H Series Captive Portal with NID FS Integration
Zyxel Employee
Identity Federation for Captive Portals
The USG Flex H series now supports Captive Portal authentication integrated with Zyxel's Nebula Identity Federation Service (NID FS ). This allows for a more streamlined authentication flow using external Identity Providers (IdPs) like Google Workspace, Microsoft Entra ID, or Zyxel's Nebula Cloud Authentication Server (NCAS).
Authentication Flow
In this architecture, the firewall acts as an authentication proxy. When a user attempts to access the internet, they are redirected to the IFS service portal. Users then select their preferred IdP, complete the login process, and the IFS redirects them back to the firewall with the necessary credentials to grant access.

Configuration in Nebula
Administrators must first configure the IdP and User Privileges in Nebula.


In the local firewall settings, the "Sign on with" method is set to NID FS. A unique FQDN is assigned to each organization for the IFS service portal.

Certificate Management
To prevent browser security warnings during redirection, Nebula automatically provisions an "Auto" certificate for the firewall. This certificate matches the redirection FQDN, ensuring a seamless and secure user experience without manual certificate installation.
Categories
- All Categories
- 442 Beta Program
- 3.1K Nebula
- 237 Nebula Ideas
- 6.8K Security
- 740 USG FLEX H Series
- 376 Security Ideas
- 1.8K Switch
- 87 Switch Ideas
- 1.5K Wireless
- 58 Wireless Ideas
- 7.2K Consumer Product
- 319 Service & License
- 512 News and Release
- 99 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 5.3K FAQ
- 34 Documents
- 91 About Community
- 119 Security Highlight