title=

Setting up Tailscale on the Zyxel USG Flex 500H gateway

... VPN service based on the WireGuard protocol that simplifies building secure ... the Zyxel USG Flex 500H security gateway, analyze the configuration features, ... SSH, SNMP, command line and Nebula cloud, as well as flexible ... VPN router. This is useful if you need to provide secure ... the entire VPN session, while maintaining routing and security controls on ... inside the VPN, without leaving the secure channel. This increases security, as ... integrating Tailscale with existing corporate VPN solutions. To do this, ...
 title=

Setting up protection against IT attacks in the enterprise using Zyxel equipment

A typical IoT attack looks like this: the device connects to a malicious Internet resource directly or through its own VPN, downloads and installs malicious code on itself, after which it begins to be either part of a large bot farm for attacks on third-party resources and use as a resident proxy, or simply spies on your network, trying to intercept anythat data, pull information from open resources or harm in any other way. It is not difficult to protect your network from possible IoT attacks. ...
 title=

Bulletin on IoT security. Is your network ready for Internet of Things exploits?

Not so long ago, Human Security revealed an entire shadow network associated with infected devices and malicious applications. Infected were not only Android TV set-top boxes, but also tablet PCs, wearable devices and even cars. Some IoT devices may even be infected with viruses or Trojans already at the stage of their production or sale, and since it is impossible to imagine a modern company without IoT today, it is important to properly protect your network. Today's world is completely ...
 title=

Setting up GeoIP blocking for web services using pfSense, HAProxy and free IPDeny databases

One of the ways to protect a web service may be to restrict access to it by IP, including GeoIP, based on the user's location. We will set up protection without using paid services, without Maxmind, without registration and SMS Today, many organizations that transfer their services to web platforms are forced to provide an entry point to the Internet for user authentication. Even with 2-factor authentication, a web service accessible via the Internet remains vulnerable to complex attacks, the ...
 title=

Let's explore the features of Zyxel XMG1930-30HP, a switch with 2.5G/10G PoE ports and licensed L3 functions

Zyxel reasoned this way: if the L3 functionality is already determined only by the firmware, 99% choose an access switch for the sake of port density, PoE, VLAN, Multicast, and less often for static routing, then here's the base model XMG1930, which is generally L2, but slightly L3. And if your network requires advanced L3 functions, then all this is also there, just buy the appropriate license and get the core-level functionality. You can do this at any time, even when buying a device, even ...
 title=

Zyxel XGS2220-30HP - L3 Access switch for modern converged networks

This L3 layer switch has 4 x 10-Gigabit SFP+ slots, 1-Gigabit PoE+ ports for the main fleet of devices, NVR/VoIP optimized interface, support for Nebula cloud service and multi-Gigabit PoE+ ports for Wi-Fi 6 access points. That is, Zyxel has added a maximum of functions to make it the most versatile. In the Zyxel hierarchy, the XGS2220 series refers to access switches, that is, to the lowest level that serves end devices and access points. We are used to the fact that cheap maintenance-free ...
 title=

We explore Zyxel Connect & Protect and answer the main questions: is it possible to do without a security gateway?

... access point to raise the VPN tunnel to the headquarters, ... access point to raise the VPN tunnel to the headquarters, ... includes. What about blocking VPN? If the user uses ... restrict access for the entire VPN tunnel. Naturally, CNP will ... the user's work via VPN, too. Both tunneling protocols ... including OpenVPN and Wireguard) and VPN services such as NordVPN and ... enabled redirect all traffic through Nebula? No, the access point ... Connect and Protect replace a security gateway in small installations? In ...
 title=

Will Zyxel Nebula survive on the sovereign internet?

What will happen to your network if the Iron Curtain suddenly falls, and the Global Internet turns into something sovereign and all cross-border channels are blocked? Let's simulate this situation and tell you how to unsign the device from Nebula without Internet access. We have reviewed the Nebula Control Center management system from Zyxel many times. This is a cloud service that allows you to configure and monitor the company's network stack via the Internet, including setting up Wi-Fi, ...
 title=

Orchestration of wireless networks in Zyxel Nebula CC: configuring horizontal traffic protection and shaping

... traditional topology, in which a security gateway was installed on top, ... is broadcast immediately to the security gateway, on which the access ... related to wireless connection security settings is set at ... direct channel via VPN to the headquarters (Secure WiFi technology, which ... patrol and reputation filter, - security functions that are applied to ... equally interesting function related to security: This is connecting users ... scary. Conclusions The Zyxel Nebula Control Center cloud management system ...
 title=

Quick setup of a wireless network via Zyxel Nebula when deployed in branches

... an opportunity when using the Nebula service. Let's consider a ... an opportunity when using the Nebula service. Let me briefly remind ... about  setting up various VPN scenarios  via Nebula. One of the advantages ... to his organization through the Nebula Control Center application. Step 2 ... the MAC address of the security gateway and be sure that wireless ... is organized quite interestingly in Nebula: a log is displayed separately ... download the configuration from the Nebula cloud, and you will only ...