Introduction
Overview
Major Model Features
Fast-path Acceleration
Registration at Nebula Control Center (NCC)
Licenses
License Priority
Grace Period
Applications
Security Router
VPN Connectivity
User-Aware Access Control
Load Balancing
Management Overview
Web Configurator
Web Configurator Access
Remote Access to the Zyxel Device Networks
Web Configurator Screens Overview
Navigation Panel
Tables and Lists
Error /Warning Messages
Hardware, Interfaces and Zones
Hardware Overview
Multi-Gigabit
Default Physical Port – Interface Mapping
PoE
Front Panels
Rear Panels
Console Port Pin Connectors
Installation Scenarios
Desktop Installation Procedure
Rack-mounting
Wall-mounting
Power Cord Lock
Procedure A
Procedure B
Dashboard
Dashboard Overview
The System Screen
System Information Screen
Port Status Screen
Resource Usage Screen
Bandwidth
Client Usage Screen
The Latest Logs Screen
The Security Screen
Monitor
Overview
What You Can Do in this Chapter
The Application Usage Screen
The Port Statistics Screen
The Interface Statistics Screen
The Session Monitor Screen
The Content Filter Screen
The Reputation Filter Screens
IP Reputation
DNS Threat Filter
URL Threat Filter
The IPS Screen
The Anti-Malware Screen
The Sandbox Screen
The SSL Inspection Screens
The Summary Screen
The Certificate Cache List Screen
The Interface Screen
The Device Insight Screen
The Login Users Screen
The Lockout IPs Screen
The DHCP Table Screen
The IPSec VPN Screen
The Site to Site VPN Screen
The Remote Access VPN Screen
The SSL VPN Screen
Regular Expressions in Searching IPSec Policies
The Tailscale Screen
Licensing
Licensing
What you Need to Know
The Licenses Screen
The Signature Update Screen
Signature Update
Auto Update
Interfaces
Interface Overview
What You Can Do in this Chapter
What You Need to Know
Interface Screen
Interface Screen Warning Messages
External Interface
External Interface Add/Edit
Internal Interface
Internal Interface Add/Edit
General Interface
Add/Edit DHCP Extended Options
VTI Interface
Restrictions for IPSec Virtual Tunnel Interface
VTI Edit
Trunk Overview
What You Need to Know
The Trunk Summary Screen
Configuring a User-Defined Trunk
Configuring the System Default Trunk
Port
Routing
Policy and Static Routes Overview
What You Need to Know
Policy Route Screen
Policy Route Edit Screen
Static Route Screen
Static Route Add/Edit Screen
NAT
NAT Overview
What You Need to Know
The NAT Screen
The NAT Add/Edit Screen
BWM (Bandwidth Management)
Overview
What You Need to Know
The Bandwidth Management Configuration
The Bandwidth Management Add/Edit Screen
Adding Objects for the BWM Policy
Example: Prioritize a Specific Application
ALG
ALG Overview
What You Need to Know
Before You Begin
The ALG Screen
Multicast
Multicast Overview
What You Need to Know
The Multicast Screen
IPSec VPN
Virtual Private Networks (VPN) Overview
IPSec VPN Background Information
IKE SA Overview
Additional Topics for IKE SA
Additional Topics for IPSec SA
What You Need to Know
The Site to Site VPN Screen
The Site to Site VPN Add/Edit Screen- Wizard
The Site to Site VPN Add/Edit Screen - Custom
The Remote Access VPN Screen
Remote Access VPN Setup Example
Zyxel Device Setup
Home User Setup
Test the VPN Connection
SSL VPN
Overview
What You Can Do in this Chapter
The SSL VPN Screen
Tailscale
Overview
What You Can Do in this Chapter
What You Need to Know
The Tailscale Screen
Set Up a Tailscale Network
Security Policy
Overview
What You Can Do in this Chapter
What You Need to Know
The Security Policy Screen
Configuring the Security Policy Control
The Policy Control Add/Edit Screen
Example: Allow a Server to Ping the Zyxel Device Without Creating Logs
DoS Prevention Overview
The DoS Prevention Policy Screen
The DoS Prevention Profile Screen
The Dos Prevention Profile Add/Edit Screen
IP Spoofing Prevention
The IP Spoofing Prevention Screen
The Trusted IP Add / Edit Screen
Session Control
Session Control Add/Edit
Captive Portal
Overview
What You Can Do in This Chapter
What You Need to Know
Authentication Policy Overview
The Policy Screen
The Policy Add/Edit Screen
The Advance Screen
Object
Address/Geo IP Overview
What You Need To Know
Address Summary Screen
Address Group Summary Screen
Geo IP Summary Screen
Service Overview
What You Need to Know
The Service Summary Screen
The Service Group Summary Screen
Zone Overview
What You Need to Know
The Zone Screen
Schedule Overview
What You Need to Know
The Schedule Screen
The Schedule Group Screen
Application Patrol
Overview
Application Patrol Profile
Application Patrol Profile > Add/Edit - Application Management
Example: Block an Application
Content Filtering
Overview
What You Need to Know
Content Filtering General
Content Filtering Add Profile
Content Filtering Profile (Allow List)
Content Filtering Profile (Block List)
Content Filtering Profile (Blocked URL Keywords)
Content Filtering Profile (Test Web Site Category)
Content Filtering Example: Block LAN Users
Reputation Filter
Overview
What You Need to Know
What You Can Do in this Chapter
IP Reputation Screen
IP Reputation Allow List
IP Reputation Block List
IP Reputation SecuReporter Allow List
DNS Threat Filter Screen
DNS Threat Filter Allow List
DNS Threat Filter Block List
DNS Threat Filter SecuReporter Allow List
URL Threat Filter Screen
URL Threat Filter Allow List
URL Threat Filter Block List
URL Threat Filter SecuReporter Allow List
Anti-Malware
Overview
Anti-Malware Screen
The Allow List Screen
The Block List Screen
Sandbox
Overview
What You Need to Know
Sandbox Screen
IPS
Overview
What You Need To Know
Before You Begin
The IPS Screen
The Allow List Screen
IP Exception
Overview
The IP Exception Screen
The IP Exception Add/Edit Screen
Example: Bypass a Website
SSL Inspection
What You Need To Know
What You Need To Know
Before You Begin
The SSL Inspection Profile Screen
Add/Edit SSL Inspection Profiles
Exclude List Screen
Certificate Update Screen
External Block Lists
Overview
IP Reputation External Block List Screen
DNS / URL Threat Filter External Block List Screen
User & Authentication
User/Group
What You Need To Know
User/Group User Summary Screen
User Add/Edit Screen
User/Group Group Summary Screen
User/Group Setting Screen
User Authentication Overview
What You Need To Know
AAA Server Overview
AAA Server Configuration
Add an AD Server
Join an AD Domain
Add an LDAP Server
Add a RADIUS Server
Two-Factor Authentication Overview
User Authentication Two-Factor Authentication
Wireless
Overview
What You Can Do in this Chapter
What You Need to Know
The AP Control Service Screen
The AP List Screen
The AP List > Managed AP Screen
The AP List > Unmanaged AP Screen
Edit AP List
The Policy Screen
The AP Firmware Screen
The WLAN Clients Screen
The WLAN Clients > All Clients Screen
The WLAN Clients > All Clients > Policy Screen
The WLAN Clients > All Clients > Add Policy Clients Screen
The WLAN Clients > Policy Clients Screen
The WLAN Clients > Policy Clients > Add Policy Screen
The WLAN Clients > Policy Clients > Add Policy Clients Screen
The SSID Settings Screen
The SSID Advanced Settings Screen
Edit SSID Advanced Settings
The Radio Settings Screen
The Wireless > WLAN Settings > Radio Settings > Edit Band Screen
The AP Settings Screen
The Wireless > WLAN Settings > AP Settings > Edit AP Screen
The AP Group Settings Screen
