How to Set Up Nebula Hub-and-Spoke VPN and the USG FLEX H series model as the Hub site?

Zyxel_Jeff
Zyxel_Jeff Posts: 1,316  Zyxel Employee
100 Answers 500 Comments Friend Collector Fourth Anniversary

This example shows how to use the USG FLEX H series model to establish Hub-and-Spoke VPN tunnel between Nebula firewalls (USG FLEX/ATP series models). It explains how to configure the Nebula Site-to-Site VPN using the Nebula Control Center. Once the Hub-and-Spoke VPN tunnel is established, LAN hosts can communicate with each other through the VPN tunnel seamlessly.

Set Up the Hub-and-Spoke VPN settings on the Nebula Firewall

On Nebula Control Center, navigate to Side-wide > Configure > Firewall > Site-to-Site VPN > Configure the Primary interface, Secondary interface (backup interface), on the local networks, enabling the interface will require routing through the VPN. Enable the Nebula VPN and choose the Hub-and-Spoke VPN topology and ensure that the USG FLEX H series is set as the Hub site.

USG FLEX H series site

USG FLEX/ATP series site

Verify The VPN Connection

Navigate to Side-wide > Firewall > VPN connections to check the site-to-site VPN connection was connected successfully on both sites.

Navigate to the Web-GUI path VPN Status > IPsec VPN > Site to Site VPN of the USG Flex H series model to check the Nebula VPN connection was connected successfully.

Tagged: