Flex H series - firmware 1.35 - Nebula is mandatory?

GiuseppeR
GiuseppeR Posts: 444  Master Member
Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Engineer Level 1 - Nebula First Comment Friend Collector

Hello everyone,

I'm setting up some new H series, when I config them at the beginning I choose web management instead of Nebula to have all the options but when I have to register the device to a Zyxel Account I see that Nebula enrolls Flex H directly on an ORG on Nebula.

So is it mandatory to have that firewall on Nebula from 1.35 firmware?

Is there a way to use Nebula ONLY to monitor it and to leave the users able to modify its parameters ONLY on premise?

All Replies

  • PeterUK
    PeterUK Posts: 3,939  Guru Member
    100 Answers 2500 Comments Friend Collector Seventh Anniversary

    From what I can tell the FLEX H model support being standalone and Nebula meaning you register but don't have to config by Nebula if you just want to config local.  

  • Zyxel_Tina
    Zyxel_Tina Posts: 132  Zyxel Employee
    Zyxel Certified Network Administrator - Security Zyxel Certified Network Administrator - Switch 25 Answers First Comment

    Hi @GiuseppeR,

    You can choose to begin with the local web GUI for initial configuration. Starting from firmware V1.35, during this initial setup process, the device will prompt you to register it to Nebula and create a Nebula organization and site.

    While this procedure was introduced in V1.35, the hybrid cloud/on-premise architecture has been available since V1.32, which allows configuration and monitoring from both Nebula and the web GUI.

    Due to this unified design, any changes made either on Nebula or via the local GUI will automatically sync across both managements.

    If your goal is to allow Nebula access for monitoring only, we suggest the following:

    • Do not invite users with “Full Admin” privileges to your Nebula Org.
    • Assign the “Read-only Administrator” role to users who should only monitor the device.

    As for local GUI access, you can control who has access to that interface via IP filtering or admin password policies.

    Zyxel Tina

  • GiuseppeR
    GiuseppeR Posts: 444  Master Member
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Engineer Level 1 - Nebula First Comment Friend Collector
    edited August 11

    Hi @Zyxel_Tina

    as per your confirmation, starting from 1.35, Flex H series firewalls have to have at least 1 full admin on Nebula where each firewall is assigned to with the initial configuration.

    Have I understood it correctly?

    As for the local GUI I see that Flex H series are similar to FLEX/ATP "old" ones.

  • Zyxel_Tina
    Zyxel_Tina Posts: 132  Zyxel Employee
    Zyxel Certified Network Administrator - Security Zyxel Certified Network Administrator - Switch 25 Answers First Comment

    Hi @GiuseppeR,

    Yes, you have understood it correctly.

    Whether in on-premise mode or Nebula mode, the device owner and the org. owner will be the same admin.

    Zyxel Tina