-
[Security Router]Do I need to create an rule after setting a virtual server rule?
No, setting a NAT rule for the virtual server automatically allows traffic. However, since the priority is Country Restriction > Security Policies > Virtual Server, any blocking rule in Country Restriction or Security Policies may prevent access to the virtual server.
-
What Is the Priority Order of Policies on the Security Router?
On the SCR 50AXE and USG LITE 60AX. The priority order is as follows: Country Restriction > Security Policies > Virtual Server If Country Restriction is set to "Allow", it takes precedence over security policies, even if a blocking rule exists. Example: If a security policy blocks a specific IP from Taiwan, but country…
-
[Security Router]How does the country restriction feature function?
On the SCR 50AXE and USG LITE 60AX. The country restriction feature allows you to either block or allow traffic based on a country’s IP address. Block List: If you select "Block" for a country, only traffic from that country is denied, while all other countries can still access the device. Example: If you block Japan for…
-
Why is the SCR 50AXE Event log not showing any Data?
The event log of the SCR50 AXE includes Threat Management and Content Filter logs. Other logs will not be displayed in the event log on SCR 50AXE. If you encounter any issue, please navigate to Help -> Support request and enable "Invite Zyxel support as administrator" feature for us.
-
How to add domain into allow list on Security router?
To add the domain to the allow list for the Security Router ( SCR 50AXE ,USG LITE 60AX) Please follow the steps below: Navigate to Site-wide > Configure > Traffic management In the "Customer allowed/blocked domain", you can add the domain in to allow/block list on this page. Please note the domain list is common and is…
-
Does SCR 50AXE Support Area Leader Mode?
SCR 50AXE supports Spoke mode only and does not function as an Area Leader. To set up a Hub-and-Spoke configuration with VPN Orchestrator, a firewall is required.
-
How to unblock a client on Security Router?
Once the client is blocked by the Security Router(SCR 50AXE, USG LITE 60AX) To unblock the client, please follow the steps below. Go to Site-wide > Clients, Category select "Security router clients" and click the show policy clients on the right. The page displays clients that are under policies. Select the client and…
-
How can I block a specific client on security router?
Go to Site-wide > Client list > Choose Security router clients. Then select the client and click Policy and select the "Block list" to block the client.
-
How to block SSH protocol to the Security router?
Go to Site-wide > Configure > Security router > Firewall Block access to the device by adding a rule for port 22 (SSH).
-
Is it possible to set up a static IP for a VPN user with cloud authentication?
The USG LITE 60AX does not support to assign static IP for specific user, if you are looking to adjust the IP Pool subnet for remote access VPN user, please refer to Site-wide- > Configure > Security router > Remote Access VPN Enable the IPSec VPN server, click "Advanced Options," and modify your Client VPN subnet as…
-
Does the security router support configuring rules for users?
The Security Router SCR50AXE and USG LITE 60AX do not support configuring firewall rules with user or setting user policies.
-
How do I find my security router password when the device is on Nebula?
Once the Security Router(SCR 50AXE/ USG LITE 60AX) registers on Nebula and is online. The device local password will be set up the same as the password on the Nebula cloud. To check and modify your router password, refer to Site-wide > Configure > Site settings
-
Does USG LITE 60AX support to create user group on Nebula?
On Nebula, support to create users, but it is not available to create user groups. To create a user for cloud authentication, please go to Configure > Cloud Authentication Click the "Add" button You can configure the user settings in this page.
-
How to config Lan interface IP Pool address settings on SCR 50AXE?
The default IP address of the security router SCR 50AXE is 192.168.168.1 To modify the LAN IP pool settings, please follow the steps below: Navigate to Site-wide > Configure > Security router > Interface Click the Edit icon on the LAN interface to start modifying the DHCP IP Pool address
-
How to Fix 'Disconnected - Operation Modes Mismatch' Error
Question: How can I resolve the "Disconnected - Operation modes mismatch" error when adding my device to the Org in monitor mode? Answer: This issue occurs when your device was deployed by gamma site, but does not change back to officail site due to some reason. Steps: * Access the CLI of your device. * Enter the following…
-
Can VLAN subnets on the USG LITE 60AX communicate with each other?
Yes, VLAN subnets on the USG LITE 60AX can communicate with each other And the USG LITE 60AX does not support direct VLAN assignment to individual port interfaces. However, you can achieve VLAN segmentation in your network by configuring an SSID with a VLAN and allowing devices to connect wirelessly. If you need to connect…
-
Does USG LITE 60AX support optional to enable/disable upnp?
USG LITE 60AX does not support to enable/disable upnp function. If you want to forward a specific protocol to the client, please refer to the article below to enable NAT services. https://community.zyxel.com/en/discussion/26730/how-to-set-up-nat-rule-for-usg-lite-60ax-on-nebula
-
How to config static route on security router?
Navigate to Configure> Security router > interface At the bottom of the page, you can set up a static route policy on this page.
-
How to set up firewall rule for Security Router device on Nebula?
To configure a firewall rule for your Security router(SCR 50AXE/USG LITE 60AX) device on Nebula, follow these steps: 1. Go to Site-wide > Configure > Security router > Firewall in your Nebula dashboard. 2. Click on "ADD" to create a rule Add a rule to deny the destination IP address 3. Click "Save" to save and apply the…
-
How to set up wifi SSID on nebula for security router device?
1.Navigate to Configure > Security Router > SSID settings 2.Click Add SSID network 3. Turn on the "Advance mode" 4. Click "Edit" 5.enable the 2.4Ghz and 5Ghz band mode.