Flex H series - firmware 1.35 - Nebula is mandatory?
 
             Master Member
  Master Member 
         
         
             
         
         
             
         
         
             
         Hello everyone,
I'm setting up some new H series, when I config them at the beginning I choose web management instead of Nebula to have all the options but when I have to register the device to a Zyxel Account I see that Nebula enrolls Flex H directly on an ORG on Nebula.
So is it mandatory to have that firewall on Nebula from 1.35 firmware?
Is there a way to use Nebula ONLY to monitor it and to leave the users able to modify its parameters ONLY on premise?
Accepted Solution
- 
            Hi @GiuseppeR, You can choose to begin with the local web GUI for initial configuration. Starting from firmware V1.35, during this initial setup process, the device will prompt you to register it to Nebula and create a Nebula organization and site. While this procedure was introduced in V1.35, the hybrid cloud/on-premise architecture has been available since V1.32, which allows configuration and monitoring from both Nebula and the web GUI. Due to this unified design, any changes made either on Nebula or via the local GUI will automatically sync across both managements. If your goal is to allow Nebula access for monitoring only, we suggest the following: - Do not invite users with “Full Admin” privileges to your Nebula Org.
- Assign the “Read-only Administrator” role to users who should only monitor the device.
 As for local GUI access, you can control who has access to that interface via IP filtering or admin password policies. Zyxel Tina 0
All Replies
- 
            From what I can tell the FLEX H model support being standalone and Nebula meaning you register but don't have to config by Nebula if you just want to config local. 0
- 
            Hi @GiuseppeR, You can choose to begin with the local web GUI for initial configuration. Starting from firmware V1.35, during this initial setup process, the device will prompt you to register it to Nebula and create a Nebula organization and site. While this procedure was introduced in V1.35, the hybrid cloud/on-premise architecture has been available since V1.32, which allows configuration and monitoring from both Nebula and the web GUI. Due to this unified design, any changes made either on Nebula or via the local GUI will automatically sync across both managements. If your goal is to allow Nebula access for monitoring only, we suggest the following: - Do not invite users with “Full Admin” privileges to your Nebula Org.
- Assign the “Read-only Administrator” role to users who should only monitor the device.
 As for local GUI access, you can control who has access to that interface via IP filtering or admin password policies. Zyxel Tina 0
- 
            Hi @Zyxel_Tina as per your confirmation, starting from 1.35, Flex H series firewalls have to have at least 1 full admin on Nebula where each firewall is assigned to with the initial configuration. Have I understood it correctly? As for the local GUI I see that Flex H series are similar to FLEX/ATP "old" ones. 0
- 
            Hi @GiuseppeR, Yes, you have understood it correctly. Whether in on-premise mode or Nebula mode, the device owner and the org. owner will be the same admin. Zyxel Tina 0
Categories
- All Categories
- 439 Beta Program
- 2.8K Nebula
- 199 Nebula Ideas
- 125 Nebula Status and Incidents
- 6.3K Security
- 492 USG FLEX H Series
- 322 Security Ideas
- 1.6K Switch
- 83 Switch Ideas
- 1.3K Wireless
- 47 Wireless Ideas
- 6.8K Consumer Product
- 285 Service & License
- 455 News and Release
- 89 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 4.3K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 85 About Community
- 95 Security Highlight

 
          
          
         
 Guru Member
  Guru Member 
          
          
          
                     
                     
                     
                    