Introduction
NCC Overview
The Zyxel Nebula Control Center (NCC) is a cloud-based network management system that allows you to remotely manage and monitor Zyxel Nebula Mobile Routers, Access Points, Ethernet Switches, and Security Appliances. A Nebula Mobile Router is an LTE or NR cellular 5G indoor or outdoor router that can be managed by Nebula. You need to set up a myZyxel account in order to log into the NCC and manage your Nebula Devices, as discussed in Access the NCC Portal.
NCC feature support includes:
System accounts with different privilege levels
Site Administrator: manage one site, which is a network that contains Nebula Devices
Organization Administrator: manage one or more organizations, which are sets of sites
Multi-tenant management
Inventory and license management
Alerts to view events, such as when a device goes down
Graphically monitor individual devices
Securely manage Nebula Devices by using the Network Configuration Protocol (NETCONF) over TLS
*NCC supports IPv4 address only.
The following table describes the supported Nebula Devices.
Supported Nebula Devices 
category
Included Zyxel Devices
Hybrid Mobile Routers
LTE/NR Indoor/Outdoor Models
NSG (Nebula Security Gateway) devices
NSG Series
Hybrid Security Firewall devices
ZyWALL ATP / USG FLEX / USG20(W)-VPN Series
*The following Nebula Devices do NOT have a P1 port:
USG FLEX 50
USG FLEX 100 rev 2.0
ATP100 rev 2.0
Hybrid Switches
NSW / GS / XGS / XS Series
Hybrid APs (Access Point)
NAP / NWA / WAC / WAX Series
*To view the list of Nebula Devices that can be managed through NCC, go to Help > Device function table.
A hybrid device can operate in either standalone or Nebula cloud management mode. When the hybrid device is in standalone mode, it can be configured and managed by the Web Configurator. When the hybrid device is in Nebula cloud management mode, it can be managed and provisioned by the Zyxel Nebula Control Center (NCC).
MSP (Managed Services Provider) Portal
If you have an MSP license (as discussed in Overview), use the MSP menus for cross-organization management and branding.
A Managed Service Provider (MSP) network is a group of organizations that belong to the same organization administrator. With MSP, you can:
View the organization summary and transfer licenses
Copy the settings from a source organization to a destination organization
Create administrators or groups of administrators (teams) and view their login details
Assign administrators to multiple organizations
Upload/replace/remove the dashboard logo on NCC
Set the support contact details
Configure MSP alerts to monitor Nebula Devices for unexpected events (for example, online/offline events)
Groups, Organizations, and Sites
To manage by how Nebula Devices are deployed, use the Group-wide, Organization-wide, and Site-wide menus.
In the NCC, a site is a group of Nebula-managed devices in the same network. An organization is a group of sites. A group is a collection of two or more organizations. To use the NCC to manage your Nebula Devices, each Nebula Device should be assigned to a site and the site must belong to an organization.
A site can have multiple Nebula Devices, but can only belong to one organization.
A site can be managed by more than one site or organization administrator.
An organization can contain multiple sites and can be managed by more than one organization administrator.
A myZyxel.com account can be an organization administrator and/or site administrator in the NCC (see Administrators).
A site administrator can manage more than one site.
Mobile Router, Firewall (Security Appliance), Switch, and Access Point
To manage by Nebula Device type, use the Mobile Router, Firewall (Security Gateway), Switch or Access Point menus.
In the following example, Nebula managed devices, such as the NAP102 or the NSW100-28P, are deployed in two separate networks (Site A and Site B). With the NCC organization administrator account, you can remotely manage and monitor all Nebula Devices even when they are located at different places.
NCC Example Network Topology
License Concept
The following section describes license concepts in NCC. Licenses unlock additional features in NCC. This means you purchase a license, assign the license to a Nebula Device, and you can then use the service in the site or organization that the Nebula Device is in.
Summary of NCC Licenses
There are three categories of licenses in NCC:
Organization: These licenses unlock advanced features for sites and organizations.
Security Service: These licenses unlock advanced security features on a Security Appliance/Firewall device.
MSP: This license unlocks the MSP menu for an NCC user account.
The following table gives a summary of all licenses in NCC at the time of writing.
Licenses Summary 
License
Category
Assign to
Description
Nebula Professional Pack
Organization
Any NCC-managed devices
Unlocks all advanced features within the Nebula Device’s organization.
For details on Pro features, see Organization License Tiers.
Nebula Plus Pack
Organization
Any NCC-managed devices
Unlocks certain advanced features within the Nebula Device’s organization.
*Upgrade to Nebula Professional Pack to get all the advanced features.
For details on Plus features, see Organization License Tiers.
MSP
MSP
NCC user account
Unlocks the MSP menu and MSP features for an NCC user account.
MSP Trial
MSP
NCC user account
Unlocks the MSP menu and MSP features but is available only once per NCC account for 30 days. Go to More > My devices & services > Services: Activate trial for MSP.
*An MSP Trial license may not be transferred to a different account. A deactivated trial license ends the service and cannot be re-claimed.
Organization Trial
Organization
Organization
Available when creating a new organization. Unlocks all Nebula Professional Pack and Nebula Security Pack (NSS) features in the organization for 30 days. There are no restrictions on the allowed number of Nebula Devices or sites.
*Each Nebula user account can create 10 new organizations with trial licenses every 90 days.
Nebula Security Pack (Nebula Security Service)
Security Service
Nebula Security Gateway (NSG) devices
Unlocks security services, such as anti-virus and anti-malware.
You can use these security services within the NSG’s site.
UTM Security Pack
Security Service
USG FLEX devices
Unlocks security services, such as anti-malware, content filtering, URL threat filter, IP reputation, sandboxing, IPS (Intrusion Prevention System), application patrol, SecuReporter, CDR (Collaborative Detection & Response), and security profile sync (see Security Profile Sync for more information), on a Security Firewall.
You can then use these security services within the Security Firewall’s site.
Gold Security Pack
Organization and Security Service
ATP devices
Unlocks security services, such as content filtering, application patrol, DNS/URL threat filter, IPS (Intrusion Prevention System), Reputation filter, anti-malware with hybrid mode, sandboxing, CDR (Collaborative Detection & Response), security profile sync, Secure WiFi, SecuReporter, and all advanced features of a Nebula Professional Pack license.
For details on Pro features, see Organization License Tiers.
Gold Security Pack
Organization and Security Service
USG FLEX devices except USG20-VPN / USG20W-VPN / USG FLEX 50
Unlocks security services, such as content filtering, application patrol, DNS/URL threat filter, IPS (Intrusion Prevention System), Reputation filter, anti-malware, sandboxing, CDR (Collaborative Detection & Response), security profile sync, Secure WiFi, SecuReporter, and all advanced features of a Nebula Professional Pack license.
Secure WiFi
Security Service
USG FLEX devices except USG FLEX 50
Unlocks the Remote AP feature.
Content Filter Pack
Security Service
USG VPN devices
Unlocks security services, such as content filtering, SecuReporter, and security profile sync on USG FLEX 50 / USG20-VPN / USG20W-VPN devices.
Connect & Protect (CNP)
Security Service
NWA1123-ACv3, WAC500, WAC500H
Unlocks security services, such as threat protection using DNS and IP reputation filters.
Connect & Protect Plus (CNP+)
Security Service
NWA110AX, NWA210AX, WAX510D, WAX610D, WAX630S, WAX650S
Unlocks security services, such application visibility and threat protection using DNS and IP reputation filters.
Organization License Tiers
NCC features the following license tiers for organizations: Base, Plus, Professional.
The Base tier is free and included with every organization.
The Plus and Professional tier licenses unlock additional features within the organization. From a Plus tier license, upgrade to a Professional tier license to unlock all the additional features. These features are marked in the user interface with a diamond icon (). Hover the mouse over the licensed features to view the license type.
The feature differences between the license tiers are listed below:
NCC License Tier Differences 
Feature
Base
Plus
Professional
Location
Notes
Group-wide menu (Monitor – Overview, Inventory, Change log, and Configure – Settings, Org-to-Org VPN, and Administrators)
No
No
Yes
Group-wide
To create a group, you must be an NCC admin and the owner of two or more Professional organizations.
Organization change logs
No
No
Yes
Organization-wide > Monitor > Change log
 
Login IPv4 address ranges for an organization
No
No
Yes
Organization-wide > Configure > Settings
 
Number of admin accounts
5
8
Unlimited
Organization-wide > Configure > Administrators
 
Number of cloud authentication accounts
50
100
Unlimited
Organization-wide > Configure > Cloud authentication
 
Cloud authentication users with VLAN attribute
No
No
Yes
Organization-wide > Configure > Cloud authentication (Account type: User)
 
Cloud Authentication DPPSK account type
No
No
Yes
Organization-wide > Configure > Cloud authentication (Account type: DPPSK)
 
New site configuration clone
No
No
Yes
Organization-wide > Configure > Create site
 
Site-wide settings sync
No
No
Yes
Organization-wide > Configure > Configuration management
 
Switch settings clone
No
No
Yes
Organization-wide > Configure > Configuration management
 
Site/Switch configuration backup and restore
No
No
Yes
Organization-wide > Configure > Configuration management
 
Configuration templates
No
No
Yes
Organization-wide > Configure > Configuration templates
At the time of writing, gateway and mobile router configuration templates are not available
Add client to block list/allow list
No
No
Yes
Site-wide > Monitor > Clients
 
WiFi aid
No
No
Yes
Site-wide > Monitor > Clients
 
Connection log
No
No
Yes
Site-wide > Monitor > Clients
Access point > Monitor > Clients
 
Site-wide topology
No
Yes
Yes
Site-wide > Monitor > Topology
 
Summary report email & schedule
No
Yes
Yes
Site-wide / Access point / Switch / Security gateway / Firewall > Monitor > Summary report
 
Time period for summary reports
24 hours
7 days
365 days
Site-wide / Access point / Switch / Security gateway / Firewall > Monitor > Summary report
 
