NWA90AX - Can i block WEB configuration only for wlan interfaces ?

Options
Thierry95
Thierry95 Posts: 3 image  Freshman Member
First Comment
edited December 2025 in Wireless

Hello,

I did see the web server configuration for NWA90AX : Configuration/System/www (standalone mode) with Enable HTTPS/HTTP global options.

but i don't find "how disable WEB configuration for wlan interfaces".

I only want to allow WEB or SSH access via the Ethernet port.

Any solution ?

Bests regards

All Replies

  • PeterUK
    PeterUK Posts: 4,342 image  Guru Member
    250 Answers 2500 Comments Friend Collector Eighth Anniversary
    edited December 2025

    Don't think there is a way to do that.

    But what does work is Management VLAN ID is other then your WLAN and uncheck As Native VLAN.

    Note you need to setup on your router a VLAN subnet as tag for the AP Management to connect too

  • Thierry95
    Thierry95 Posts: 3 image  Freshman Member
    First Comment

    Thank you.

    It's a shame, some access points offer this option. I'll try configuring it by managing multiple VLANs.

    It would be great if this option were available in the future.

    Alternatively, is it possible to restrict web/SSH administration to a single client? (IP access list)

  • Zyxel_Tina
    Zyxel_Tina Posts: 529 image  Zyxel Employee
    Zyxel Certified Network Administrator - Security Zyxel Certified Network Administrator - Switch 100 Answers 500 Comments

    Hi @Thierry95,

    Welcome to the Zyxel Community!

    On the NWA90AX in standalone mode, there isn't a direct setting to disable web configuration only for WLAN interfaces while keeping it enabled for Ethernet.

    The web GUI access is tied to the device’s management IP, and the settings under Configuration > System > www only control global HTTP/HTTPS access, not interface-specific access.

    If you want to restrict web configuration access to wired clients only, please consider:

    1. Network design – Design your network so that the WLAN client subnet cannot reach the NWA90AX management IP. The management IP should only be accessible from a trusted wired management network.
    2. Firewall rules – If you have an upstream firewall or router, you can create rules to block access to the AP’s management IP (ports 80/443) from WLAN subnets or VLANs, while allowing access from your wired management subnet.
    3. VLAN separation – Assign the AP’s management interface to a dedicated management VLAN, and ensure your WLAN SSIDs are mapped to different VLANs that do not have access to the management VLAN.

    Additionally, may we confirm whether your main requirement is to prevent wireless clients from accessing the AP’s GUI?

    If so, we recommend managing the AP via Nebula Control Center (cloud mode). In Nebula, enabling Guest Network on the SSID will automatically enable Layer-2 isolation, preventing guest Wi-Fi clients from accessing the AP’s web GUI.

    Regarding your question about restricting web/SSH access to a single IP, this can also be done in Nebula under Site-wide > Configure > Site settings > Administrative Access.

    image.png

    Please note this setting applies site-wide to all devices in the same Nebula site.

    Zyxel Tina