Nebula joined AP Layer 2 isolation
So here is the implementation I'm doing at my cliënts now: NWA210AX AP's configured in Nebula with extra SSID's in separate VLAN. VLAN configured in firewall so that it can't communicate with LAN1 and also can't communicate with ZyWALL and in Nebula Layer 2 Isolation enabled that cliënts only can communicate with LAN1 interface on Firewall.
Pretty tightened down: Cliënts can't access management interface ZyWALL, cliënts can't access other cliënts connected through wifi and they can't see devices in LAN1.
But what they have access to is the management interface of the Access points (IP in LAN1). It's strange in how this is possible because the security rule in the firewall doesn't allow this(ZyXEL FLEX 200)
All Replies
-
Not sure if you can do this with Nebula but what I have done is given AP's their own VLAN so on boot they connect by Native get the config then load on set VLAN so you can't access management interface
0 -
Hi @nielsscheldeman ,
Firstly, could you please verify if your NWA210AX is running on the latest firmware version, which is 6.60P1? Also, please check if the Captive Portal (Sign-in method) is enabled for the SSID.
If the Captive Portal is enabled and the NWA210AX firmware is not up-to-date, you can upgrade it by navigating to Configure > Firmware Management > Device Tab, selecting the device, and clicking on 'Upgrade Now'. This is a known issue that has been resolved.
Another possible reason could be a misconfiguration in the firewall rules or the VLAN settings. I would suggest double-checking the firewall rules and the VLAN configurations. Make sure that the rules are correctly applied for the VLANs are properly isolated.
In case the issue still recurs after implementing the recommendation above, please share with us your Org/ site name and enable Zyxel support by going to Help (On the top of right) > Support Request > Zyxel support Access to enable and save. Additionally, please send us the USG FLEX 200 configuration file and diagnostic file via private message. This will allow us to review your specific firewall rules and any other relevant configurations.
Share your feedback through our survey, make your voice heard, and win a WiFi 7 AP!
0
Categories
- All Categories
- 415 Beta Program
- 2.4K Nebula
- 144 Nebula Ideas
- 94 Nebula Status and Incidents
- 5.6K Security
- 237 USG FLEX H Series
- 267 Security Ideas
- 1.4K Switch
- 71 Switch Ideas
- 1.1K Wireless
- 40 Wireless Ideas
- 6.3K Consumer Product
- 247 Service & License
- 384 News and Release
- 83 Security Advisories
- 29 Education Center
- 10 [Campaign] Zyxel Network Detective
- 3.2K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 83 About Community
- 71 Security Highlight