H Series SSL VPN with NID FS Support

Options
Zyxel_Lynn
Zyxel_Lynn image  Zyxel Employee
5 Answers First Comment Friend Collector First Anniversary
edited August 17 in Other Topics

Modernizing Remote Access

Zyxel has expanded NID FS support to SSL VPN connections for the H series firewalls. This integration enables the use of modern OIDC-based authentication for remote workers.

OpenVPN Connect Support

Because the standard SecuExtender software does not yet support OIDC/NID FS, this feature is specifically designed for use with the OpenVPN Connect client. The connection is initiated in the OpenVPN software, which then triggers the system's default web browser to open the NID FS login page.


Redirection and Certificates

Successful authentication requires the firewall to have a valid redirection endpoint. For SSL VPN, the firewall can automatically request a certificate from Let's Encrypt based on the site's domain name. This requires the firewall to have a public IP address to pass the HTTP-01 challenge. If a private IP is used, the firewall falls back to a default certificate.

User Privileges

Access control is managed through the "User Privilege" settings in the Nebula Control Center (NCC). Administrators can define which authenticated NID FS users or groups are permitted to use the SSL VPN service.