-
Security Router Interface Naming Enhancements in Nebula 18.30
With Nebula 18.30, Zyxel has introduced new interface description fields and improved error handling for reserved interface names on security routers, specifically the SCR 50AXE and USG-Lite 60AXE. These enhancements improve network visibility, organization, and configuration reliability. 1. New Interface Description Field…
-
[SCR]Why are some hosts unable to be controlled by the SCR50AXE content filter service?
Question: We are testing the content filter service on SCR50AXE. Why are some hosts unable to be controlled by the SCR50AXE content filter service? Answer: Please check if DNS over HTTPS (DoH) is enabled on the Windows host. The SCR50 content filter would not work if hosts have DoH enabled. To check if DNS over HTTPS (DoH)…
-
Does the USG LITE 60AX support exporting security policy rules?
Currently, Nebula does not support this feature. We suggest using the CLI command 'show running-config' to retrieve the security policy content as a workaround solution.
-
How do I set up a VPN on a USG LITE 60AX with a non Zyxel device?
To create a site-to-site VPN between a Zyxel device in Nebula and a device from another manufacturer. You can follow the steps below: To build up non-Nebula VPN tunnel on Nebula, follow these steps: 1. Navigate to Site-wide > Configure > Security router > Site-to-Site VPN 2.Configure VPN settings: 1.Activate the tunnel.…
-
How do I set up a VPN on a SCR 50AXE with a non Zyxel device?
To create a site-to-site VPN between a Zyxel device in Nebula and a device from another manufacturer. You can follow the steps below: To build up non-Nebula VPN tunnel on Nebula, follow these steps: 1. Navigate to Site-wide > Configure > Security router > Site-to-Site VPN 2.Configure VPN settings: 1.Activate the tunnel.…
-
How to allow a service using NAT instead of UPnP on SCR 50AXE?
There is no option to enable/disable the UPnP function or check the services. If you would like to connect the device, you can use the NAT function. Here is the article on how to set up NAT on Nebula https://community.zyxel.com/en/discussion/18193/scr-how-to-set-up-nat-rule-for-scr-device-on-nebula Refer to the article…
-
My Security router detects external attacks daily. Is there a way to block my fixed IP ?
Blocking a fixed IP or preventing external attacks requires additional configuration. Here are some possible solutions: 1 .Configure Firewall Rules – Utilize the firewall's rule to establish more precise access control, including filtering by IP addresses, port numbers, and protocols. 2 .Enable Country Restriction -…
-
Bridge mode cannot be configured via the local web GUI for USG LITE 60AX?
The local GUI includes WAN configuration options. However, to change to bridge mode is not possible via local web GUI. Refer to the article below to check where to configure bridge mode on Nebula. https://community.zyxel.com/en/discussion/28658/how-to-configure-bridge-mode-on-nebula-for-usg-lite-60ax/p1?new=1
-
How to configure Bridge mode on Nebula for USG LITE 60AX?
Navigate to Site-wide > Configure > Interface Enable IPTV and select Bridge mode to enable it. Refer to the link below for more information about the bridge mode https://community.zyxel.com/en/discussion/25392/usg-lite-60-ax-iptv-interface
-
How to config Lan settings on USG LITE 60AX on Nebula?
The default IP address of the security router USG LITE 60AX is 192.168.168.1 To modify the LAN settings, please follow the steps below: Navigate to Site-wide > Configure > Security router > Interface Click the Edit icon on the LAN interface to start modifying.
-
Where can I check my license on the SCR 50AXE?
Question :Where can I check my license on the SCR 50AXE? Navigate to Site-wide > License & inventory Click Licenses You can view your license on the page
-
How to set PPPoE with static IP address on USG LITE 60AX
Navigate to Site-wide > Security router > Configure > Interface. Click Edit Type select PPPoE with static IP
-
How to view historical CPU/memory status on Nebula firewall?
Question: When managing devices via Nebula Cloud Mode, how to check the historical CPU and memory usage? Answer: Log in to your Nebula Control Center. Navigate to Monitor > Firewall > Summary report. Here, you can view the CPU and memory status. You can adjust the period of time for which you want to view the data by…
-
[Security Router]Why doesn’t country restriction block remote VPN connections
The Country Restriction feature only applies to traffic between the internet and LAN or LAN and the internet. It does not affect traffic between the internet and the device itself (e.g., remote VPN connections). This is why a VPN connection can still be established, even if the country is blocked. How to Restrict VPN…
-
[Security Router]Do I need to create an rule after setting a virtual server rule?
No, setting a NAT rule for the virtual server automatically allows traffic. However, since the priority is Country Restriction > Security Policies > Virtual Server, any blocking rule in Country Restriction or Security Policies may prevent access to the virtual server.
-
What Is the Priority Order of Policies on the Security Router?
On the SCR 50AXE and USG LITE 60AX. The priority order is as follows: Country Restriction > Security Policies > Virtual Server If Country Restriction is set to "Allow", it takes precedence over security policies, even if a blocking rule exists. Example: If a security policy blocks a specific IP from Taiwan, but country…
-
[Security Router]How does the country restriction feature function?
On the SCR 50AXE and USG LITE 60AX. The country restriction feature allows you to either block or allow traffic based on a country’s IP address. Block List: If you select "Block" for a country, only traffic from that country is denied, while all other countries can still access the device. Example: If you block Japan for…
-
Why is the SCR 50AXE Event log not showing any Data?
The event log of the SCR50 AXE includes Threat Management and Content Filter logs. Other logs will not be displayed in the event log on SCR 50AXE. If you encounter any issue, please navigate to Help -> Support request and enable "Invite Zyxel support as administrator" feature for us.
-
How to add domain into allow list on Security router?
To add the domain to the allow list for the Security Router ( SCR 50AXE ,USG LITE 60AX) Please follow the steps below: Navigate to Site-wide > Configure > Traffic management In the "Customer allowed/blocked domain", you can add the domain in to allow/block list on this page. Please note the domain list is common and is…
-
Does SCR 50AXE Support Area Leader Mode?
SCR 50AXE supports Spoke mode only and does not function as an Area Leader. To set up a Hub-and-Spoke configuration with VPN Orchestrator, a firewall is required.
-
How to unblock a client on Security Router?
Once the client is blocked by the Security Router(SCR 50AXE, USG LITE 60AX) To unblock the client, please follow the steps below. Go to Site-wide > Clients, Category select "Security router clients" and click the show policy clients on the right. The page displays clients that are under policies. Select the client and…
-
How can I block a specific client on security router?
Go to Site-wide > Client list > Choose Security router clients. Then select the client and click Policy and select the "Block list" to block the client.