Time period for device monitoring statistics
24 hours
7 days
365 days
Access point / Switch / Security gateway / Firewall > Monitor > Access Points / Switches / Security gateway / Firewall > [Select Access Points / Switches]
 
Time period for client monitoring statistics
24 hours
7 days
365 days
Access point / Switch / Security gateway / Firewall > Monitor > Clients > [Select client]
 
Time period for device event log access
24 hours
7 days
365 days
Access point / Switch / Security gateway / Firewall > Monitor > Event log
 
Export data to CSV/XML file
No
No
Yes
All monitoring pages with tables
 
Open API
No
No
Yes
All monitoring information
 
API access (for example, DPPSK third-party integration)
No
No
Yes
Site-wide > Configure > General settings
 
Smart email alerts
No
Yes
Yes
Site-wide > Configure > Alert settings
 
Per-device firmware upgrade schedules
No
Yes
Yes
Site-wide > Configure > Firmware management
 
Org-wide firmware upgrade
No
Yes
Yes
Organization-wide > Configure > Firmware management
 
Priority support requests from NCC portal or Nebula app
Yes
No
Yes
Help center > Support request
 
Web chat with tech support directly from NCC portal
No
No
Yes
Website footer
 
Maximum uploaded photos from phone through NCC app
1
1
5
Device (for example, Access point) > Monitor > Device (for example, Access points) > [Select Device for example, AP] > Photo
 
Remote CLI access
No
No
Yes
Access point / Security gateway / Firewall > Monitor > Access Points / Security gateway / Firewall [Select AP] Live tools
 
Wireless health monitor and report
No
No
Yes
Access point > Monitor > Wireless health
 
Programmable SSID/PSK
No
No
Yes
Access point > Configure > SSID settings
 
Dynamic Personal Pre-Shared Key (DPPSK)
No
No
Yes
Access point > Configure > SSID advanced settings
 
Vouchers as WiFi authentication credentials
No
Yes
Yes
Site-wide > Monitor > Vouchers
Site-wide > Configure > General settings
Access point > Configure > SSID advanced settings
Access point > Configure > Captive portal customization > [portal theme]
 
Facebook WiFi
Configure in NCC
No
Yes
Access point > Configure > SSID advanced settings
 
RADIUS accounting for captive portal
No
No
Yes
Access point > Configure > SSID advanced settings
 
Customize RADIUS NAS ID
No
No
Yes
Access point > Configure > SSID advanced settings
 
Customize portal redirect URL parameter
No
No
Yes
Access point > Configure > Captive portal customization
 
Smart steering per AP
No
No
Yes
Access point > Configure > Radio settings > [Edit the selected Access Point]
 
Bandwidth Management by VLAN interface
No
No
Yes
Access point > Configure > Traffic shaping
Currently supported on NWA1123ACv3, WAC500, WAC500H, NWA110AX, NWA210AX, WAX510D, WAX610D, WAX630S, WAX650S
AP traffic log
No
No
Yes
Site-wide > Configure > General settings
 
IPTV report
No
No
Yes
Switch > Monitor > IPTV report
 
Advanced IGMP
No
No
Yes
Switch > Configure > Advanced IGMP
 
Switch Surveillance Monitoring with ONVIF
No
No
Yes
Switch > Monitor > Surveillance
Currently only supported on GS1350 series switches
Extended PoE range
Yes
Yes
Yes
Switch > Configure > Switch ports > [select port]
Currently only supported on GS1350 series switches
Automatic PoE device recovery
No
Yes
Yes
Switch > Configure > Switch ports > [select port]
Currently only supported on GS1350, GS2220 and XGS2220 series switches
Port bandwidth control
Yes
Yes
Yes
Switch > Configure > Switch ports > [edit the selected port]
 
Vendor ID-based VLAN
No
Yes
Yes
Switch > Configure > Switch settings
 
IP interface and static route
No
No
Yes
Switch > Configure > IP & Routing
 
Remote SSH in Live tools
No
No
Yes
Switch > Monitor > Switches: Switch Details > Live tools > Remote Access
Currently only supported on XS3800-28 and XGS2220 series v4.80 switches
IP Source Guard
No
No
Yes
Switch > Configure > Switch settings
Currently only supported on XS3800-28 and XGS2220 series v4.80 switches
Nebula cloud authentication
Yes
Yes
Yes
Switch > Configure > Authentication
Currently only supported on XGS1930 series v4.70 patch 5 switches
IGMP report proxy
No
No
Yes
Switch > Configure > Advanced IGMP
Currently not supported on GS1915 series switches
Time period for security service (AV/App Patrol/CF/IDP/NSS) analysis report
24 hours
7 days
365 days
Security gateway > Monitor > NSS analysis report
Requires Nebula Security Gateway (NSG) Nebula Security Service (NSS) – Security Pack (SP) license
Traffic log archiving
No
No
Yes
Firewall > Monitor > SecuReporter
 
VPN topology with traffic usage
No
No
Yes
Organization-wide > Configure > VPN Orchestrator
 
