Nebula Cloud Monitoring Mode – How to Add or Remove a Firewall

Print Friendly and PDF
Have more questions? Submit a request

Nebula Cloud Monitoring Mode allows you to monitor an on-premises Zyxel firewall through Nebula Control Center (NCC) while keeping the firewall configuration locally managed. It also provides features such as Remote SSH, Remote Web GUI, and configuration backup.

Requirements before starting:

  • The firewall must already be registered to the Zyxel/MyZyxel account used for the Nebula organization.
  • The firewall must run firmware later than V5.37.
  • Create a Nebula Organization and Site if they do not already exist.

Step 1 – Add the Firewall to Cloud Monitoring Mode

In Nebula Control Center, go to:

Organization-wide > Organization-wide manage > Organization settings

Copy the Cloud Monitoring Mode ID.

Step 2 – Enable Cloud Monitoring Mode on the Firewall

Log in to the firewall's local Web GUI and go to:

Configuration > Mgmt. & Analytics > Nebula

  1. Enable Cloud Monitoring Mode.
  2. Paste the Cloud Monitoring Mode ID.
  3. Click Apply.

The status will first change to Connecting and then to Connected after the firewall successfully connects to Nebula.

Step 3 – Assign the Firewall to a Site

In Nebula, go to:

Organization-wide > License & inventory > Devices

The firewall should appear with the device type Firewall (Monitor only).

Select the firewall and click:

Actions > Change site assignment

Select the required site and save the changes.

Step 4 – Verify the Connection

Go to:

Site-wide > Devices > Firewall

Verify that the firewall is online and operating in Monitor Mode.

Remove the Firewall from Cloud Monitoring Mode

Step 1 – Remove the Firewall from Nebula

In Nebula, go to:

Organization-wide > License & inventory > Devices

Select the firewall and click Remove from organization.

Step 2 – Disable Cloud Monitoring Mode

Log in to the firewall's local Web GUI and go to:

Configuration > Mgmt. & Analytics > Nebula > Cloud Monitoring Mode

Clear Enable and apply the changes.

The firewall will remain in on-premises/standalone management mode and will no longer be monitored by Nebula.

Enable or Disable Cloud Monitoring Mode Using CLI

Enter configuration mode:

configure terminal

Enable Cloud Monitoring Mode

Enable Monitor Mode:

monitor-mode

Specify the Nebula organization Cloud Monitoring Mode ID:

monitor-mode id <Cloud-Monitoring-Mode-ID>

Verify the connection:

show monitor-mode

A successful connection should show values such as:

active: yes
status: connected
is_connected: yes

These commands and status output are documented in the Zyxel ZLD CLI Reference Guide.

Disable Cloud Monitoring Mode

Note: no monitor-mode disables Cloud Monitoring Mode on the firewall. To completely remove the firewall from the Nebula organization, first remove the device under Organization-wide > License & inventory > Devices in NCC. 

Enter configuration mode and disable Monitor Mode:

configure terminal
no monitor-mode

Verify the status:

show monitor-mode

Articles in this section

Was this article helpful?
0 out of 0 found this helpful
Share

Comments

0 comments

Please sign in to leave a comment.