Unjustified connections NWA50AX PRO access point

Options
c777
c777 Posts: 14 image  Freshman Member
First Comment Friend Collector Third Anniversary

Hello,

I purchased an NWA50AX PRO access point and configured it in standalone mode right out of the box, with update the latest firmware V7.10 (3) It works very well, no complaints on that front.

However, I am seeing some very surprising connections for a standalone device. It is connected to a firewall with Suricata on its interface, which is not happy.

image.png

I have a log on the access point that mentions a Nebula connection on TCP port 4335.

image.png

I think that in standalone mode, it shouldn't connect or be joined by other services such as ntp, update...

I never registered this access point on a Nebula portal.

Maybe there is a service running in the background. Can you help me shut it down properly and permanently?

Thank you.

Best regards,

Best Answers

  • PeterUK
    PeterUK Posts: 4,272 image  Guru Member
    250 Answers 2500 Comments Friend Collector Eighth Anniversary
    Answer ✓

    The following SSH disable this:

    configure terminal
    netconf inactivate
    write

    to undo it

    no netconf inactivate
    write
    
  • Zyxel_Tina
    Zyxel_Tina Posts: 471 image  Zyxel Employee
    Zyxel Certified Network Administrator - Security Zyxel Certified Network Administrator - Switch 100 Answers First Comment
    Answer ✓

    Hi @c777,

    Based on the screenshots you shared, both service port 4335 and 6667 are used in TCP for Nebula Cloud Management(NETCONF). You may check the status through ZON utility. If it is enabled, please check the Disable NCC Discovery box to prevent Nebula connection attempts.

    This option is available if the selected device supports NCC discovery. You must have Internet access to use this feature. Use this icon on the selected device to disable the NCC discovery feature.

    image.png

    Another method is to run the commands via SSH as mentioned by @PeterUK.

    However, if the status is already disabled, please provide us with the diagnostic info file via private message so we can investigate further.

    Zyxel Tina

All Replies