Guest access for Zyxel Nebula

In this topic, you will learn how to configure access points managed by Zyxel Nebula Control Center to work together with the Portnox™ Cloud captive portal for guest user authentication.

Before you begin configuring your guest SSID, you must configure the guest network in Portnox Cloud and note down the values of the fields: IP (for walled garden) and Captive Portal URL.

Important:
This guide gives general instructions for integrating Portnox Cloud with specific third-party devices. We try to provide useful examples for common models, but settings can differ between manufacturers, models, and environments. Because of this, we cannot guarantee these steps will work in every case. For questions or problems with RADIUS setup – which is an industry standard and not specific to Portnox – or with device-specific settings and troubleshooting, we recommend checking the device manufacturer’s documentation and contacting their support team. Portnox Support can help when possible, but detailed setup of third-party devices is usually best handled by the manufacturer. We also recommend updating your NAS device firmware to the latest version, as old firmware can cause issues.
Important:
All values in this configuration are examples. Make sure to adjust the configuration to your individual profile names, RADIUS server addresses, ports, and keys by replacing the values that are presented as underlined italics.
Note:
This configuration was tested on Nebula Control Center 20.10 with an NWA240BE access point. The capabilities and the user interface on other versions of the platform may differ.

Create the guest SSID

In this section, you will create a new open SSID for guest access, and configure it to authenticate guests using the Portnox™ Cloud RADIUS servers.

  1. In Nebula Control Center, in the left-hand side menu, click on the following menu options: Configure > SSID settings.

  2. In the SSID settings pane, activate the Advanced mode switch, and then click on the Add SSID network button.

    Note:
    Without advanced mode, the pane shows a simplified view with only the Open and Password security options. Advanced mode changes only which fields are visible. It does not change your configuration.

    Result: A new SSID column appears to the right of the existing SSIDs.

  3. In the new SSID column, click on the Edit link in the SSID settings row.

    Result: The SSID advanced settings screen opens.

  4. In the Basic Info section, in the SSID name field, enter the network name that guests see when they search for Wi-Fi networks, and activate the Enabled switch.

  5. In the Network access section, next to the Security options label, leave the Open option selected.
  6. In the Sign-in method section, select the Sign-on with option, and in the field next to it, select the My RADIUS server option. Leave the MAC authentication fallback switch deactivated.

    Result: The RADIUS server and Captive portal advanced setting sections appear below.

  7. In the RADIUS server section, enter the details of the Portnox Cloud RADIUS server that you created earlier:

    1. In the Host field, enter the Cloud RADIUS IP value from Portnox Cloud.
    2. In the Port field, enter the Authentication port value from Portnox Cloud.
    3. In the Secret field, enter the Shared Secret value from Portnox Cloud.
      Warning:
      The Secret field does not mask its value. Anyone who can see your screen or who has access to Nebula Control Center can read the shared secret.
    4. If you use Cloud RADIUS servers in both regions, click on the Add button, and enter the details of the second RADIUS server in the new row.

      The table accepts a maximum of two servers.

    5. Optional: Activate the Authentication MS-CHAPv2 protocol switch to have the access point use the MS-CHAPv2 protocol when it sends guest credentials to the RADIUS server.

      If you leave this switch deactivated, the access point uses the less secure PAP protocol.

  8. In the Captive portal advanced setting section, activate the Walled garden switch. Then, in the Walled garden ranges field, enter the addresses from the IP (for walled garden) field that you obtained when you configured the guest network in Portnox Cloud, one address per line.

    Warning:
    The NAS device must be able to communicate with the walled garden IP addresses at all times. If this communication is blocked in any way, the captive portal will not work, and guest devices will be unable to connect to the network. Before you proceed, verify that all firewalls, ACLs, and any other security measures that could interfere with this communication are configured to explicitly allow the walled garden IP addresses.
  9. Leave the remaining settings in the Captive portal advanced setting section at their default values unless your environment requires otherwise.
  10. Leave the settings in the Traffic options, Advanced settings, and SSID schedule sections at their default values unless your environment requires otherwise. Then, click on the Back button.

    Result: The SSID settings pane opens with your changes. Nebula Control Center does not apply these changes yet.

  11. In the SSID settings pane, click on the Save button.

    Important:
    If you leave the SSID settings pane without clicking on the Save button, you lose all changes made on the SSID advanced settings screen.

    The access points receive the new configuration within 1 to 2 minutes.

Result: You created an open guest SSID that authenticates guests using the Portnox Cloud RADIUS servers.

Redirect guests to the Portnox Cloud captive portal

In this section, you will configure the guest SSID to redirect guests to the Portnox™ Cloud captive portal.

  1. In Nebula Control Center, in the left-hand side menu, click on the following menu options: Configure > Captive portal customization.

  2. In the SSID field, select the guest SSID that you created earlier.

  3. In the External captive portal URL section, activate the Use URL switch, and in the URL field, paste the Captive Portal URL that you obtained when you configured the guest network in Portnox Cloud, including the leading https://.

  4. Optional: In the Captive portal behavior section, select where guests go after they authenticate: the Stay on Captive portal authenticated successfully page option, or the To promotion URL option, and enter the address of the page that guests see.
  5. Click on the Save button.

    The access points receive the new configuration within 1 to 2 minutes.

Result: You configured an open SSID that redirects guests to the Portnox Cloud captive portal for authentication.