Nebula Cloud Monitoring Mode allows you to monitor an on-premises Zyxel firewall through Nebula Control Center (NCC) while keeping the firewall configuration locally managed. It also provides features such as Remote SSH, Remote Web GUI, and configuration backup.
Requirements before starting:
- The firewall must already be registered to the Zyxel/MyZyxel account used for the Nebula organization.
- The firewall must run firmware later than V5.37.
- Create a Nebula Organization and Site if they do not already exist.
Step 1 – Add the Firewall to Cloud Monitoring Mode
In Nebula Control Center, go to:
Organization-wide > Organization-wide manage > Organization settings
Copy the Cloud Monitoring Mode ID.
Step 2 – Enable Cloud Monitoring Mode on the Firewall
Log in to the firewall's local Web GUI and go to:
Configuration > Mgmt. & Analytics > Nebula
- Enable Cloud Monitoring Mode.
- Paste the Cloud Monitoring Mode ID.
- Click Apply.
The status will first change to Connecting and then to Connected after the firewall successfully connects to Nebula.
Step 3 – Assign the Firewall to a Site
In Nebula, go to:
Organization-wide > License & inventory > Devices
The firewall should appear with the device type Firewall (Monitor only).
Select the firewall and click:
Actions > Change site assignment
Select the required site and save the changes.
Step 4 – Verify the Connection
Go to:
Site-wide > Devices > Firewall
Verify that the firewall is online and operating in Monitor Mode.
Remove the Firewall from Cloud Monitoring Mode
Step 1 – Remove the Firewall from Nebula
In Nebula, go to:
Organization-wide > License & inventory > Devices
Select the firewall and click Remove from organization.
Step 2 – Disable Cloud Monitoring Mode
Log in to the firewall's local Web GUI and go to:
Configuration > Mgmt. & Analytics > Nebula > Cloud Monitoring Mode
Clear Enable and apply the changes.
The firewall will remain in on-premises/standalone management mode and will no longer be monitored by Nebula.
Enable or Disable Cloud Monitoring Mode Using CLI
Enter configuration mode:
configure terminalEnable Cloud Monitoring Mode
Enable Monitor Mode:
monitor-modeSpecify the Nebula organization Cloud Monitoring Mode ID:
monitor-mode id <Cloud-Monitoring-Mode-ID>Verify the connection:
show monitor-modeA successful connection should show values such as:
active: yes
status: connected
is_connected: yesThese commands and status output are documented in the Zyxel ZLD CLI Reference Guide.
Disable Cloud Monitoring Mode
Note: no monitor-mode disables Cloud Monitoring Mode on the firewall. To completely remove the firewall from the Nebula organization, first remove the device under Organization-wide > License & inventory > Devices in NCC.
Enter configuration mode and disable Monitor Mode:
configure terminal
no monitor-modeVerify the status:
show monitor-mode

Comments
0 commentsPlease sign in to leave a comment.