Wi-Fi employee access for Zyxel Nebula

In this topic, you will learn how to configure access points managed by Zyxel Nebula Control Center to work together with Portnox™ Cloud for 802.1X and MAC-based authentication of Wi-Fi connections.

Important:
This guide gives general instructions for integrating Portnox Cloud with specific third-party devices. We try to provide useful examples for common models, but settings can differ between manufacturers, models, and environments. Because of this, we cannot guarantee these steps will work in every case. For questions or problems with RADIUS setup – which is an industry standard and not specific to Portnox – or with device-specific settings and troubleshooting, we recommend checking the device manufacturer’s documentation and contacting their support team. Portnox Support can help when possible, but detailed setup of third-party devices is usually best handled by the manufacturer. We also recommend updating your NAS device firmware to the latest version, as old firmware can cause issues.
Important:
All values in this configuration are examples. Make sure to adjust the configuration to your individual profile names, RADIUS server addresses, ports, and keys by replacing the values that are presented as underlined italics.
Note:
Zyxel Nebula does not support RadSec.
Note:
Zyxel Nebula does not support RADIUS-based IPSK. Zyxel’s equivalent feature, called DPPSK (Dynamic Personal Pre-Shared Key), works only with the Nebula cloud authentication server, so you cannot use it with Portnox Cloud.
Note:
This configuration was tested on Nebula Control Center 20.10 with an NWA240BE access point. The capabilities and the user interface on other versions of the platform may differ.

Create an SSID for 802.1X authentication

In this section, you will create a new SSID and configure it for WPA2 or WPA3 Enterprise authentication, using the Portnox™ Cloud RADIUS servers.

  1. In Nebula Control Center, in the left-hand side menu, click on the following menu options: Configure > SSID settings.

  2. In the SSID settings pane, activate the Advanced mode switch, and then click on the Add SSID network button.

    Note:
    Without advanced mode, the pane shows a simplified view with only the Open and Password security options. Advanced mode changes only which fields are visible. It does not change your configuration.

    Result: A new SSID column appears to the right of the existing SSIDs.

  3. In the new SSID column, click on the Edit link in the SSID settings row.

    Result: The SSID advanced settings screen opens.

  4. In the Basic Info section, in the SSID name field, enter the network name that devices see when they search for Wi-Fi networks, and activate the Enabled switch.

  5. In the Network access section, next to the Security options label:

    1. Select the WPA Enterprise with option, and in the field next to it, select the WPA2 or WPA3 option, depending on what your devices support.
    2. In the second WPA Enterprise with field below, select the My RADIUS server option.
    3. Leave the MAC-based Authentication with switch deactivated.

      To use MAC-based authentication, create a separate SSID (see below).

    Result: The RADIUS server section appears below.

  6. In the Sign-in method section, leave the Disabled option selected.

    This section configures web-based sign-in for captive portals.

  7. In the RADIUS server section, enter the details of the Portnox Cloud RADIUS server that you created earlier:

    1. In the Host field, enter the Cloud RADIUS IP value from Portnox Cloud.
    2. In the Port field, enter the Authentication port value from Portnox Cloud.
    3. In the Secret field, enter the Shared Secret value from Portnox Cloud.
      Warning:
      The Secret field does not mask its value. Anyone who can see your screen or who has access to Nebula Control Center can read the shared secret.
    4. If you use Cloud RADIUS servers in both regions, click on the Add button, and enter the details of the second RADIUS server in the new row.

      The table accepts a maximum of two servers.

  8. In the RADIUS accounting field, select the RADIUS accounting enabled option. Then, in the RADIUS accounting servers table that appears, enter the same details as in the previous step, but in the Port field, enter the Accounting port value from Portnox Cloud.

  9. Leave the settings in the Traffic options, Advanced settings, and SSID schedule sections at their default values unless your environment requires otherwise. Then, click on the Back button.

    Result: The SSID settings pane opens with your changes. Nebula Control Center does not apply these changes yet.

  10. In the SSID settings pane, click on the Save button.

    Important:
    If you leave the SSID settings pane without clicking on the Save button, you lose all changes made on the SSID advanced settings screen.

    The access points receive the new configuration within 1 to 2 minutes.

Result: You created an SSID that authenticates employee Wi-Fi devices using 802.1X and the Portnox Cloud RADIUS servers.

Optional: Create an SSID for MAC-based authentication

This is an optional task. Follow this task only if you want to authenticate devices, such as IoT devices, that do not support 802.1X, using their MAC address instead. Skip this task if you do not need MAC-based authentication.

  1. In Nebula Control Center, in the left-hand side menu, click on the following menu options: Configure > SSID settings.

  2. In the SSID settings pane, activate the Advanced mode switch, and then click on the Add SSID network button.

    Note:
    Without advanced mode, the pane shows a simplified view with only the Open and Password security options. Advanced mode changes only which fields are visible. It does not change your configuration.

    Result: A new SSID column appears to the right of the existing SSIDs.

  3. In the new SSID column, click on the Edit link in the SSID settings row.

    Result: The SSID advanced settings screen opens.

  4. In the Basic Info section, in the SSID name field, enter the network name that devices see when they search for Wi-Fi networks, and activate the Enabled switch.

  5. In the Network access section, next to the Security options label:

    1. Select the Open option.
    2. Activate the MAC-based Authentication with switch, and in the field next to it, select the My RADIUS server option.

    Result: The RADIUS server section appears below.

  6. In the Sign-in method section, leave the Disabled option selected.

    This section configures web-based sign-in for captive portals.

  7. In the RADIUS server section, enter the details of the Portnox Cloud RADIUS server that you created earlier:

    1. In the Host field, enter the Cloud RADIUS IP value from Portnox Cloud.
    2. In the Port field, enter the Authentication port value from Portnox Cloud.
    3. In the Secret field, enter the Shared Secret value from Portnox Cloud.
      Warning:
      The Secret field does not mask its value. Anyone who can see your screen or who has access to Nebula Control Center can read the shared secret.
    4. Leave the Account Format and Calling Station ID fields set to the default FFFFFFFFFFFF value.
    5. If you use Cloud RADIUS servers in both regions, click on the Add button, and enter the details of the second RADIUS server in the new row.

      The table accepts a maximum of two servers.

  8. In the RADIUS accounting field, select the RADIUS accounting enabled option. Then, in the RADIUS accounting servers table that appears, enter the same details as in the previous step, but in the Port field, enter the Accounting port value from Portnox Cloud.

  9. Leave the settings in the Traffic options, Advanced settings, and SSID schedule sections at their default values unless your environment requires otherwise. Then, click on the Back button.

    Result: The SSID settings pane opens with your changes. Nebula Control Center does not apply these changes yet.

  10. In the SSID settings pane, click on the Save button.

    Important:
    If you leave the SSID settings pane without clicking on the Save button, you lose all changes made on the SSID advanced settings screen.

    The access points receive the new configuration within 1 to 2 minutes.

Result: You created a separate SSID that authenticates IoT devices by their MAC address using the Portnox Cloud RADIUS servers on the basis of MAC-based accounts.