category | Included Zyxel Devices |
---|---|
NSG (Nebula Security Gateway) devices | NSG Series |
Hybrid Security Firewall devices | ZyWALL ATP / USG FLEX / USG20(W)-VPN Series |
Hybrid Switches | NSW / GS / XGS / XS Series |
Hybrid APs (Access Point) | NAP / NWA / WAC / WAX Series |
label | Included Zyxel Devices |
---|---|
NSG | NSG Series |
ATP | ATP / USG FLEX / USG20(W)-VPN Series |
NSW | NSW / GS / XGS / XS Series |
NAP | NAP / NWA / WAC / WAX Series |
License | Category | Assign to | Description |
---|---|---|---|
Pro Pack | Organization | Any NCC-managed device | Unlocks all advanced features within the Nebula Device’s organization. For details on Pro features, see Organization License Tiers. |
Plus Pack | Organization | Any NCC-managed device | Unlocks certain advanced features within the Nebula Device’s organization. ![]() For details on Plus features, see Organization License Tiers. |
Organization Trial | Organization | Organization | Available when creating a new organization. Unlocks all Pro Pack and Nebula Security Service (NSS) features in the organization for 30 days. There are no restrictions on the allowed number of Nebula Devices or sites. ![]() |
Nebula Security Pack (Nebula Security Service) | Security Service | Nebula Security Gateway (NSG) device | Unlocks security services, such as anti-virus and anti-malware, on a Nebula Security Gateway (NSG) device. You can use these security services within the NSG’s site. |
UTM Security Pack | Security Service | USG FLEX device | Unlocks security services, such as anti-spam, anti-malware, content filtering and security profile sync (see Security Profile Sync for more information), on a Security Firewall. You can then use these security services within the Security Firewall’s site. |
Gold Security Pack | Organization and Security Service | ATP device | Unlocks security services, such as web filtering, application patrol, IPS (Intrusion Prevention System), Reputation filter, anti-malware with hybrid mode, sandboxing, CDR (Collaborative Detection & Response), security profile sync, Secure WiFi, SecuReporter, and all advanced features of a Pro Pack license on an ATP device. |
Secure WiFi | Security Service | USG FLEX device | Unlocks the Remote AP feature on a USG FLEX device. |
Content Filter Pack | Security Service | USG VPN device | Unlocks security services, such as content filtering, SecuReporter, security profile sync, and all advanced features of a Pro Pack license on USG20-VPN / USG20W-VPN devices. |
MSP | MSP | NCC user account | Unlocks the MSP menu and MSP features for the assigned user account. |
Feature | Base | Plus | Pro | Location | Notes |
---|---|---|---|---|---|
Groups-wide menu (create organization groups, admins & teams, org-to-org VPN) | No | No | Yes | Groups-wide | To create a group, you must be an NCC admin and the owner of two or more Pro organizations. |
Organization change logs | No | No | Yes | Organization-wide > Monitor > Change log | |
Login IP address ranges for an organization | No | No | Yes | Organization-wide > Configure > Setting | |
Number of admin accounts | 5 | 8 | Unlimited | Organization-wide > Configure > Administrators | |
Number of cloud authentication accounts | 50 | 100 | Unlimited | Organization-wide > Configure > Cloud authentication | |
Cloud authentication users with VLAN attribute | No | No | Yes | Organization-wide > Configure > Cloud authentication (Account type: Users) | |
Cloud Authentication DPPSK account type | No | No | Yes | Organization-wide > Configure > Cloud authentication (Account type: DPPSK) | |
Vouchers as general authentication credentials | No | Yes | Yes | Site-wide > Monitor > Vouchers Site-wide > Configure > General Settings | |
New site configuration clone | No | No | Yes | Organization-wide > Configure > Create site | |
Site-wide settings sync | No | No | Yes | Organization-wide > Configure > Configuration management | |
Switch settings clone | No | No | Yes | Organization-wide > Configure > Configuration management | |
Site/Switch configuration backup and restore | No | No | Yes | Organization-wide > Configure > Configuration management | |
Configuration templates | No | No | Yes | Organization-wide > Configure > Configuration templates | At the time of writing, gateway configuration templates are not available |
Add client to block list/allow list | No | No | Yes | Site-wide > Monitor > Clients | |
Site-wide topology | No | Yes | Yes | Site-wide > Monitor > Topology | |
