How to Set Up Nebula Hub-and-Spoke VPN and the USG FLEX H series model as the Hub site?

Zyxel_Jeff
Zyxel_Jeff Posts: 1,317  Zyxel Employee
100 Answers 500 Comments Friend Collector Fourth Anniversary

This example shows how to use the USG FLEX H series model to establish Hub-and-Spoke VPN tunnel between Nebula firewalls (USG FLEX/ATP series models). It explains how to configure the Nebula Site-to-Site VPN using the Nebula Control Center. Once the Hub-and-Spoke VPN tunnel is established, LAN hosts can communicate with each other through the VPN tunnel seamlessly.

image-908753121a8f-5c4e.png

Set Up the Hub-and-Spoke VPN settings on the Nebula Firewall

On Nebula Control Center, navigate to Side-wide > Configure > Firewall > Site-to-Site VPN > Configure the Primary interface, Secondary interface (backup interface), on the local networks, enabling the interface will require routing through the VPN. Enable the Nebula VPN and choose the Hub-and-Spoke VPN topology and ensure that the USG FLEX H series is set as the Hub site.

USG FLEX H series site

image-37e7d0cc41989-6b05.png

USG FLEX/ATP series site

image-da4c4a20a116d-8b8b.png

Verify The VPN Connection

Navigate to Side-wide > Firewall > VPN connections to check the site-to-site VPN connection was connected successfully on both sites.

image-a582dc3c78012-2ed8.png

image-9fb86229d75a2-2406.png

Navigate to the Web-GUI path VPN Status > IPsec VPN > Site to Site VPN of the USG Flex H series model to check the Nebula VPN connection was connected successfully.

image-998f17ce7a651-12dc.png
Tagged: