[2026 August Notification] Set Up Passkeys Login for Firewall Captive Portal and SSL VPN with NID FS

Options
Zyxel_Bruce
Zyxel_Bruce Posts: 24 image  Zyxel Employee
Fifth Anniversary
edited August 6 in Security Highlight
[NCCSR] Community Post Banner_600x200.png

Nebula Identity Federation Service (NID FS) brings network access into the same identity-driven model used by cloud applications, helping IT teams manage authentication consistently across network services.

This tutorial shows how one organization-level NID FS configuration can provide Nebula Cloud Authentication Server (NCAS) authentication for both Firewall Captive Portal and SSL VPN, eliminating separate sign-in setups for each service. An IT administrator enables NID FS, adds NCAS as an identity source, configures both services, and grants the required user privileges. Each end user then registers a Passkey once and uses it to sign in to both services without entering a password.

🎯What You’ll Learn

IT Administrator Configuration

Step

What You’ll Do

1

Enable NID FS and Add NCAS

2

Configure the Firewall Captive Portal to use NID FS

3

Configure SSL VPN to Use NID FS

4

Authorize NCAS Users for Both Services

5

Create an NCAS User

End-User Enrollment and Login Experience

Step

What You’ll Do

6

Register a Passkey

7

Sign In to the Firewall Captive Portal with an NCAS Passkey

8

Sign In to SSL VPN with an NCAS Passkey

🧑‍💻IT Administrator Configuration

Complete the following steps in Nebula to configure NID FS, network access policies, and NCAS users before end users connect to the network.

Step 1 - Enable NID FS and add NCAS

In NCC, go to Organization-wide > Organization-wide manage > Nebula identity federation service.

  1. Turn on Enable.
  2. On the Identity provider tab, click Add.
  3. Enter a descriptive Name, such as NCAS.
  4. For Type, select NCAS.
  5. Click Create, then save the page when prompted.
image.png

Step 2 - Configure the firewall captive portal to use NID FS

  1. Go to Site-wide > Configure > Firewall > Captive portal
  2. On the Authentication Policy tab, click Add.
  3. Turn on Enable and enter a policy Name.
  4. Under Criteria, select the incoming interface, source address, and destination address to which the policy applies.
image.png

Under Sign-in method, select Sign-on with, then choose Nebula identity federation service. Click Save to take effect.

image.png

Don't forget to enable it.

image.png

.Step 3 - Configure SSL VPN to use NID FS

  1. Go to Site-wide > Configure > Firewall > Remote access VPN
  2. Enable SSL VPN Server
  3. For Sign-on with, select Nebula Identity Federation Service
  4. Click Save. After synchronization, download the SSL VPN configuration for the supported VPN client.
  5. Download the SSL VPN configuration file and provide this file to the authorized end user.
image.png

Step 4 - Authorize NCAS users for both services

Creating the identity provider is not enough by itself. A user privilege policy maps the NCAS identity source to the captive portal and SSL VPN services that NCAS users are allowed to access.

  1. Return to Organization-wide > Organization-wide manage > Nebula identity federation service
  2. Open the User privilege tab and click Add.
  3. In Select user, enter a Policy name and select NCAS as the Source IdP.
  4. For Principle type, choose All users, or choose the option for a specified user list if access must be limited.
image.png

In Select service, choose Customize the allowed services for IdP. Select the target site, then select the firewall captive portal policy and the Remote Access VPN service.

image.png

Review the Summary, click Create, and save the page.

image.png

Step 5 - Create an NCAS user

  1. Go to Organization-wide > Organization-wide manage > Nebula cloud authentication server
  2. On the User tab, click Add.
  3. Enter the user's email address, username, optional description, and a strong temporary password.
  4. Under Authorized, choose All sites or the specific sites that the user is allowed to access. Do not leave the account as Not authorized.
  5. Choose whether the user signs in with an email address, username, or both.
image.png

Click Create user, then save the page.

🙋‍♂️End-User Login Experience

The administrator configuration is now complete. The following steps show how an end user connects to the network and signs in through the NID FS Portal using an NCAS Passkey.

Step 6 - Register a passkey

The NCAS user completes the Passkey enrollment; the administrator does not create or have access to the user’s Passkey. Each NCAS user only needs to register a Passkey once. The registered Passkey can then be used to sign in to both the Firewall Captive Portal and SSL VPN. Follow the steps below to complete the registration.

Open the NCAS account email and follow the account-management link.

linktomanage.png

Sign in with the NCAS email address or username and the temporary password.

image.png

On the account page, scroll to Security > Set up passkeys and click Add Passkey.

image.png

Follow the prompt. Depending on the device, confirm with a PIN, fingerprint, face recognition, security key, or a passkey provider.

image.png

When prompted, give the passkey a recognizable name and confirm the registration.

image.png

Verify that the passkey appears under Set up passkeys.

image.png

Step 7 - Sign in to the firewall captive portal with the NCAS passkey

  1. Connect the user's computer to the designated network by plugging in the Ethernet cable. The browser opens automatically and redirects the user to the Captive Portal.
  2. On the NID FS portal, select NCAS
image.png

On the Nebula Cloud Authentication Service page, click Continue with Passkey.

image.png

Approve the browser or operating-system passkey prompt.

image.png

After successful verification, the firewall captive portal displays the success page and applies.

image.png

Step 8 - Sign in to SSL VPN with the NCAS passkey

Before you begin, install OpenVPN Connect and import the SSL VPN configuration file provided by your IT administrator.

Open OpenVPN Connect and click Connect.

vpn_connect.png

When Authentication required appears, continue in the system browser. If the browser does not open automatically, use the displayed URL or click Retry. On the Nebula Identity Federation Service portal, select NCAS.

image.png

On the Nebula Cloud Authentication Service page, click Continue with Passkey.

image.png

Approve the browser or operating-system passkey prompt.

image.png

When the browser displays "Access granted," verify that OpenVPN Connect shows as connected.

vpn_connect_success.png

✅Validation checklist

  • NID FS is enabled, and NCAS appears on the Identity provider tab.
  • The captive portal policy uses Nebula identity federation service as its sign-on method.
  • SSL VPN Server is enabled, and its Sign-on with field is set to Nebula identity federation service.
  • The user privilege policy includes the intended captive portal policy and Remote Access VPN service.
  • The NCAS user is authorized for the correct site
  • The passkey is listed in the user's NCAS account and can be used to complete the browser or device verification prompt.
  • The captive portal flow reaches the success page after passkey authentication.
  • The VPN client reaches Connected after browser-based passkey authentication.

🗨️We’d Love Your Feedback

Try it out and let us know how it goes. Share your questions, feedback, or suggestions in the comments below.