Summary report email & schedule | No | Yes | Yes | Site-wide / Access point / Switch / Security gateway > Monitor > Summary report | |
Time period for summary reports | 24 hours | 7 days | 365 days | Site-wide / Access point / Switch / Security gateway > Monitor > Summary report | |
Time period for device monitoring statistics | 24 hours | 7 days | 365 days | Access point / Switch / Security gateway > Monitor > AP / SW / SG > [Select AP / SW] | |
Time period for client monitoring statistics | 24 hours | 7 days | 365 days | Access point / Switch / Security gateway > Monitor > Clients > [Select client] | |
Export data to CSV/XML file | No | Yes | Yes | All monitoring pages with tables | |
API access (for example, DPPSK third-party integration) | No | No | Yes | Site-wide > Configure > General settings | |
Smart email alerts | No | Yes | Yes | Site-wide > Configure > Alert settings | |
Nebula mobile app push notifications for VPN | No | Yes | Yes | App > Notification Center | |
Per-device firmware upgrade schedules | No | Yes | Yes | Site-wide > Configure > Firmware Management | |
Org-wide firmware upgrade | No | Yes | Yes | Organization-wide > Configure > Firmware management | |
Priority support requests from NCC UI or Nebula app | No | No | Yes | Help > Support request | |
Web chat with tech support directly from NCC UI | No | No | Yes | Website footer | |
Maximum uploaded photos from phone through NCC app | 1 | 1 | 5 | Device (for example, Access point) > Monitor > Device (for example, Access points) > [Select Device for example, AP] > Photo | |
Remote CLI access | No | No | Yes | Access point / Security gateway > Monitor > AP / SG [Select AP] Live tools | |
Wireless health monitor and report | No | No | Yes | Access point > Monitor > Wireless health | |
Programmable SSID | No | No | Yes | Access point > Configure > SSID overview | |
Dynamic Personal Pre-Shared Key (DPPSK) | No | No | Yes | Access point > Configure > SSID settings | |
Vouchers as WiFi authentication credentials | No | Yes | Yes | Site-wide > Monitor > Vouchers Site-wide > Configure > General Settings Access point > Configure > SSID settings Access point > Configure > Captive portal customization > [Portal Theme] | |
Facebook WiFi | No | No | Yes | Access point > Configure > SSID settings | |
RADIUS accounting for captive portal | No | No | Yes | Access point > Configure > SSID settings | |
Customize RADIUS NAS ID | No | No | Yes | Access point > Configure > SSID settings | |
Customize portal redirect URL parameter | No | No | Yes | Access point > Configure > Captive portal customization | |
Smart steering per AP | No | No | Yes | Access point > Configure > Radio settings > [Edit the Selected AP] | |
AP traffic log | No | No | Yes | Site-wide > Configure > General settings | |
IPTV report | No | No | Yes | Switch > Monitor > IPTV report | |
Advanced IGMP | No | No | Yes | Switch > Configure > Advanced IGMP | |
Switch Surveillance Monitoring with ONVIF | No | No | Yes | Switch > Monitor > Surveillance | Currently only supported on GS1350 series switches |
Extended PoE range | No | No | Yes | Switch > Configure > Switch ports > [Select Port] | Currently only supported on GS1350 series switches |
Automatic PoE device recovery | No | No | Yes | Switch > Configure > Switch ports > [Select Port] | Currently supported on GS1350 and GS2220 series switches |
Port bandwidth control | No | No | Yes | Switch > Configure > Switch ports > [Edit the selected port] | |
Vendor ID-based VLAN | No | No | Yes | Switch > Configure > Switch settings | |
IP interface and static route | No | No | Yes | Switch > Configure > IP & Routing | |
Packet capture | No | No | Yes | USG Flex > Monitor > Security gateway | Only supported on Security Firewall devices |
Time period for security service (AV/App Patrol/CF/IDP/NSS) analysis report | 24 hours | 7 days | 365 days | Security gateway > Monitor > NSS analysis report | Requires NSG NSS-SP license |
VPN topology with traffic usage | No | No | Yes | Organization-wide > Configure > VPN Orchestrator | |
Smart VPN | No | No | Yes | Organization-wide > Configure > VPN Orchestrator | Free beta feature until the end of 2021 |
VPN provision script email | No | No | Yes | Security gateway > Configure > Remote access VPN (L2TP/IPSec) | |
Collaborative Detection & Response (CDR) with automatic respond action | No | No | Yes | Site-wide > Configure > Collaborative detection & response | Requires Security Firewall UTM Security Pack license |
Label | Description |
---|---|
Group | This shows the name of the groups you are managing, if your NCC account has an MSP license. Click to choose another group if you have multiple groups. ![]() |
Organization | This shows the name of the organization you are managing. Click to choose another organization, access the MSP portal or create a new organization. |
Site | This shows the name of the site you are managing. Click to choose another site if you have multiple sites in the selected organization. |
Orchestrator | Click this to go to the Nebula Orchestrator portal to manage your SD-WAN devices. See the SD-WAN user’s guide. |
Search | Use this to search for managed devices by model, description or MAC address. |
More | Click this to view your account information, login history and active sessions. You can also view your devices and manage NCC licenses linked to your account. |
Notification | Click this to view log messages. |
Settings | Click this to select a display language for the screens, or change the theme between dark and light mode. |
Applications | Click this to open a list of links to different Zyxel sites, such as myZyxel, Circle, SecuReporter, CNC, Marketplace, and the Forum. |
Account | Click this to manage your NCC account settings, or to sign out of NCC. |
Label | Description |
---|---|
Profile | This shows account information, such as name, address, and phone number. |
My devices & services | This shows a list of all Nebula Devices in NCC that have your login account as the owner. You can filter the list of Nebula Devices by name, serial number, model, or organization. You can also register licenses to your account, such as an MSP license. |
Active sessions | Shows all active web browser sessions for this login account. Click End Session to close a session and force the user to log into NCC again in that browser. |
Recent logins | Shows the login history for this user account, including IP address, location, and time. |
Label | Description |
---|---|
Dark mode | Click this to apply a black background and white text to the white background and black text on the NCC screen. |
Language | Select the NCC display language. At the time of writing, the following languages are available: English, Chinese, Japanese, German, Russian, French. |
Label | Description |
---|---|
Manage account | Click this to edit your account settings at myZyxel. |
Sign out | Sign out of NCC. |
Label | Description |
---|---|
Use these menus to set up customer networks. | |
MSP | Create multiple organizations and change the branding and assign administrators to multiple organizations. |
Group-wide | Manage settings for multiple organizations and create VPN links between groups in the organization. Two or more Pro tier organizations can be a group. |
Organization-wide | Manage multiple network sites within an organization. |
Site-wide | Manage Nebula Devices in a site. |
Use these menus to set up customer Nebula Devices. | |
Security gateway | Manage ZyWALL NSG devices (firewalls). |
Firewall | Manage ZyWALL ATP, Security Firewall, and USG20W-VPN devices (firewalls). |
Switch | Manage Zyxel Switches. |
Access point | Manage Zyxel APs (Access Points). |
Help | Access the Zyxel community forum, submit a support ticket, view User Guides for Nebula managed devices, view ports used by Nebula, view Nebula privacy policies, and view devices/features that can be managed by Nebula. |
Level 1 | level 2 / level 3 | Function |
---|---|---|
MSP | Monitor | |
MSP portal | Use this menu to create multiple organizations and change the branding and assign administrators to multiple organizations. | |
Configure | ||
Create organization | Use this menu to create a new organization or copy settings from an existing organization. | |
MSP branding | Use this menu to upload/replace/remove the dashboard logo. You can also set the support contact details. | |
Admins & teams | Use this menu to create administrators or groups of administrators (teams) and view their login details. | |
Cross-org synchronization | Use this menu to sync or clone organization-wide settings from a source organization to a destination organization. | |
MSP alerts | Use this menu to configure MSP alerts to monitor Nebula Devices for unexpected events (for example, on-line/off-line events). | |
Group-wide | Monitor | |
Overview | Use this menu to view organization and license details of a selected group. | |
Inventory | Use this menu to view Nebula Devices belonging to organizations. You may also export the list of Nebula Devices found to your computer. | |
Change log | Use this menu to view log messages about configuration changes in the group. | |
Configure | ||
Settings | Use this menu to configure group information and group members. | |
Org-to-Org VPN | Use this menu to view and manage VPNs between members in the group. | |
Administrators | Use this menu to view, remove, or create a new administrator account for the selected group. | |
Organization-wide | Monitor | |
Overview | Use this menu to view a list of sites belonging to the selected organization and detailed information about the Nebula Devices connected to the sites. | |
Change log | Use this menu to view log messages about configuration changes in this organization. | |
Configure | ||
Settings | Use this menu to configure security settings or delete the organization. | |
Create site | Use this menu to create a new site. | |
License & inventory | Use this menu to manage your licenses and view the summary of Nebula Devices which have been registered and assigned to the sites in the selected organization. | |
Administrators | Use this menu to view, remove, or create a new administrator account for this organization. | |
Cloud authentication | Use this menu to create or remove user accounts and grant user access to all sites in the selected organization through different authentication methods, such as MAC-based authentication, captive portal, or the IEEE 802.1x authentication method. | |
Configuration management | Use this menu to synchronize the configuration between sites or switch ports and back up or restore a configuration file. | |
Configuration templates | Use this menu to create or delete a configuration template or bind a site to the template. | |
Security profile sync | Use this menu to synchronize the settings of URL threat filter, anti-malware and content filtering on the selected gateways. | |
VPN Orchestrator | Use this menu to view and manage VPNs created for the selected organization. | |
Firmware management | Use this menu to upgrade firmware or schedule firmware upgrades for Nebula Devices in the organization. | |
Site-wide | Monitor | |
Dashboard | Use this menu to view Nebula Device connection status and traffic summary. | |
Clients | ||
Clients list | Use this menu to view the connection status and detailed information of all wired and wireless clients connected to Nebula Devices (APs, switches, Security Gateway) in the site. | |
Client diagnostic | Use this menu to view all related event logs between APs and wireless clients, and DHCP logs of Nebula Security Gateways / Security Firewalls (NSG, ZyWALL USG FLEX, ATP, and USG20W-VPN). Association, Authentication, Disconnection, and DHCP event logs that occur are summarized in chronological order to aid in troubleshooting. | |
Containment list | Use this menu to view and manage Nebula Devices contained by CDR (Collaborative Detection & Response). | |
Map & Floor plans | Use this menu to locate Nebula Devices on a world map or on a floor plan. | |
Topology | Use this menu to view Nebula managed-device connections in your network. | |
Vouchers | Use this menu to create and manage vouchers that allow WiFi network access | |
Cloud intelligent logs | Use this menu to view log messages about configuration changes made by the NCC for the site. | |
Summary report | Use this menu to view network statistics for a site, such as bandwidth usage, power usage, top Nebula Devices, top clients and/or top SSIDs. | |
Applications | Use this menu to view usage of applications such as Social Network, Telephony (VoIP), Advertising, News, Web Services in the network. | |
Configure | ||
General settings | Use this menu to change the general settings for the site, such as the site name, device login password and firmware upgrade schedule. | |
Collaborative detection & response | Use this menu to view and configure the policies and notification settings for malware, IDP and web threats and corresponding containment actions to quarantine, alert or block. This is only available for ZyWALL USG Flex Series at the time of writing. | |
Alert settings | Use this menu to set which alerts are created and emailed or sent by the Zyxel Nebula app. You can also set the email addresses to which an alert is sent. | |
Add devices | Use this menu to register a Nebula Device and add it to the site. | |
