Nebula rollback options in case of malicious admin action

Options
henriquev
henriquev Posts: 19 image  Freshman Member
First Comment Friend Collector

Hello,

We manage a Nebula deployment with 200+ sites and expect to add 600+ more. We’d like to understand what recovery options exist if an administrator with malicious intent deletes all sites and backups.

Specifically:

  • Is there a rollback or restore mechanism for Nebula itself?
  • If needed, can Zyxel support assist with a rollback?

Accepted Solution

  • Zyxel_Melen
    Zyxel_Melen Posts: 4,134 image  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate
    Answer ✓

    Hi @henriquev

    1. No rollback or restore option on Nebula.
    2. We will assist in recovering. (Might not fully recover)

    May I know if you need any assist now?

    Zyxel Melen


All Replies

  • Zyxel_Melen
    Zyxel_Melen Posts: 4,134 image  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate
    Answer ✓

    Hi @henriquev

    1. No rollback or restore option on Nebula.
    2. We will assist in recovering. (Might not fully recover)

    May I know if you need any assist now?

    Zyxel Melen


  • GiuseppeR
    GiuseppeR Posts: 539 image  Master Member
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Engineer Level 1 - Nebula First Comment Friend Collector

    Hi @Zyxel_Melen

    I think that this request of @henriquev is really interesting.

    To avoid issues I give read only permissions and read-write when it is needed, anyway it is something stressful because you have to remember to restrict again permissions.

    It would be sufficient to use a similar way to the snapshots of VMs: the owner of the ORG can save some snapshots of all of his ORG, when he wants to or scheduled time, and revert back at some snapshots in the past to get back all config ok.

    You just did something similar with H series firewall:

    immagine.png
  • henriquev
    henriquev Posts: 19 image  Freshman Member
    First Comment Friend Collector

    We are very strict with write permission as well, there is an issue though that to change a site label/tag you have to have write permission in the organization. With 200+ sites, I have to waste my time changing label when needed or drop this feature altogether

  • GiuseppeR
    GiuseppeR Posts: 539 image  Master Member
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Engineer Level 1 - Nebula First Comment Friend Collector

    On Nebula I see only "Read" and "ReadWrite" option for users.

    Unfortunately no topology on which permission you can give to others.

  • Zyxel_Melen
    Zyxel_Melen Posts: 4,134 image  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate

    Well, since the delete site and backup (configuration management) are org level function, some of admin you can give them only site privilege (org privilege is none) to private potential risks.

    Zyxel Melen


Nebula Tips & Tricks