Captive Portal Customization After Nebula 20.10 Update

Options
Zyxel_Bella
Zyxel_Bella Posts: 596
Zyxel Certified Network Engineer Level 2 - Switch Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch 50 Answers
image  Zyxel Employee
edited 7:51AM in SSID

After the Nebula 20.10 update, you might notice that your guest Wi-Fi captive portal, especially when using Nebula Cloud Authentication, no longer displays custom branding like logos and colors. Instead, it redirects to a generic authentication page.

  1. Understanding the New Authentication Flow

    • Nebula 20.10 introduces a modernized authentication flow for the Nebula Cloud Authentication Server (NCAS), based on OIDC (OpenID Connect). This new flow redirects clients to an authentication page hosted by the Nebula Identity Federation Service (IFS)/NCAS, replacing previous local captive portal pages.
    • This change is part of an effort to standardize authentication and align with current security architecture.
  2. Customization Options with NCAS

    • With the modernized NCAS flow, direct theme customization, including adding a custom logo, is only supported for specific authentication methods:
      • Click-to-Continue
      • Voucher
      • Sign-in with My RADIUS Server
  3. Firmware Version Considerations

    • The updated NCAS captive portal behavior is observed when your Nebula organization is at version 20.10 and the Access Point (AP) firmware is 7.40 P1 or newer.
    • If your AP firmware is older than 7.40 while Nebula is at 20.10, users might still be directed to the older captive portal page.
  4. Actionable Advice

    • If a custom logo or specific branding is essential for your guest Wi-Fi experience, review your current authentication method.
    • Consider switching to one of the supported methods (Click-to-Continue, Voucher, or Sign-in with My RADIUS Server) to enable custom branding.