Smart VPN
No
No
Yes
Organization-wide > Configure > VPN Orchestrator
 
VPN provision script email
No
No
Yes
Security gateway / Firewall > Configure > Remote access VPN (L2TP/IPSec)
 
Collaborative Detection & Response (CDR) with automatic respond action
No
No
Yes
Site-wide > Configure > Collaborative detection & response
Requires Security Firewall UTM Security Pack license
Smart mesh with manual select of mesh controller (root) and automatic fall back to auto mode
Yes
Yes
Yes
Access point > Monitor > Access points
Currently supported on NWA110AX, NWA210AX, WAX510D, WAX610D, WAX630S, WAX650S, NWA1123ACv3, WAC500, and WAC500H APs
Traffic logs to SecuReporter
No
No
Yes
Site-wide > Configure > General settings
Also available for Gold Security Pack, UTM Security Pack, and Content Filter Pack
Cellular IP Passthrough
No
No
Yes
Mobile Router > Configuration
Currently only supported on NR7101 and LTE7461
Remote configurator in Live tools
No
No
Yes
Mobile Router > Live tools > Remote configurator
Requires LTE or NR cellular 5G indoor or outdoor router running the latest firmware
Organization License Grace Period
If a Professional or Plus license expires while assigned to a Nebula Device or you add an unlicensed Nebula Device to the organization, you have a 15-day grace period during which the organization’s license remains active. During the grace period, you must perform one of the following actions:
Assign a valid Plus or Professional license to the unlicensed Nebula Device.
Remove the unlicensed Nebula Device from the organization.
If the expired Nebula Device is still in the organization after the grace period elapses, the organization automatically downgrades to the Base tier.
The grace period status can be any of the following:
Near Expiring: Any Nebula Devices with licenses expiring within 15 days before the grace period has started.
License Expired: Any Nebula Devices with expired licenses after the grace period.
Insufficient Licenses: Any Nebula Devices that are unlicensed, or lower tier licensed Nebula Devices added during the grace period.
General License Information
License Validity
Each license has a validity period, for example: 6 months, 1 year, 2 years. After being activated, a license also has an expiry date, which is calculated as Activation Date + Validity Period. For example, if a 1-year license is activated on January 1st 2022, then its expiry date is January 1st 2023.
*A license cannot be deactivated. An activated license continues counting towards its expiry date, even if its licensed service is deactivated.
Bundled and Renewal Licenses
A bundled license is a license that is included when you purchase a Nebula Device. The bundled license is automatically assigned to the purchased Nebula Device when you add the Nebula Device to NCC.
A renewal license is a license purchased separately from a Nebula Device as a license key, from Zyxel or a third-party reseller. To assign a renewal license to a Nebula Device, go to Organization-wide > Configure > License & inventory > License and then click +Add. See License & Inventory Licenses Screen for more information.
Getting Started
You can perform network management with the NCC using a web browser. Use a browser that supports HTML5, such as Microsoft Edge, Mozilla Firefox, or Google Chrome. The recommended browser is Google Chrome.
View the browser in full screen mode to display the NCC portal properly.
Connect Nebula Managed Devices
Connect your Nebula managed devices (such as the NAP102 or the NSW100-28P) to your local network. Your local network must have Internet access. See the corresponding Quick Start Guides for hardware connections.
Access the NCC Portal
Go to the NCC portal website.
1 Enter http://nebula.zyxel.com in a supported web browser. Click Get Started.
*The NCC requires a myZyxel account before you can register and manage Nebula Devices. Log into the NCC with your myZyxel account. Click Create Account if you do not have a myZyxel account and create an account with your existing email address.
2 Enter the Email Address and Password, and then click Sign In.
*Click Try Demo to enter the Demo Site. The Demo Site allows you to explore the NCC Portal.
3 Click Go under Nebula Control Center to log in to NCC.
Alternatively, click Go under Nebula Orchestrator to go to the Nebula SD-WAN (Orchestrator) web portal to configure ZyWALL VPN devices. This is only available if you have purchased the SD-WAN license for Orchestrator Management.
Nebula SD-WAN (Orchestrator)
You can click Control Center to go back to the NCC platform.
4 Click Create organization to create a new organization. If this is the first time you have logged into NCC, proceed to step 10.
If you have more than one organization, click a row to select the organization you want to manage.
5 The NCC supports two-factor authentication (2FA) to add a second layer of security to your account. Click Manage account to enable Two-factor authentication on the following page. Otherwise, you can skip 2FA and go to step 10 directly.
6 Click Two-Factor Authentication and then click the switch to enable Two-Factor Authentication.
7 The following screen appear. Activate the two-step verification service using the Google Authenticator app or your email address. If you select Google Authenticator, install the app on your smartphone and scan the QR code on the NCC web screen to get a 6-digit one-time code. Then enter the code and click Verify to authenticate your identity.
 
