The following article explains how to configure a non-default Management VLAN for Nebula-managed switches and access points.
1. What is a Management VLAN?
A Management VLAN is a dedicated VLAN used for managing network infrastructure such as switches and access points. Separating management traffic from user traffic helps prevent end users from directly accessing network devices and adds an additional layer of security to the network.
For example, user and guest traffic can use their own VLANs, while Nebula devices use a separate VLAN exclusively for management and communication with the Nebula Control Center (NCC).
When changing the Management VLAN, it is important to ensure that the new VLAN has the correct network configuration, including IP addressing, gateway access, and Internet connectivity. An incorrect VLAN or port configuration can cause a device to lose its connection to NCC and become unreachable for remote management.
This guide explains how to configure a Management VLAN other than the default VLAN for Nebula switches and access points while maintaining connectivity to NCC.
2. Example Network Topology
Configure the switch ports connected to the firewall and the access point to allow the VLANs required by the network topology.
In this example, the ports allow:
- VLAN 10 – Private Network
- VLAN 20 – Guest Network
- VLAN 100 – Management Network
The client VLANs (10 and 20) are specific to this example. For your own deployment, allow the client VLANs used by your network and make sure that the Management VLAN (VLAN 100 in this example) is permitted on the required uplink and AP ports.
3. Fall-back Mechanism
Nebula Switch and Access Points include an Auto configuration recovery mechanism designed to help prevent loss of connectivity after configuration changes.
If a configuration change causes the switch to lose connectivity, the device can automatically revert to a previously working configuration.
You can verify that this feature is enabled under:
Site-wide > Configure > Switches > Switch settings > Auto configuration recovery
Before making changes to the Management VLAN, make sure this option is enabled and verify that the new VLAN provides the required IP addressing, gateway, and Internet access for communication with the Nebula Control Center (NCC).
The key to successfully configuring a new management IP address or VLAN is to ensure that both old and new settings can reach the Internet. Only after Nebula CC has verified that the changes made on the device does not cause loss of Internet access can you start scaling-back, removing VLANs, or IP interfaces on your switches and gateways.
4. Configure the Management VLAN on the Firewall
Create the required VLAN interfaces on the USG FLEX H and assign them to the physical interface connected to the switch. In this example, all VLANs use port p7.
- VLAN 10 – Private Network:
192.168.10.1/24, Zone: LAN - VLAN 20 – Guest Network:
192.168.20.1/24, Zone: DMZ - VLAN 100 – Management Network:
192.168.100.1/24, Zone: LAN
Enable DHCP on each VLAN interface as required.
The firewall sends these VLANs as tagged traffic through p7. The switch uplink port must therefore be configured to allow VLANs 10, 20, and 100.
Site-wide Configure Firewall Port & Interface > LAN Interface [+Add]5. Configure the switch uplink and AP Ports to allow VLAN 100.
Site-wide > Configure > Switch > Switch ports Configure the switch ports connected to the firewall and the access point so that all VLANs required by the network topology can pass through them.
In this example:
- VLAN 10 – Private Network
- VLAN 20 – Guest Network
- VLAN 100 – Management Network
Open the port settings for both the firewall uplink port and the port connected to the access point, and configure them as Trunk ports.
The firewall uplink port must allow VLAN 100 so that the switch can reach the Management Network. VLANs 10 and 20 are also allowed so that user and guest traffic can be forwarded through the firewall.
The port connected to the access point must allow VLAN 10 and VLAN 20 for the wireless client networks, as well as VLAN 100 for management of the access point.
6. Configure the Switch Management IP and VLAN
Site-wide > Devices > Switches > Select Switch > Edit LAN IP.Navigate to:
Site-wide > Devices > Switches > Select Switch > Edit LAN IP
Configure the switch to use the Management VLAN created on the firewall.
In this example:
- IP type: Static IP
- IP address: 192.168.100.11
- VLAN: 100
- Subnet mask: 255.255.255.0
- Gateway: 192.168.100.1
- Primary DNS: 8.8.8.8
Click OK to apply the changes.
After the configuration is applied, the switch will move from the previous management network to VLAN 100 and use the new management IP address.
Allow a few minutes for the switch to reconnect to the Nebula Control Center.
Note: If the switch does not reconnect or the updated LAN IP/VLAN information is not reflected after waiting a few minutes, briefly disconnect and reconnect the Ethernet cable on the uplink port. This forces the physical link to renegotiate and can help the switch re-establish connectivity using the new Management VLAN settings.
Before doing this, verify that VLAN 100 is allowed on both the firewall interface and the switch uplink port.
7. Setting the Management VLAN of the Access Point
After configuring the switch port connected to the access point to allow the Management VLAN, configure the access point itself to use VLAN 100 for management traffic.
Navigate to:
Site-wide > Devices > Access points > Select Access Point > Edit LAN IP
Configure the access point to use the Management VLAN.
In this example:
- IP type: Static IP
- IP address: 192.168.100.15
- Management VLAN ID: 100
- VLAN tagging: Tagged
- Subnet mask: 255.255.255.0
- Gateway: 192.168.100.1
- Primary DNS: 8.8.8.8
Click OK to apply the configuration.
Because VLAN 100 is configured as a tagged VLAN on the switch port connected to the access point, select Tagged for the Management VLAN.
After applying the configuration, allow a few minutes for the access point to reconnect to the Nebula Control Center (NCC).
Verify that the AP is online and that its LAN IP belongs to the Management VLAN subnet (192.168.100.0/24).
Important: Make sure VLAN 100 is allowed on the switch port connected to the access point before changing the AP Management VLAN. Otherwise, the AP may lose connectivity to NCC.
Note: After changing the AP Management VLAN and assigning a new static management IP, the access point may temporarily lose connectivity. If it does not reconnect after a few minutes, briefly disconnect and reconnect the Ethernet/PoE cable to renegotiate the link and apply the new network settings

Comments
0 commentsPlease sign in to leave a comment.