What suggestions if the Client Policy Limit is not enough?

Options
Zyxel_Bella
Zyxel_Bella Posts: 596
Zyxel Certified Network Engineer Level 2 - Switch Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch 50 Answers
image  Zyxel Employee

Nebula Client Policy is implemented using MAC Filter, the policy entries apply to individual APs and stored on the AP. The current limits are:

  • Allow list: up to 256 entries
  • Block list: up to 512 entries

If your deployment requires managing more clients than these limits, we recommend using MAC Authentication with a RADIUS server instead of relying on Client Policy.

RADIUS-based MAC Authentication is better suited for larger deployments because it provides greater scalability and centralizes client authentication. It can also improve overall manageability, network stability, and security, while providing more flexibility for future authentication, access-control, or analysis requirements.

For environments with a large number of managed clients, MAC Authentication is generally a more scalable solution than simply increasing the Client Policy capacity.