Alternatively, click Email Verification to use your email to authenticate.
If you select Email Verification, an email is sent to your myZyxel account’s email address. Enter the code exactly as it appears in the email and click Verify.
8 Enter the verification code to get 10 backup codes, which help regain access to your account in case your smartphone is not available for 2FA the next time you need to log in again.
*If you generate a new set of backup codes, the old set will become inactive.
Write down or print out the backup codes for your account. You can enter the backup code on the NCC web page to authenticate your identity at the next login. Each code can only work once. Click Download to download the backup codes.
9 To re-log in Nebula after the Two-Factor Authentication is enabled. Go to Applications > Nebula and then enter a code to log in your Nebula account.
10 If this is the first time you have logged into NCC, the setup wizard welcome screen displays. You need to create your organization and sites, register Nebula Devices and associate them with a site. See Setup Wizard for how to use the wizard.
NCC Portal Overview
The following summarizes how to navigate the Nebula web site from the Dashboard screen. The NCC portal screen is divided into these parts:
NCC Overview
A – Title Bar
B – Navigation Panel
C – Main Screen
Title Bar
The title bar provides common links and is always at the top of NCC.
NCC Title Bar
The icons provide the following functions.
NCC Title Bar 
Label
Description
Group
This shows the name of the groups you are managing, if your NCC account has an MSP license. Click to choose another group if you have multiple groups.
*To create a group, you must be the owner of two or more Pro pack organizations that are not currently assigned to a group, as discussed in Creating a Group.
Organization
This shows the name of the organization you are managing. Click to choose another organization, access the MSP portal or create a new organization.
Site
This shows the name of the site you are managing. Click to choose another site if you have multiple sites in the selected organization.
Search
Use this to search for managed Nebula Devices by model, description or MAC address.
More
Click this to view your account information, login history and active sessions. You can also view your Nebula Devices and manage NCC licenses linked to your account.
Notification
Click this to view log messages.
Settings
Click this to select a display language for the screens, or change the theme between dark and light mode.
Applications
Click this to open a list of links to different Zyxel sites, such as myZyxel, Nebula, SecuReporter, CNC, Circle, Marketplace, and the Forum.
Account
Click this to manage your NCC account settings, or to sign out of NCC.
*If the browser window is too narrow, the layout of the title bar changes and some settings are hidden under the More menu.
Layout of the Title Bar
Group/Organization/Site
Select the group, organization and site that you want to manage.
If you select a group, you can only select organization in that group. Select List all Groups from the Group drop-down list to view all organizations and group.
If you have multiple organizations, select MSP Portal from the Organization drop-down list box to view your organization summary (see MSP Portal).
*You need to have an MSP license to view the MSP Portal.
If you need to have more organizations, select Create organization from the Organization drop-down list box to create a new one (see Create Organization).
If you need to have more sites, select Create site from the Site drop-down list box to create a new one (see Create Site).
NCC Title Bar: Group/Organization/Site
Search
Click this to search for NCC-managed devices by model, description or MAC address. You can enter partial search criteria.
Search
More
Click the More icon at the top right-hand corner of the Dashboard screen to view and configure account settings.
More
The following table describes this menu.
Login Account Menu
Label
Description
Profile
This shows account information, such as name, address, and phone number.
My devices & services
This shows a list of all Nebula Devices in NCC that have your login account as the owner. You can filter the list of Nebula Devices by name, serial number, model, or organization.
You can also register licenses to your account, such as an MSP license.
Active sessions
Shows all active web browser sessions for this login account. Click End Session to close a session and force the user to log into NCC again in that browser.
Recent logins
Shows the login history for this user account, including IPv4 address, location, and time.
Click My devices & services and the following screen appears. Click Devices to view all Nebula Devices of the user account which can be managed by NCC, and/or all Nebula Devices not registered to this user account but with a Full (Delegated) administrator privilege. See the table on MSP > Configure > Admins & teams > Admins in Admins Screen for details on the organization privileges.
My Devices
Click Services to view and configure the start dates, end dates, registered dates, activated dates and statuses of an MSP license, purchase or register a license key, and export the list of MSP licenses in CSV/XML format.
My Services
Click Purchase history to view the order ID, purchase date, number of licenses, statuses of purchased MSP license(s), and export the information in CSV/XML format.
Purchase History
Notifications
Click this alert icon to view log messages for the selected site.
NCC Notification
Settings
Click the Settings icon at the top right-hand corner of the screen to view and configure NCC settings.
Settings
The following table describes this menu.
Settings Menu
Label
Description
Dark mode
Click this to apply a black background and white text to the white background and black text on the NCC screen.
Language
Select the NCC display language.
At the time of writing, the following languages are available: English, Chinese, Japanese, German, Russian, French.
Dark Mode
Applications
Click this to display a list of related NCC links.
Related NCC Links
Account
Click the Account icon at the top right-hand corner of the screen to view and configure NCC account settings.
Account
The following table describes this menu.
Account Menu
Label
Description
Manage account
Click this to edit your account settings at myZyxel.
Sign out
Sign out of NCC.
Navigation Panel
Use the NCC menu items to configure network management for each site, organization and/or Nebula Device. Click the arrow () on the upper right corner of the navigation panel to collapse or expand the navigation panel menus.
Navigation Menus Overview 
Label
Description
Use these menus to set up customer networks.
MSP
Create multiple organizations and change the branding and assign administrators to multiple organizations.
