How to configure security policy on USG FLEX H on Nebula?

Zyxel_Emily
Zyxel_Emily Posts: 1,413  Zyxel Employee
Zyxel Certified Network Administrator - Security Zyxel Certified Sales Associate 100 Answers 1000 Comments
edited April 11 in Networking

Security Policy

A security policy is a template of security settings that can be applied to specific traffic at specific times. The policy can be applied:
to a specific direction of travel of packets (from/to)
to a specific source and destination address objects
to a specific type of traffic (services)
to a specific user or group of users
at a specific schedule

Sometimes, we may need to access a device via SSH for troubleshooting purpose. This example illustrates how to configure security policy on Nebula to allow SSH service from a specific IP address or Geo IP to USG FLEX H.

image.png

Configuration
On Nebula, go to Configure > Firewall > Security policy. Click +Add to add a new security policy rule.

Action: Allow
From: WAN
To: ZyWALL
Source: Allowed IP address or Geo IP
Service: SSH

image.png

You can login to the web GUI and go to Security Policy > Policy Control to check if the security policy rule is added correctly to USG FLEX H.

Note: Make sure "Enable" is turned on.

image.png image.png

Verification
Access the USG FLEX H via SSH from wan IP address.

image.png