[Nebula] Implement EAP-TLS and EAP-TTLS on Nebula Managed AP
Zyxel Employee
Background
Windows Active Directory Server are widely used to maintain enterprise inventory and employee information. Furthermore, we can utilize the information inside server for wireless authentication to raise the network security. Over several authentication credentials, the certificate is much securer than username/password, and In the wireless network, there’re two popular approaches using certificate: EAP-TTLS and EAP-TLS. The former approach uses certificate to protect authentication traffic and verify server’s identity (make sure the client is connecting to a trusted server), and uses username and password for client authentication. Meanwhile, the latter one uses certificate for both server and client authentication.
This document includes the process for constructing an environment using EAP-TTLS and EAP-TLS when APs are managed in Nebula Control Center, which covers configurations on client device and Nebula Control Center. Help user to deploy their network easily and efficiently.
Topology

Check the attached file for complete configuration process.
Categories
- All Categories
- 439 Beta Program
- 2.8K Nebula
- 202 Nebula Ideas
- 126 Nebula Status and Incidents
- 6.3K Security
- 513 USG FLEX H Series
- 328 Security Ideas
- 1.7K Switch
- 84 Switch Ideas
- 1.3K Wireless
- 49 Wireless Ideas
- 6.8K Consumer Product
- 288 Service & License
- 458 News and Release
- 90 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 4.3K FAQ
- 34 Documents
- 85 About Community
- 97 Security Highlight