Group-wide
Manage settings for multiple organizations and create VPN links between groups in the organization. Two or more Pro tier organizations can be a group.
Organization-wide
Manage multiple network sites within an organization.
Site-wide
Manage Nebula Devices in a site.
Use these menus to set up customer Nebula Devices.
Mobile router
Manage Zyxel LTE/NR devices.
Security gateway
Manage ZyWALL NSG devices (firewalls).
Firewall
Manage ZyWALL ATP, USG FLEX, and USG20(W)-VPN devices (firewalls).
Switch
Manage Zyxel Switches.
Access point
Manage Zyxel APs (Access Points).
Help center
Access the Zyxel community forum, submit a support ticket, view User Guides for Nebula managed devices, view ports used by Nebula, view Nebula privacy policies, and view devices/features that can be managed by Nebula.
This is a summary of the menu details.
NCC Menu Summary 
Level 1
level 2 / level 3
Function
MSP
Monitor
MSP portal
Use this menu to create multiple organizations and change the branding and assign administrators to multiple organizations.
Change log
Use this menu to view log messages about configuration changes in the Admins & teams and Cross-org synchronization screens.
Configure
Create organization
Use this menu to create a new organization or copy settings from an existing organization.
MSP branding
Use this menu to upload/replace/remove the dashboard logo. You can also set the support contact details.
Admins & teams
Use this menu to create administrators or groups of administrators (teams) and view their login details.
Cross-org synchronization
Use this menu to sync or clone organization-wide settings from a source organization to a destination organization.
MSP alert template
Use this menu to configure MSP alert templates to monitor Nebula Devices for unexpected events (for example, online or offline events).
Group-wide
Monitor
Overview
Use this menu to view organization and license details of a selected group.
Inventory
Use this menu to view Nebula Devices belonging to organizations. You may also export the list of Nebula Devices found to your computer.
Change log
Use this menu to view log messages about configuration changes in the group.
Configure
Settings
Use this menu to configure group information and group members.
Org-to-Org VPN
Use this menu to view and manage VPNs between members in the group.
Administrators
Use this menu to view, remove, or create a new administrator account for the selected group.
Organization-wide
Monitor
Overview
Use this menu to view a list of sites belonging to the selected organization and detailed information about the Nebula Devices connected to the sites.
Change log
Use this menu to view log messages about configuration changes in this organization.
Configure
Settings
Use this menu to configure security settings or delete the organization.
Create site
Use this menu to create a new site.
License & inventory
Use this menu to manage your licenses and view the summary of Nebula Devices which have been registered and assigned to the sites in the selected organization.
Administrators
Use this menu to view, remove, or create a new administrator account for this organization.
Cloud authentication
Use this menu to create or remove user accounts and grant user access to all sites in the selected organization through different authentication methods, such as MAC-based authentication, captive portal, or the IEEE 802.1x authentication method.
Configuration management
Use this menu to synchronize the configuration between sites or switch ports and back up or restore a configuration file.
Configuration templates
Use this menu to create or delete a configuration template or bind a site to the template.
Security profile sync
Use this menu to synchronize the settings of URL threat filter, anti-malware and content filtering on the selected gateways.
VPN Orchestrator
Use this menu to view and manage VPNs created for the selected organization.
Firmware management
Use this menu to upgrade firmware or schedule firmware upgrades for Nebula Devices in the organization.
Site-wide
Monitor
Dashboard
Use this menu to view Nebula Device connection status and traffic summary.
Clients
Client list
Use this menu to view the connection status and detailed information of all wired and WiFi clients connected to Nebula Devices (Access Points, Switches, Security Appliances, Security Firewalls) in the site.
WiFi Aid
Use this menu to display an overview of the AP’s WiFi clients connection issues, as an aid to troubleshooting.
Connection log
Use this menu to view all related event logs between Access Points and WiFi clients, and DHCP logs of Nebula Security Appliances (NSG, ZyWALL USG FLEX, ATP, and USG20(W)-VPN). Association, Authentication, Disconnection, and DHCP event logs that occur are summarized in chronological order to aid in troubleshooting.
Containment list
Use this menu to view and manage Nebula Devices contained by CDR (Collaborative Detection & Response).
Map & floor plans
Use this menu to locate Nebula Devices on a world map or on a floor plan.
Topology
Use this menu to view Nebula managed-device connections in your network.
Vouchers
Use this menu to create and manage vouchers that allow WiFi network access
Cloud intelligent logs
Use this menu to view log messages about configuration changes made by the NCC for the site.
Summary report
Use this menu to view network statistics for a site, such as bandwidth usage, power usage, top Nebula Devices, top clients and/or top SSIDs.
Applications
Use this menu to view usage of applications such as Social Network, Telephony (VoIP), Advertising, News, Web Services in the network.
Configure
General settings
Use this menu to change the general settings for the site, such as the site name, Nebula Device login password, captive portal reauthentication, SNMP, AP traffic logs to a Syslog server, traffic logs to SecuReporter, WiFi network authentication voucher settings, and API access for DPPSK third-party integration.
Collaborative detection & response
Use this menu to view and configure the policies and notification settings for malware, IDP and web threats and corresponding containment actions to quarantine, alert or block. This is only available for ZyWALL USG Flex Series at the time of writing.
Alert settings
Use this menu to set which alerts are created and emailed or sent by the Zyxel Nebula app. You can also set the email addresses to which an alert is sent.
Add devices
Use this menu to register a Nebula Device and add it to the site.
Firmware management
Use this menu to upgrade firmware or schedule firmware upgrades for Nebula Devices in the site.
Cloud authentication
Use this menu to add user accounts and grant user access to the selected site through different authentication methods, such as the MAC-based authentication, captive portal or the IEEE 802.1x authentication method.
Mobile Router
 
