H Series Captive Portal with NID FS Integration

Options
Zyxel_Lynn
Zyxel_Lynn image  Zyxel Employee
5 Answers First Comment Friend Collector First Anniversary
edited August 17 in Other Topics

Identity Federation for Captive Portals

The USG Flex H series now supports Captive Portal authentication integrated with Zyxel's Nebula Identity Federation Service (NID FS ). This allows for a more streamlined authentication flow using external Identity Providers (IdPs) like Google Workspace, Microsoft Entra ID, or Zyxel's Nebula Cloud Authentication Server (NCAS).

Authentication Flow

In this architecture, the firewall acts as an authentication proxy. When a user attempts to access the internet, they are redirected to the IFS service portal. Users then select their preferred IdP, complete the login process, and the IFS redirects them back to the firewall with the necessary credentials to grant access.


Configuration in Nebula

Administrators must first configure the IdP and User Privileges in Nebula. 



In the local firewall settings, the "Sign on with" method is set to NID FS. A unique FQDN is assigned to each organization for the IFS service portal.


Certificate Management

To prevent browser security warnings during redirection, Nebula automatically provisions an "Auto" certificate for the firewall. This certificate matches the redirection FQDN, ensuring a seamless and secure user experience without manual certificate installation.