The Wireless Health Screen
System
Overview
What You Can Do in this Chapter
Settings
System Settings
System Time
Administration Settings
Settings
Device HA (High Availability)
What You Can Do in These Screens
Heartbeat
Preparing to Deploy Device HA
Using NCC To Manage Device HA
Deployment Overview
HA Status
HA Configuration
HA Log
Firmware Upgrade on Paired Zyxel Devices
Disabling Device HA
DNS & DDNS
DNS Server Address Assignment
The DNS Screen
Address/PTR Record
Adding an Address/PTR Record
CNAME Record
MX Record
Domain Zone Forwarder
Security Option Control
Editing a Security Option Control
The DDNS Screen
The DDNS Add/Edit Screen
SNMP
SNMPv3 and Security
Supported MIBs
SNMP Traps
Configuring SNMP
Add SNMP V3 User
Notification
The Mail Server Screen
The Alert Screen
Certificate Overview
What You Need to Know
Verifying a Certificate
My Certificates
The My Certificates Add Screen
The My Certificates Edit Screen
The My Certificates Import Screen
Trusted Certificates
The Trusted Certificates Edit Screen
The Trusted Certificates Import Screen
Advanced
External Integrations
Log and Report
Overview
What You Can Do In this Chapter
Log/Events Screens
System Logs
Log Details
APC Logs
AP Logs
Log Settings Screen
SecuReporter
Email Daily Report
Firmware/File Manager
Overview
Configuration File Flow at Restart
The Configuration File Screen
Example: Back Up and Restore Zyxel Device Configuration
Firmware Management
Cloud Helper
The Firmware Management Screen
Diagnostics
Overview
What You Can Do in this Chapter
The Diagnostics Screens
The Diagnostics Screen
The Packet Capture Screen
The Packet Capture Edit Screen
The CPU / Memory Status Screen
The System Log Screen
The Network Tool Screen
Packet Flow Explore
Overview
What You Can Do in this Chapter
Routing Status
The SNAT Status Screen
Route Traces
Reboot/ShutDown
Overview
Reboot/Shutdown
Troubleshooting
Reserved System Ports
Resetting the Zyxel Device
Restarting the Zyxel Device
Getting More Troubleshooting Help
Introduction
Hardware, Interfaces and Zones
Dashboard
Monitor
Licensing
Interfaces
Routing
NAT
BWM (Bandwidth Management)
ALG
Multicast
IPSec VPN
SSL VPN
Tailscale
Security Policy
Captive Portal
Object
Application Patrol
Content Filtering
Reputation Filter
Anti-Malware
Sandbox
IPS
IP Exception
SSL Inspection
External Block Lists
User & Authentication
Wireless
System
Log and Report
Firmware/File Manager
Diagnostics
Packet Flow Explore
Reboot/ShutDown
Troubleshooting
Dashboard_System
Dashboard_Security
TrafficStatistics_ApplicationUsage
TrafficStatistics_Port
TrafficStatistics_Interface
TrafficStatistics_SessionMonitor
SecurityStatistics_ContentFilter
SecurityStatistics_ReputationFilter_IPReputation
SecurityStatistics_ReputationFilter_DNSThreatFilter
SecurityStatistics_ReputationFilter_URLThreatFilter
SecurityStatistics_IPS
SecurityStatistics_AntiMalware
SecurityStatistics_SSLInspection_Summary
SecurityStatistics_SSLInspection_CertificateCache
NetworkStatus_Interface
NetworkStatus_LoginUsers
NetworkStatus_LoginUsers_LockoutIPs
NetworkStatus_DHCPTable
VPNStatus_IPSecVPN_SitetoSiteVPN
Monitor_VPNMonitor_SSL
VPNStatus_Tailscale
Licensing_Licenses
Licensing_SignatureUpdate
Licensing_SignatureUpdate_Update
Licensing_SignatureUpdate_Schedule
Interface_Interface
Interface_Interface_EnternalAdd
Interface_Interface_InternalAdd
Interface_Interface_GeneralAdd
DHCPOpt
Interface_VTIAdd
Interface_Trunk
Interface_UserDefineTrunkAdd
Interface_DefaultTrunkEdit
Interface_Port
Routing_PolicyRoute
Routing_PolicyRoute_Add
Routing_StaticRoute
Routing_StaticRoute_Add
NAT
NAT_Add
BWM
BWM_Add
ALG
Multicast
VPN
VPN_Add_Scenario
VPN_Add_Network
