money is everything.
Norphy Posted April 2, 2017 Posted April 2, 2017 Schools shouldn't buy a new BMW for teachers ..they need a ford mondeo. Value for money is everything. Granted but value for money does not necessarily mean the cheapest. If a BMW somehow provides a feature that you need that a Ford doesn't, you're not going to buy the Ford 3
FN-GM Posted April 2, 2017 Posted April 2, 2017 Any ddos attack is likely to come from a single weakness ... so you would expect if one of the traced back attacks was from a zyxel device...you could bet the others are. In this case, it's a switch in a school behind a firewall or gateway...and is not going to be greatly at risk. If it was a bank ...ok...I'd spend a lot more. Schools shouldn't buy a new BMW for teachers ..they need a ford mondeo. Value for money is everything. So you're happy to have devices on a network with vulnerabilities?
Edu-IT Posted April 3, 2017 Posted April 3, 2017 So you're happy to have devices on a network with vulnerabilities? Are these vulnerabilities confirmed? Link please?
FN-GM Posted April 3, 2017 Posted April 3, 2017 (edited) Are these vulnerabilities confirmed? Link please? http://letmegooglethat.com/?q=zyxel+ddos+attack You don't even work in IT anymore? Edited April 3, 2017 by FN-GM
ricki Posted April 3, 2017 Posted April 3, 2017 (edited) If you don't want vunerable kit on your network don't have Microsoft then Edited April 3, 2017 by ricki
FN-GM Posted April 3, 2017 Posted April 3, 2017 If you don't want vunerable kit on your network don't have Microsoft then It is in the process of being removed. We have reduced the amount of MS devices by 1/3 in 6 months.
ricki Posted April 3, 2017 Posted April 3, 2017 Got forget all CCTV equipment after news a couple of weeks ago about being used for did attacks
FN-GM Posted April 3, 2017 Posted April 3, 2017 To be fair with Microsoft though. They do fix the vulnerabilities. the ZyXEL thing has been known for years. When I had the DDOS I was find stuff from years previous to that about the exact same thing. I didn't look too much into the CCTV attacks, but I believe it was all from cheap products that I wouldn't recommend anyway.
ricki Posted April 3, 2017 Posted April 3, 2017 The point I am trying to make is all kit is vulnerable at some point you live with it and do your best. If you don't want to be vulnerable turn all your kit off 1
FN-GM Posted April 3, 2017 Posted April 3, 2017 The point I am trying to make is all kit is vulnerable at some point you live with it and do your best. If you don't want to be vulnerable turn all your kit off The point I am trying to make is cheap equipment doesn't mean good value. In this case they are known for not fixing issues. Probably why you don't pay much for it. 1
rrrrr Posted April 3, 2017 Posted April 3, 2017 There are always new vulnerabilities being discovered, no matter the brand of the device. The issue with some cheaper kit is the support cycle for it. The cheaper devices, once a few years old may no longer be supported by the patched firmware. It comes down to good network management, so if a device is compromised, its detected and doesn't allow the attacker to escalate the attack, or use it as a pivot point to attack other devices. Regarding DDoS attacks, if the network device is not internet facing its unlikely to be a culprit unless there is a larger scale internal compromise, but good egress filtering and monitoring at the corporate firewall should prevent/identify this. Some of the cheaper switches dont offer some security features. check you can implement good network access control with the new devices. 1
AlanD Posted April 5, 2017 Posted April 5, 2017 I wouldn't have a concern using them internally on the network in a school. From what I have seen - it appears you can run all your ZyXel switches as a single "virtual" switch through a single web interface. Makes visibility and configuration a breeze. If we weren't already a "netgear" site I would be using ZyXel switches - and spending the thousands (and more) on other stuff. Not sure I would use a ZyXEL firewall/router - there are lots of options for that role - again without spending a fortune. Perhaps for a university or something - then I would be looking for something more robust.
Edu-IT Posted April 6, 2017 Posted April 6, 2017 (edited) Let Me Google That You don't even work in IT anymore? By job title, no, but, I've still got my finger in the pie. Thanks for the links. Edited April 6, 2017 by Edu-IT
mavhc Posted July 21, 2021 Posted July 21, 2021 Local IT company just recommended them to me, but https://threatpost.com/cybercriminals-exploits-zyxel-flaw/162789/ they're still insecure in 2021
FN-GM Posted July 21, 2021 Posted July 21, 2021 Local IT company just recommended them to me Because they are cheap and easy to setup. 2
Norphy Posted September 2, 2021 Posted September 2, 2021 @ZyxelNetworksDaniel, the post you're quoting was written in 2017! I think you may have missed the boat on that one. Also, you don't need to make essentially the same post three times in a row...
RedwayNetworks_Michael Posted March 31, 2023 Posted March 31, 2023 BUMP How are we feeling about ZyXEL in 2023? Love this haha made my morning
Norphy Posted March 31, 2023 Posted March 31, 2023 BUMP How are we feeling about ZyXEL in 2023? Much the same, I suspect. From what I've seen, the hardware is OK for the price but the support isn't all that.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now