Nebula Assigned Domain Name
Zyxel Employee
To streamline secure remote access, USG FLEX H Series Firewall now supports Nebula-assigned domain names. This feature provides each Nebula-managed firewall with a unique, auto-generated FQDN, making it easier to set up and manage Remote Access VPN connections.
In this article, we’ll explore what the Nebula-assigned domain name is, how it works, and how you can configure binding addresses for different deployment scenarios.
1. What Is a Nebula-Assigned Domain Name?
Each Nebula-managed firewall is automatically assigned a unique domain name (e.g., abc123.zyxelcloud.net) by the Nebula Control Center (NCC). This domain is:
- Bound to your firewall’s IP address
Used for Remote Access VPN services such as IPSec VPN and SSL VPN
2. Where to Configure It
This setting is only available in Nebula and cannot be modified through the local firewall GUI.
To find the setting:
- Navigate to Site-wide > Configure > Firewall > Remote access VPN
You’ll also see an option to choose or change the binding address - this determines which interface or IP the domain name points to.
3. Binding Address Options
The Binding Address defines which IP address the Nebula-assigned domain name will resolve to. You have several options:
Auto (Default)
- The domain name resolves to the IP address used to connect to Nebula
- Ideal for most setups with a single internet-facing interface
Specific Interface (e.g., Ge1, Ge2)
- You can bind the domain to a specific WAN interface IP
- Useful when managing multiple WAN connections
Custom IP Address
- Manually define a public IP address
- Perfect for setups with static public IPs or multi-WAN scenarios
Example Binding Scenarios:
When clients perform a DNS lookup for the assigned domain (e.g., using nslookup), the returned IP address depends on the binding address configuration:
- Auto: IP used for Nebula connectivity (usually public)
- Interface (e.g., GU1): IP of the selected interface (may be private if NAT is involved)
- Custom: The manually specified public IP
This gives you control over which address is published to DNS for VPN access
4. Certificate Binding for VPN
Importing Nebula Assigned Domain Name Certificate:
- NebulaRemoteAccessDefaultCert is uploaded to firewall after firewall has successfully onboarded with NCC
- This certificate is used by Auto certificate validation when VPN Server Address has Nebula Assigned Domain Name selected
You may also manually configure the certificate if needed.
Categories
- All Categories
- 439 Beta Program
- 2.8K Nebula
- 202 Nebula Ideas
- 127 Nebula Status and Incidents
- 6.3K Security
- 515 USG FLEX H Series
- 328 Security Ideas
- 1.7K Switch
- 84 Switch Ideas
- 1.3K Wireless
- 49 Wireless Ideas
- 6.9K Consumer Product
- 288 Service & License
- 458 News and Release
- 90 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 4.3K FAQ
- 34 Documents
- 85 About Community
- 97 Security Highlight

