GS1920-8HP as a WAN Switch - Connect to Nebula Cloud

DialectFalun79177
DialectFalun79177 Posts: 3  Freshman Member
First Comment Third Anniversary

Is it possible to get a WAN Switch GS1920-8HP to communicate with Nebula if it is placed before the firewall? We have a total of 15 WAN IP addresses, but there are available addresses. Should the switch be configured with a public static WAN IP, or is there another way to do it?

Accepted Solution

  • Zyxel_Kay
    Zyxel_Kay Posts: 1,210  Zyxel Employee
    Zyxel Certified Network Engineer Level 2 - Nebula Zyxel Certified Network Engineer Level 2 - WLAN Zyxel Certified Network Engineer Level 2 - Switch Zyxel Certified Network Engineer Level 2 - Security
    edited September 26 Answer ✓

    Hi @DialectFalun79177

    Yes, it’s possible to connect the GS1920-8HP to Nebula CC even if it’s placed before the firewall. Assigning a static public IP to the switch will work, but make sure the switch can ping the default gateway to ensure proper communication with Nebula Cloud.

    Additionally, after registering the switch to Nebula CC, you’ll need to configure the static public IP, subnet mask, and gateway on Nebula CC. If these settings are not configured on Nebula, the default Nebula settings will override the switch's local settings once it connects to the cloud.

    Feel free to reach out if you need further assistance!

    Update:

    We recommend limiting access to the Nebula switch for improved security. You can follow this guide to block local access (HTTP, HTTPS, FTP, SSH, Telnet) on Nebula switches:
    How to Block Local Access (HTTP, HTTPS, FTP, SSH, Telnet) on Nebula Switches — Zyxel Community

    Kay

    See how you've made an impact in Zyxel Community this year! https://bit.ly/Your2024Moments_Community

All Replies

  • Zyxel_Kay
    Zyxel_Kay Posts: 1,210  Zyxel Employee
    Zyxel Certified Network Engineer Level 2 - Nebula Zyxel Certified Network Engineer Level 2 - WLAN Zyxel Certified Network Engineer Level 2 - Switch Zyxel Certified Network Engineer Level 2 - Security
    edited September 26 Answer ✓

    Hi @DialectFalun79177

    Yes, it’s possible to connect the GS1920-8HP to Nebula CC even if it’s placed before the firewall. Assigning a static public IP to the switch will work, but make sure the switch can ping the default gateway to ensure proper communication with Nebula Cloud.

    Additionally, after registering the switch to Nebula CC, you’ll need to configure the static public IP, subnet mask, and gateway on Nebula CC. If these settings are not configured on Nebula, the default Nebula settings will override the switch's local settings once it connects to the cloud.

    Feel free to reach out if you need further assistance!

    Update:

    We recommend limiting access to the Nebula switch for improved security. You can follow this guide to block local access (HTTP, HTTPS, FTP, SSH, Telnet) on Nebula switches:
    How to Block Local Access (HTTP, HTTPS, FTP, SSH, Telnet) on Nebula Switches — Zyxel Community

    Kay

    See how you've made an impact in Zyxel Community this year! https://bit.ly/Your2024Moments_Community

  • DialectFalun79177
    DialectFalun79177 Posts: 3  Freshman Member
    First Comment Third Anniversary

    Thanks.
    I will try to configure the switch locally, then when all the staff are not in the office.
    Most likely the switch can update the firmware and I don't want to cause interruptions in the connections for the colleagues :-)
    I have already entered the WAN-Ip it should have in Nebula

  • Zyxel_Kay
    Zyxel_Kay Posts: 1,210  Zyxel Employee
    Zyxel Certified Network Engineer Level 2 - Nebula Zyxel Certified Network Engineer Level 2 - WLAN Zyxel Certified Network Engineer Level 2 - Switch Zyxel Certified Network Engineer Level 2 - Security

    Hi @DialectFalun79177

    For security reasons, we don't recommend placing the switch directly on the WAN side with public IP address, as this could expose it to the Internet which has potential attacks and risk the switch going down. Instead, we suggest placing a firewall before the switch and configuring a VLAN segment for enhanced network security.

    If you really need to place your switch above your firewall for some reason, we recommend configuring your switch as follows to segment your network:

    1. First, connect a firewall before the switch and allow the switch to establish a connection to Nebula Control Center (CC).
    2. Once the switch is online in Nebula CC, configure the switch port as shown above, and wait for the configuration to be updated.
    3. After that, you can reconnect the switch as illustrated in the diagram.

    Kay

    See how you've made an impact in Zyxel Community this year! https://bit.ly/Your2024Moments_Community

Nebula Tips & Tricks