VPN_Add_Authentication
VPN_Add_PolicyRouting
VPN_Add_Summary
VPN_Add_Custom
SSL_AccessPrivilege_Edit
SSLVPN
SSL_AccessPrivilege
VPN_Tailscale
SecurityPolicy_PolicyControl
SecurityPolicy_PolicyControl_Add
SecurityPolicy_DoSPrevention_Policy
SecurityPolicy_DoSPrevention_Profile
SecurityPolicy_DoSPrevention_Profile_Add
SecurityPolicy_IPSpoofingPrevention
SecurityPolicy_IPSpoofingPrevention_AddTrustedIP
SecurityPolicy_SessionControl
SecurityPolicy_SessionControl_Add
CaptivePortal_AuthenticationPolicy_Policy
CaptivePortal_AuthenticationPolicy_Policy_Add
CaptivePortal_AuthenticationPolicy_Advance
Object_Address
Object_Address_Add
Object_AddressGroup
Object_AddressGroup_Add
Object_GeoIP
Object_GeoIP_Add
Object_Service
Object_Service_Add
Object_ServiceGroup
Object_ServiceGroup_Add
Object_Zone
Object_Zone_Add
Object_Schedule
Object_Schedule_OneTimeAdd
Object_Schedule_RecurringAdd
Object_ScheduleGroup
Object_ScheduleGroup_Add
SecurityService_AppPatrol
SecurityServices_ContentFilter
SecurityServices_ContentFilter_Add
SecurityService_ReputationFilter_IPReputation
SecurityService_ReputationFilter_DNSThreatFilter
SecurityService_ReputationFilter_URLThreatFilter
SecurityService_Anti-Malware
SecurityService_Sandboxing
SecurityService_IPS
SecurityService_IPS_AllowList
SecurityService_IPException
SecurityService_IPException_Add
SecurityService_SSLInspection_Profile
SecurityService_SSLInspection_ProfileAdd
SecurityService_SSLInspection_ExcludeList
SecurityService_SSLInspection_CertificateUpdate
SecurityService_ExternalBlockList_IPReputation
SecurityService_ExternalBlockList_DNSURLThreatFilter
UserAuth_UserGroup_User
UserAuth_UserGroup_UserAdd
UserAuth_UserGroup_Group
UserAuth_UserGroup_GroupAdd
UserAuth_UserGroup_Setting
UserAuth_UserAuth_AAAServer
UserAuth_UserAuth_AAAServer_ADAdd
UserAuth_UserAuth_AAAServer_LDAPAdd
UserAuth_UserAuth_AAAServer_RADIUSAdd
UserAuth_UserAuth_TwoFactorAuth
h_Wireless
Wireless_APControlService
Wireless_AccessPoints_APList_ManagedAP
Wireless_AccessPoints_APList_ManagedAPEdit
Wireless_AccessPoints_Policy
Wireless_AccessPoints_APFirmware
Wireless_WLANClients_AllClients
Wireless_WLANClients_AllClients_AddPolicy
Wireless_WLANClients_PolicyClients
Wireless_WLANClients_PolicyClients_AddPolicy
Wireless_WLANClients_AllClients_AddPolicyClients
Wireless_WLANSettings_SSIDSettings
Wireless_WLANSettings_SSIDSettings_AdvancedMode
Wireless_WLANSettings_SSIDSettings_AdvancedMode_Edit
Wireless_WLANSettings_RadioSettings
Wireless_WLANSettings_RadioSettings_EditBand
Wireless_WLANSettings_APSettings
Wireless_WLANSettings_APSettings_EditAP
Wireless_WLANSettings_APGroupSettings
Wireless_WirelessHealth
System_Settings
System_DeviceHA_HAStatus
System_DeviceHA_HAConfiguration
System_DeviceHA_HALog
System_DNS
System_DDNS
System_DDNS_Add
System_SNMP
System_SNMP_Add
System_Notification_Alert
System_Notification_MailServer
System_Notification_Alert_EventNotifi_Add
System_Notification_Alert_LogAlert_Add
System_Certificate_MyCertificate
System_Certificate_MyCertificate_Add
System_Certificate_MyCertificate_Edit
System_Certificate_MyCertificate_Import
System_Certificate_TrustedCertificate
System_Certificate_TrustedCertificate_Edit
System_Advanced
System_ExternalIntegrations
LogReport_LogEvents_System
LogReport_LogEvents_APC
LogReport_LogEvents_AP
LogReport_LogSettings
LogReport_SecuReporter
Maintenance_FileManager_ConfigFile
Diag_Diagnostics
Diag_PacketCapture
Diag_PacketCapture_Edit
Diag_CPUMemory
Diag_SystemLog
Diag_NetworkTools
Maintenance_PacketFlowExplore_RoutingStat
Maintenance_PacketFlowExplore_SNAT
Maintenance_PacketFlowExplore_RouteTraces
PacketFlowExplore_RouteTraces
Maintenance_Reboot