title=

Setting up GeoIP blocking for web services using pfSense, HAProxy and free IPDeny databases

One of the ways to protect a web service may be to restrict access to it by IP, including GeoIP, based on the user's location. We will set up protection without using paid services, without Maxmind, without registration and SMS Today, many organizations that transfer their services to web platforms are forced to provide an entry point to the Internet for user authentication. Even with 2-factor authentication, a web service accessible via the Internet remains vulnerable to complex attacks, the ...
 title=

Let's explore the features of Zyxel XMG1930-30HP, a switch with 2.5G/10G PoE ports and licensed L3 functions

Zyxel reasoned this way: if the L3 functionality is already determined only by the firmware, 99% choose an access switch for the sake of port density, PoE, VLAN, Multicast, and less often for static routing, then here's the base model XMG1930, which is generally L2, but slightly L3. And if your network requires advanced L3 functions, then all this is also there, just buy the appropriate license and get the core-level functionality. You can do this at any time, even when buying a device, even ...
 title=

Zyxel XGS2220-30HP - L3 Access switch for modern converged networks

This L3 layer switch has 4 x 10-Gigabit SFP+ slots, 1-Gigabit PoE+ ports for the main fleet of devices, NVR/VoIP optimized interface, support for Nebula cloud service and multi-Gigabit PoE+ ports for Wi-Fi 6 access points. That is, Zyxel has added a maximum of functions to make it the most versatile. In the Zyxel hierarchy, the XGS2220 series refers to access switches, that is, to the lowest level that serves end devices and access points. We are used to the fact that cheap maintenance-free ...
 title=

We explore Zyxel Connect & Protect and answer the main questions: is it possible to do without a security gateway?

From the point of view of the network, a modern facility can be just one access point connected directly to the WAN from the provider, and there are enough resources on this access point to raise the VPN tunnel to the headquarters, and for NAT, and to configure restrictions for customers and for basic protection of customers and employees. No, but really, why should an expensive security gateway be built on a small facility where the network infrastructure is completely wireless? Modern ...
 title=

Will Zyxel Nebula survive on the sovereign internet?

What will happen to your network if the Iron Curtain suddenly falls, and the Global Internet turns into something sovereign and all cross-border channels are blocked? Let's simulate this situation and tell you how to unsign the device from Nebula without Internet access. We have reviewed the Nebula Control Center management system from Zyxel many times. This is a cloud service that allows you to configure and monitor the company's network stack via the Internet, including setting up Wi-Fi, ...
 title=

Orchestration of wireless networks in Zyxel Nebula CC: configuring horizontal traffic protection and shaping

Modern Zyxel access points allow you to work in NAT and bridge mode simultaneously for different SSIDs, connect users using 2FA, shape traffic depending on the application and flexibly use VLANs. Let's look at how you can configure a wireless network to protect horizontal traffic. Modern networks are gradually changing the traditional topology, in which a security gateway was installed on top, and the network was segmented at L2/L3 levels using switches from below. The modern network is ...
 title=

Quick setup of a wireless network via Zyxel Nebula when deployed in branches

... an opportunity when using the Nebula service. Let's consider ... an opportunity when using the Nebula service. Let me briefly ... remind you that Nebula Control Center is a ... to his organization through the Nebula Control Center application. Step ... the MAC address of the security gateway and be sure that ... is organized quite interestingly in Nebula: a log is displayed ... device class, which will give you an understanding of port ... download the configuration from the Nebula cloud, and you will ...
 title=

How Zyxel Secureporter facilitates corporate network security monitoring

... operation of your network's security gateway. Naturally, only Zyxel gateways ... based network stack management system, Nebula Control Center (NCC), to ... operation of your network's security gateway. Naturally, only Zyxel gateways ... policies. Mandatory conditions - connection to Nebula The Secureporter service is tightly ... need to pay extra for GoIP - everything is included in ... even the best signatures initially give a lot of false ... this information directly in the Nebula Control Center, without going ...
 title=

VPN orchestration from Zyxel: we configure any tunnel scenarios, even without knowing the gateway addresses

... about the existence of the Nebula VPN orchestrator. Each gateway participating ... management is done through the Nebula cloud, and the connection ... configuration of the entire network: Nebula itself will prescribe routing from ... Internet traffic through a corporate security gateway. In part, this approach ... wireless access point and a security gateway. Yes, you were not ... - adding users Since the Nebula Control Center cloud controller takes ... laptop or smartphone will not give the attacker access to the ...
 title=

Zyxel Nebula vs TP-Link Omada: comparing centralized network management systems

In large corporate networks with a complex topology, the real hell for the administrator will be the sequential configuration of all connected devices, one by one. In such cases, it is often almost impossible to detect errors in the network or determine its state. Who has the best orchestration tools today, Zyxel or TP-Link? In large corporate networks with a complex topology, the real hell for the administrator will be the sequential configuration of all connected devices, one by one. In ...