-
[ATP/FLEX]Change Firewall GUI default port
Scenario: Firewall use ports 80 and 443 for WebGui. If you have other HTTP(s) services in internal and need to use the WAN IP for mapping, you may need to modify the firewall to use different default ports. Workaround: HTTP: Router> configure terminal Router(config)# ip http port [port] Router(config)#write HTTPS: Router>…
-
Why my Firewall still offline after setting up cloud monitoring mode?
Please check the below table to verify: Status Display Description N/A Default status. You’ve not yet entered a Monitor Mode ID on the Zyxel Device. Connected The Zyxel Device is connected to Nebula. Connecting The Zyxel Device is connecting to Nebula. Disconnected – Server is not reachable The Zyxel Device cannot connect…
-
Can I add my firewall to organization before setup cloud monitoring mode?
You don't need to add the firewall to your organization before setup. After you apply the organization ID, Nebula will automatically add it to your organization. Please reference this FAQ for setting up the cloud monitoring mode:
-
Will the firewall be applied local credentials when using cloud monitoring mode?
No, the firewall won’t be applied to local credentials. It will keep the on-premises password. To change the password, please reference this topic: Please access the device's local GUI: Configuration > object > User/Group to change the admin’s password.
-
[ATP/FLEX]If you cannot do SNMP poll to firewall interface through VPN
Environment: You have site to site VPN between Headquarter and Branch. The monitor system where located in HQ try to do SNMP polling to Branch Firewall, But that's failed. Checking: Site-Wide > Configure > Firewall > Site-to-Site VPN Check the address of monitor system is in "Private Subnet" range.
-
[ATP/FLEX] How to limit ad users in the security policy rule?
Currently, nebula supports "External User Group" (not Specific User) in the security policy rule. On nebula, go to Firewall > Configure > Firewall settings > Authentication Server > My AD Server and configure AD information. You also need to add an external user group in Firewall > Configure > Firewall settings > External…
-
[ATP/FLEX] Does the group name in "External User Group" have to match the group on the AD server?
No, the group name doesn't have to match the group name on the AD server. In this example, AD_test_group is the group name on the AD server, and the group name on nebula is group1.
-
[ATP/FLEX] Is it possible to limit L2TP VPN authentication to the specified ad group?
Currently nebula doesn't support to limit L2TP VPN to a specified ad group user. It supports limiting L2TP VPN connection by different authentication method only.
-
I want to use cloud monitoring mode, but what should I do?
Scenario Nebula cloud monitoring mode is a new solution for users who require a centralized platform to manage their firewall and have complex configuration which is supported on on-premise mode. The FAQ will guide you to set up cloud monitoring mode. Step Create an organization and a site on Nebula. Then visit…
-
[SCR]How to set up multiple SSIDs on SCR device on Nebula
1.Navigate to Site-wide > Configure > WiFi SSID settings 2.Click Add SSID network 3. Enter the desired name for each SSID in the provided field. 4. Choose the WLAN security settings for each SSID. 5. Once you have configured the names and selected the security settings for the SSIDs, click "Save" to apply the changes. Your…
-
[SCR]How to Vlan on SCR device on Nebula
1.Navigate to Site-wide > Configure > Security router >Interface 2.Click “Add” on Lan Interface 3.Fill in the interface name, VLAN ID, IP address, and subnet mask and click “Ok” 4.Once you have made the changes, click "Save" to apply the new configuration to the SCR device. The Vlan interface will now be set on the lan…
-
[SCR]How to manually set up wifi channel ?
1. Navigate to Site-wide > Configure > Access points > Radio settings 2.Look for the option to choose the Wi-Fi band and choose available access points 3. To manually set the Wi-Fi channel, select the desired channel from the available options and click "Update" to change the configuration. 4. Once you have made the…
-
[SCR]How to set up a white list / block list for domains?
1. Navigate to Site-wide > Configure > Security router > Traffic Management. 2. Click on "ADD" to add URLs to either the allow list or blocked list for domains.
-
[SCR]How to set up NAT rule for SCR device on Nebula?
To configure a NAT rule for your Security router(SCR 50AXE/USG LITE 60AX) device on Nebula, follow these steps: 1. Go to Site-wide > Configure > Security router > Firewall in your Nebula dashboard. 2. Click on "ADD" to create a new NAT rule and provide the following information: Public port: Specify the port number on the…
-
[SCR]How to set up a Reserved IP on an SCR 50AXE device?
To reserve an IP address for your SCR device, follow these steps: 1. Navigate to Site-wide > Clients in your dashboard. 2. Select the Clients list. 3. Choose "Security router clients". 4. To reserve an IP address for your SCR device, follow these steps: Locate and select the specific device you want to reserve the IP for…
-
[SCR]How to set up a Static IP on an SCR device?
To configure a Static IP on your SCR device, follow these steps: 1. Navigate to Site-wide > Clients in your dashboard. 2. Select the Client list. 3. Choose the category labeled "Security router clients". 4. Click on the "Add client" option. Name: Provide a name or label for the device. MAC address: Enter the MAC address.…
-
[SCR]Why does the client count for OS version not match that of the manufacturer?
Why does the client count for OS version not match that of the manufacturer?On the dashboard, the "Security Router Clients by OS" section displays the top 5 OS versions used by clients, while the "Clients by Manufacturers" section displays the top 5 manufacturers of those clients. Security router clients by OS on the…
-
Does Nebula firewall support external authentication method?
In addition to the Nebula cloud authentication, the Nebula firewall also provides AD, LDAP, and Radius servers for authentication. The path is Site-wide > Configure > Firewall > Firewall settings
-
[ATP/FLEX] Why does the error message "Multiple VLANs are bound to one LAN port group" appear?
You can assign the same port group (LAN Group 1) to different lan interfaces only when these lan interfaces have different VLAN IDs. If these new added interface (10.92.151.200) do not have VLAN ID, you need to create new LAN Groups and assign each LAN Group to each lan interface.
-
[ATP/FLEX] Configure multiple FQDNs in one security policy rule on both destination/source address
Question: Can I configure multiple FQDNs in one security policy rule on both destination/source address? Answer: Currently you can set only one FQDN in source/destination in security policy rule on nebula. For destination, wildcard FQDN is supported. You can set one wildcard FQDN in destination.