Firmware management | Use this menu to upgrade firmware or schedule firmware upgrades for Nebula Devices in the site. | |
Cloud authentication | Use this menu to add user accounts and grant user access to the selected site through different authentication methods, such as the MAC-based authentication, captive portal or the IEEE 802.1x authentication method. | |
Security gateway | Use these menus to monitor and configure the Security Gateways, not including Security Firewall series, ATP series, and USG20(W)-VPN series, managed by the NCC. The settings are applied when a Nebula Security Gateway is registered and attached to the selected site. | |
Monitor | ||
Security gateway | Use this menu to view the detailed information about the Security Gateway of the selected site. | |
Clients | Use this menu to view the connection status and detailed information about a client in the selected site. | |
Event log | Use this menu to view all events on the Security Gateway. An event is something that has happened to a Nebula managed device. | |
VPN connections | Use this menu to view status of the site-to-site VPN connections. | |
NSS analysis report | Use this menu to view the statistics report for NSS (Nebula Security Service), such as content filtering, Intrusion Detection and Prevention (IDP), application patrol, and anti-virus. | |
Summary report | Use this menu to view network statistics specific to the Security Gateway in the site. | |
Configure | ||
Interface addressing | Use this menu to configure network mode, port grouping, interface address, static route and DDNS settings on the Security Gateway. | |
Policy route | Use this menu to view and configure policy routes. | |
Firewall | Use this menu to configure firewall rules for outbound traffic, application patrol, schedule profiles and port forwarding rules for inbound traffic. | |
Security service | Use this menu to enable content filtering and block access to specific web sites. You can also enable Anti-virus and Intrusion Detection and Prevention (IDP) on the Security Gateway. | |
Site-to-Site VPN | Use this menu to configure VPN rules. | |
Remote access VPN | Use this menu to enable and configure IPsec VPN or L2TP VPN settings. | |
Captive portal | Use this menu to configure captive portal settings for each Security Gateway interface. | |
Network access method | Use this menu to enable or disable web authentication on an interface. | |
Traffic shaping | Use this menu to configure the maximum bandwidth and load balancing. | |
Gateway settings | Use this menu to configure the DNS server and address records and also set the external AD (Active Directory) server or RADIUS server that the Security Gateway can use in authenticating users. You can also specify walled garden web site links for all interfaces on the Security Gateway. | |
Firewall | Use these menus to monitor and configure the ZyWALL USG FLEX series, ATP series, and USG20(W)-VPN series devices, not including ZyWALL NSG series devices, managed by the NCC. The settings are applied when a Nebula Security Firewall is registered and attached to the selected site. | |
Monitor | ||
Firewall | Use this menu to view the detailed information about the Security Firewall of the selected site. | |
Clients | Use this menu to view the connection status and detailed information of all wired and wireless clients connected to Nebula Devices (APs, Security Firewall) in the site. | |
Event log | Use this menu to view all events on the Security Firewall. An event is something that has happened to a Nebula managed device. | |
VPN connections | Use this menu to view status of the site-to-site VPN connections. | |
SecuReporter | Use this menu to view the statistics report for NSS (Nebula Security Service), such as content filtering, Intrusion Detection and Prevention (IDP), application patrol, and anti-virus. | |
Summary report | Use this menu to view network statistics specific to the Security Firewall in the site. | |
Configure | ||
Port | Use this menu to configure network mode and port grouping on the Security Firewall. | |
Interface | Use this menu to configure interface address, subnet mask and VLAN ID settings on the Security Firewall. | |
Routing | Use this menu to view and configure policy routes, static routes and WAN load balancing. | |
NAT | Use this menu to view and configure virtual servers and NAT settings | |
Site-to-Site VPN | Use this menu to configure VPN rules between Security Firewalls. | |
