Why is the firewall grayed out(can not be disabled) in the Wi-Fi SSD settings?

Options

In Zyxel Nebula, the reason a firewall, "Guest Network" block, or certain security options (such as Layer 2 Isolation / local firewall rules) are grayed out or restricted in your Wi-Fi SSID settings usually comes down to one of two common configuration conflicts:

1. The SSID is running in "NAT Mode"

If you have set up your SSID with the IP addressing set to NAT mode (where the AP acts as a DHCP server and hands out local IP addresses in the 10.X.X.X range to wireless clients), certain advanced traffic filtering and firewall features become grayed out.

  • Why this happens: In NAT mode, the AP automatically isolates the clients and translates all client traffic to use the AP’s own physical IP address. Because of this automatic isolation and translation, additional manual Layer 2 isolation/firewall control settings on the SSID level are disabled.
  • How to fix: If you need manual firewall control or Layer 2 Isolation rules, change the IP addressing setting of that SSID back to Bridge mode.

2. Licensing Requirements (Pro Pack vs. Base Pack)

Certain granular SSID firewall settings, advanced client-filtering policies, or security features require a Nebula Pro Pack license.

  • If your site is currently running on the free Base Pack, some of these advanced security toggles will appear in the GUI but will be grayed out.