Captive Portal Support on USG FLEX Lite 60AX in Nebula 19.10

Zyxel_Lynn
Zyxel_Lynn Posts: 71  Zyxel Employee
5 Answers First Comment Friend Collector

With the release of Nebula 19.10, Zyxel introduces captive portal support for the USG FLEX Lite 60AX. While originally designed for small office/home office (SOHO) deployments, the USG FLEX Lite 60AX has quickly gained traction among small businesses, particularly in the EU, as an affordable all-in-one solution that combines firewall protection with basic WiFi access point capabilities.

To meet small business needs, especially in hospitality and retail environments, the USG FLEX Lite 60AX now supports captive portal, enabling organizations to provide WiFi with terms of use or hotspot-style login options.

Why Captive Portal Matters for Small Business

Captive portal is a common requirement for businesses offering public or semi-public WiFi, such as:

  • Cafés, restaurants, and retail stores – Customers must agree to terms before using the internet.
  • Small offices – Businesses can control access and improve compliance.
  • Hospitality venues – Hotspot-style login improves the guest experience.

For these environments, captive portal provides both access control and a chance to present business terms or branding before users connect.

Unified SSID Settings with Access Points

When added to a Nebula site, the SSID settings on the USG FLEX Lite 60AX are identical to those of access points.

  • Any SSID created in advanced mode will apply to both APs and the USG Lite.
  • In 19.10, enabling captive portal in SSID settings now activates captive portal on both APs and the USG FLEX Lite 60AX.

This ensures a consistent login experience across wireless networks, whether clients are connected to the firewall or a standalone AP.

Supported Captive Portal Methods

The USG FLEX Lite 60AX supports most of the same sign-in methods as Zyxel APs, with some limitations.

Supported Methods

  • Click-to-continue
  • Voucher sign-on
  • Nebula Cloud Authentication (NCS sign-on)
  • Microsoft Entra ID (Azure AD) sign-on

Not Supported on USG FLEX Lite 60AX

  • Sign-on with RADIUS
  • Sign-on with Facebook

If you configure RADIUS or Facebook sign-on for an SSID, the entire SSID will be disabled on the USG FLEX Lite 60AX. While Facebook sign-on is rarely used today, RADIUS may still be relevant for some enterprise setups. However, it is unlikely to be a major requirement for the small-business environments where this model is most commonly deployed.

Scope of Captive Portal Authentication

  • Applies to wireless clients only:
    Wireless devices connecting to the USG FLEX Lite 60AX will be redirected to the captive portal landing page.
  • Does not apply to wired clients:
    Devices connected directly via Ethernet to the firewall bypass captive portal authentication.

This scope aligns with the typical use case—wireless guest access in small businesses.

In sum, with Nebula 19.10, the USG FLEX Lite 60AX gains captive portal support, making it more suitable for small businesses that want to provide guest WiFi with access control.

Key points

  • Unified SSID settings across APs and the USG Lite.
  • Captive portal now works on the firewall itself, not just APs.
  • Most sign-in methods supported, except RADIUS and Facebook.
  • Only wireless clients are redirected for authentication.

This enhancement helps businesses deliver a professional, secure, and user-friendly WiFi experience, without needing a dedicated enterprise-grade controller.