Remote access VPN | Use this menu to enable and configure IPsec VPN or L2TP VPN rules from off-site clients to an on-site Security Firewall. | |
Security policy | Use this menu to configure firewall rules for outbound traffic, application patrol, schedule profiles and port forwarding rules for inbound traffic. | |
Security service | Use this menu to enable content filtering and block access to specific web sites. You can also enable Anti-virus and Intrusion Detection and Prevention (IDP) on the Security Firewall. | |
Captive portal | Use this menu to configure captive portal settings for each Security Firewall interface. | |
Authentication method | Use this menu to configure network access settings through a captive portal or Nebula Cloud Authentication. | |
Wireless | Use this menu to configure different SSID profiles for your ZyWALL USG FLEX 100W and USG20W-VPN. ![]() | |
Gateway settings | Use this menu to configure the DNS server and address records and also set the external AD (Active Directory) server or RADIUS server that the Security Firewall can use in authenticating users. You can also specify walled garden web site links for all interfaces on the Security Firewall. | |
Switch | Use these menus to monitor and configure the Switches managed by the NCC. The settings are applied when a Nebula Switch is registered and attached to the selected site. | |
Monitor | ||
Switches | Use this menu to view the list of Switches added to the site. | |
Clients | Use this menu to view detailed information about the clients which are connecting to the Switches in the site. | |
Event log | Use this menu to view all events on the Switch. An event is something that has happened to a Nebula managed device. | |
IPTV report | Use this menu to view available IPTV channels and client information. | |
Surveillance | Use this screen to view information about Powered Devices (PDs) connected to ports on the switch. | |
Summary report | Use this menu to view network statistics specific to Switches in the site. | |
Configure | ||
Switch ports | Use this menu to view the Switch port statistics and configure Switch settings for the ports. | |
ACL | Use this menu to configure the access control list in order to control access to the Switches. | |
IP & Routing | Use this menu to configure layer 3 features such as creating IP interfaces and static routes on the Switch. | |
ONVIF discovery | Use this menu to enable ONVIF and configure ONVIF VLAN ID for the selected Switch. | |
Advanced IGMP | Use this menu to enable and configure IGMP snooping and create IGMP filtering profiles. | |
RADIUS policies | Use this menu to configure authentication servers and policies. | |
PoE schedules | Use this menu to set the schedule for Switches in distributing power to powered devices. | |
Switch settings | Use this menu to configure global Switch settings, such as (R)STP, QoS, port mirroring, voice VLAN and DHCP white list. | |
Access Point | Use these menus to monitor and configure the APs managed by the NCC. The settings are applied when a Nebula AP is registered and attached to the selected site. | |
Monitor | ||
Access points | Use this menu to view the list of APs added to the site. | |
Clients | Use this menu to view WiFi clients which are connected to the APs in the site. | |
Event log | Use this menu to view all events on the AP. An event is something that has happened to a Nebula managed device. | |
Wireless health | Use this menu to view health of the wireless networks for the supported APs and connected clients. | |
Summary report | Use this menu to view network statistics specific to APs in the site. | |
Configure | ||
SSID overview | Use this menu to view and configure SSID settings and authentication methods. | |
SSID settings | Use this menu to configure network access, traffic options and advanced settings for SSID profiles. | |
Captive portal customization | Use this menu to configure captive portal settings for SSID profiles. | |
SSID availability | Use this menu to configure SSID visibility settings and set whether the SSID is enabled or disabled on each day of the week. | |
Radio settings | Use this menu to configure global radio settings, such as maximum output power or channel width, and enable smart client steering for all APs in the site. | |
AP & port settings | Use this menu to configure load balancing settings and enable or disable a port on the managed AP and configure the port’s VLAN settings. |