Use this screen to monitor and configure the LTE/NR indoor/outdoor devices, managed by the NCC. The settings are applied when a Nebula Mobile Router is registered and added to the selected site.
Security gateway
 
Use these menus to monitor and configure the Security Appliances, not including Security Firewall series, ATP series, and USG20(W)-VPN series, managed by the NCC. The settings are applied when a Nebula Security Appliance is registered and attached to the selected site.
Monitor
Security gateway
Use this menu to view the detailed information about the Security Appliance of the selected site.
Clients
Use this menu to view the connection status and detailed information about a client in the selected site.
Event log
Use this menu to view all events on the Security Appliance. An event is something that has happened to a Nebula managed device.
VPN connections
Use this menu to view status of the site-to-site VPN connections.
NSS analysis report
Use this menu to view the statistics report for NSS (Nebula Security Service), such as content filtering, Intrusion Detection and Prevention (IDP), application patrol, and anti-virus.
Summary report
Use this menu to view network statistics specific to the Security Appliance in the site.
Configure
Interface addressing
Use this menu to configure network mode, port grouping, interface address, static route and DDNS settings on the Security Appliance.
Policy route
Use this menu to view and configure policy routes.
Firewall
Use this menu to configure firewall rules for outbound traffic, application patrol, schedule profiles and port forwarding rules for inbound traffic.
Security service
Use this menu to enable content filtering and block access to specific web sites. You can also enable Anti-virus and Intrusion Detection and Prevention (IDP) on the Security Appliance.
Site-to-Site VPN
Use this menu to configure VPN rules.
Remote access VPN
Use this menu to enable and configure IPsec VPN or L2TP VPN settings.
Captive portal
Use this menu to configure captive portal settings for each Security Appliance interface.
Network access method
Use this menu to enable or disable web authentication on an interface.
Traffic shaping
Use this menu to configure the maximum bandwidth and load balancing.
Gateway settings
Use this menu to configure the DNS server and address records and also set the external AD (Active Directory) server or RADIUS server that the Security Appliance can use in authenticating users. You can also specify walled garden web site links for all interfaces on the Security Appliance.
Firewall
 
Use these menus to monitor and configure the ZyWALL USG FLEX series, ATP series, and USG20(W)-VPN series devices, not including ZyWALL NSG series devices, managed by the NCC. The settings are applied when a Nebula Security Firewall is registered and attached to the selected site.
Monitor
Firewall
Use this menu to view the detailed information about the Security Firewall of the selected site.
Clients
Use this menu to view the connection status and detailed information of all wired and WiFi clients connected to Nebula Devices (Access Points, Security Firewall) in the site.
Event log
Use this menu to view all events on the Security Firewall. An event is something that has happened to a Nebula managed device.
VPN connections
Use this menu to view status of the site-to-site VPN connections.
SecuReporter
Use this menu to view the statistics report for NSS (Nebula Security Service), such as content filtering, Intrusion Detection and Prevention (IDP), application patrol, and anti-virus.
Summary report
Use this menu to view network statistics specific to the Security Firewall in the site.
Configure
Port
Use this menu to configure network mode and port grouping on the Security Firewall.
Interface
Use this menu to configure interface address, subnet mask and VLAN ID settings on the Security Firewall.
Routing
Use this menu to view and configure policy routes, static routes and WAN load balancing.
NAT
Use this menu to view and configure virtual servers and NAT settings.
Site-to-Site VPN
Use this menu to configure VPN rules between Security Firewalls.
Remote access VPN
Use this menu to enable and configure IPsec VPN or L2TP VPN rules from off-site clients to an on-site Security Firewall.
Security policy
Use this menu to configure firewall rules for outbound traffic, application patrol, schedule profiles and port forwarding rules for inbound traffic.
Security service
Use this menu to enable content filtering and block access to specific web sites. You can also enable Anti-virus and Intrusion Detection and Prevention (IDP) on the Security Firewall.
Captive portal
Use this menu to configure captive portal settings for each Security Firewall interface.
Authentication Method
Use this menu to configure network access settings through a captive portal or Nebula Cloud Authentication.
Wireless
Use this menu to configure different SSID profiles for your ZyWALL USG FLEX 100W and USG20W-VPN.
*This menu only appears for the ZyWALL USG FLEX 100W and USG20W-VPN.
Firewall settings
Use this menu to configure the DNS server and address records and also set the external AD (Active Directory) server or RADIUS server that the Security Firewall can use in authenticating users. You can also specify walled garden web site links for all interfaces on the Security Firewall.
Switch
 
