Why my Customized Logo disappear after Nebula 20.10?

Options
Zyxel_Bella
Zyxel_Bella Posts: 596
Zyxel Certified Network Engineer Level 2 - Switch Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch 50 Answers
image  Zyxel Employee
edited 7:57AM in SSID

After the Nebula 20.10 update, the customization of captive portals, especially for those using Nebula Cloud Authentication Server (NCAS), has changed significantly. The new authentication flow, based on OIDC, redirects users to a modern IFS/NCAS hosted authentication page, which affects how portals can be branded. Please check:

  • 1. Understanding the New Authentication Flow

    • With Nebula 20.10 and AP firmware version 7.40 P1 or newer, the Nebula Cloud Authentication Server (NCAS) now uses a modernized authentication process based on OIDC (OpenID Connect).
    • This change means clients are redirected to an authentication page hosted by the Nebula Identity Federation Service (IFS) or NCAS, rather than a local captive portal page.
    • Consequently, the visual appearance and customization options for this new NCAS authentication page are now standardized.
  • 2. Captive Portal Customization Limitations and Supported Methods

    • Direct theme customization, including the addition of a custom logo, is generally not supported for the default Nebula Cloud Authentication Server (NCAS) method under the new flow.
    • However, if a custom logo and other branding elements are essential for your captive portal, you can achieve this by switching to one of the following authentication methods:
      • Click-to-Continue
      • Voucher
      • Sign-in with My RADIUS Server
  • 3. Behavior with Older AP Firmware Versions

    • It is important to note that if your Nebula environment is running Nebula 20.10 but your AP firmware is older than version 7.40, end-users may still see the old captive portal page. The new OIDC-based flow and its associated page are primarily visible with AP firmware version 7.40 P1 and above.