H Series and Nebula Security Policy rule limitations?

Ratsnackbar
Ratsnackbar Posts: 26  Freshman Member
First Comment First Anniversary

What is the maximum number of Rules allowed in the Security Policy in Nebula for each H Series Device?

Best Answers

  • PeterUK
    PeterUK Posts: 3,987  Guru Member
    100 Answers 2500 Comments Friend Collector Seventh Anniversary
    Answer ✓

    Max Firewall ACL Rule Number

    50H = 500

    100H = 500

    200H = 2000

    500H = 5000

    700H = 10000

    page 634

    USG FLEX 700H-UG.pdf

  • Zyxel_Tina
    Zyxel_Tina Posts: 179  Zyxel Employee
    Zyxel Certified Network Administrator - Security Zyxel Certified Network Administrator - Switch 50 Answers First Comment
    Answer ✓

    Hi @Ratsnackbar,

    Is that number consistent when used in conjunction with Nebula? For the older Flex series it was not.

    After confirmation, those numbers are consistent with Nebula-managed approach since the H series firewalls has a hybrid cloud/on-premise architecture, which allows configuration and monitoring from both Nebula and the web GUI. Due to this unified design, any changes made either on Nebula or via the local GUI will automatically sync across both managements.

    Zyxel Tina

All Replies

  • PeterUK
    PeterUK Posts: 3,987  Guru Member
    100 Answers 2500 Comments Friend Collector Seventh Anniversary
    Answer ✓

    Max Firewall ACL Rule Number

    50H = 500

    100H = 500

    200H = 2000

    500H = 5000

    700H = 10000

    page 634

    USG FLEX 700H-UG.pdf

  • Ratsnackbar
    Ratsnackbar Posts: 26  Freshman Member
    First Comment First Anniversary

    Is that number consistent when used in conjunction with Nebula? For the older Flex series it was not.

  • PeterUK
    PeterUK Posts: 3,987  Guru Member
    100 Answers 2500 Comments Friend Collector Seventh Anniversary
    edited August 14

    I'm not sure I don't use Nebula as it don't have the full list of settings and their seems to be problem with Nebula and Security policy like I have 133 rules and it seems you can't reorder the rules in Nebula also the add button to make a rule does not work until you click >| to go to the last rules.

  • Ratsnackbar
    Ratsnackbar Posts: 26  Freshman Member
    First Comment First Anniversary

    I'm currently vetting the H Series devices in Nebula and so far it seems to work pretty well. Its still missing some of the security options you'd find in the older versions (CD&R for example) and some of the methods you'd wire your rules seem to need a bit of refinement. But overall I've not run into any show stoppers.

    The older Flex series though had a hard limit of 50 Firewall rules in Nebula regardless of what the devices documentation stated was supported in On-Premise mode. This was due to how the rules were implemented in nebula.

    With the H Series the Security Policies are defined more like they would be in On-Premise mode. I suspect the old limitations are more robust if not gone entirely. But I'm not finding anything definative about it.

    So I guess I will just need to start making rules until it does not allow me too anymore unless someone else knows what the upper limit is. o.O

  • Zyxel_Tina
    Zyxel_Tina Posts: 179  Zyxel Employee
    Zyxel Certified Network Administrator - Security Zyxel Certified Network Administrator - Switch 50 Answers First Comment
    Answer ✓

    Hi @Ratsnackbar,

    Is that number consistent when used in conjunction with Nebula? For the older Flex series it was not.

    After confirmation, those numbers are consistent with Nebula-managed approach since the H series firewalls has a hybrid cloud/on-premise architecture, which allows configuration and monitoring from both Nebula and the web GUI. Due to this unified design, any changes made either on Nebula or via the local GUI will automatically sync across both managements.

    Zyxel Tina

  • Ratsnackbar
    Ratsnackbar Posts: 26  Freshman Member
    First Comment First Anniversary

    Thanks Tina, much appreciated!

Nebula Tips & Tricks