Use these menus to monitor and configure the Switches managed by the NCC. The settings are applied when a Nebula Switch is registered and attached to the selected site.
Monitor
Switches
Use this menu to view the list of Switches added to the site.
Clients
Use this menu to view detailed information about the clients which are connecting to the Switches in the site.
Event log
Use this menu to view all events on the Switch. An event is something that has happened to a Nebula managed device.
IPTV report
Use this menu to view available IPTV channels and client information.
Surveillance
Use this screen to view information about Powered Devices (PDs) connected to ports on the Switch.
Summary report
Use this menu to view network statistics specific to Switches in the site.
Configure
Switch ports
Use this menu to view the Switch port statistics and configure Switch settings for the ports.
ACL
Use this menu to configure the access control list in order to control access to the Switches.
IP & Routing
Use this menu to configure layer 3 features such as creating IP interfaces and static routes on the Switch.
ONVIF discovery
Use this menu to enable ONVIF and configure ONVIF VLAN ID for the selected Switch.
Advanced IGMP
Use this menu to enable and configure IGMP snooping and create IGMP filtering profiles.
Authentication
Use this menu to configure authentication servers and policies.
PoE schedules
Use this menu to set the schedule for Switches in distributing power to powered devices.
Switch settings
Use this menu to configure global Switch settings, such as (R)STP, QoS, port mirroring, voice VLAN and DHCP white list.
Access Point
 
Use these menus to monitor and configure the Access Points managed by the NCC. The settings are applied when a Nebula Access Point is registered and attached to the selected site.
Monitor
Access points
Use this menu to view the list of Access Points added to the site.
Clients
Use this menu to view WiFi clients which are connected to the Access Points in the site.
Event log
Use this menu to view all events on the Access Point. An event is something that has happened to a Nebula managed device.
Wireless health
Use this menu to view health of the WiFi networks for the supported Access Points and connected clients.
Summary report
Use this menu to view network statistics specific to Access Points in the site.
Configure
SSID settings
Use this menu to view and configure SSID settings and authentication methods.
SSID advanced settings
Use this menu to configure network access, traffic options and advanced settings for SSID profiles.
Captive portal customization
Use this menu to configure captive portal settings for SSID profiles.
SSID availability
Use this menu to configure SSID visibility settings and set whether the SSID is enabled or disabled on each day of the week.
Radio settings
Use this menu to configure global radio settings, such as maximum output power or channel width, and enable smart client steering for all Access Points in the site.
Traffic shaping
Use this menu to configure the maximum bandwidth and load balancing.
Security service
Use this menu to enable application visibility and optimization, and IP reputation filter on the managed Access Point.
AP & port settings
Use this menu to configure load balancing settings and enable or disable a port on the managed Access Point and configure the port’s VLAN settings.
Create Organization
Use this screen to first create an organization, then create a site (network) in the organization, and finally add Nebula Devices to the site.
*You have to contact Zyxel customer support if you need to change the device owner at myZyxel or remove an Organization from the NCC. But an administrator can remove sites without customer support. Configure your Nebula Device owners and organizations carefully. See also License & Inventory.
*There is no limit as to how many organizations you can create, but you can only activate a trial license up to 10 new organizations every 90 days. The expiration date of the organization created using a trial license is shown.
1 Click Create Organization from the Organization drop-down list box in the title bar. The Wizard starts. See Setup Wizard for detailed information about how to use the wizard to create an organization and site. Otherwise, click Exit Wizard to close the wizard and display the Create organization screen.
2 Enter a name for your organization.
3 If you already have one or more than one organization under your account and you want to copy the organization settings of an existing one, select the organization name from the Copy setting from field and also Add this Org to MSP Teams by selecting existing teams before clicking the Create organization button.
4 Click the Create organization button to add a new organization.
Create Organization
5 Choose whether to activate a one-month trial of Nebula Pro Pack and Nebula Security Services for the organization. For example, USG FLEX 700, Secure WiFi License, 1MO; USG FLEX 700, UTM Security Pack License, 1MO; Nebula Professional Pack License, 1MO.
Choose Organization
When you have more than one organization on your account, the following screen displays right after you log in. Select the organization you want to manage now, access the MSP Portal or click Create organization to add a new one.
*You need to purchase an MSP license to see the MSP Portal menu.
Choose Organization
Cloud-Saving Mode
If you do not log into a base (free) license tier organization for over 30 days, the organization automatically enters Cloud-saving mode to save your network bandwidth and cloud resources.
When Cloud-saving is enabled, NCC does not record any data traffic statistics, except the following:
Event logs
Security Appliance WAN interface logs between the Nebula Device and NCC, and
NSS (Nebula Security Service) analysis report (requires Nebula Security Pack (Nebula Security Service) license).
To disable Cloud-saving mode, click the Cloud-saving mode switch or click the link in the NCC banner when notified.
Cloud-saving mode