Overview:
The Nebula cloud networking and management solution provides centralized control and visibility over all Nebula wired and wireless networking hardware — all without the cost and complexity of on-site control equipment or overlay management systems. With comprehensive product portfolio that can be centrally managed from the cloud, Nebula offers simple, intuitive and scalable management for all networks.
Nebula’s networking products, including access points, switches and security gateways, are purpose-built for cloud management. They break the traditions and come up with easy management, centralized control, autoconfiguration, real-time Web-based diagnostics, remote monitoring and more.
The Nebula cloud managed networking introduces an affordable, effortless approach for network deployments with high security and scalability to provide completely control over Nebula devices and users. When an organization grows from small sites to massive, distributed networks, the Nebula hardware with cloudbased self-provisioning enables easy, quick and plugn-play deployment to multiple locations without IT professionals.
Through Nebula cloud services, firmware and security signature updates are delivered seamlessly, while secure VPN tunnels can be established automatically between different branches over the Web with just a few clicks. Based on a secure infrastructure, Nebula is designed with fault-tolerant properties that enable local networks to keep operating properly in WAN downtimes.
One Cloud-based Management for ALL
All Nebula devices from access points, switches, security firewalls, routers, and mobile routers are managed through the cloud using an intuitive interface that allows you to configure, manage, and troubleshoot all distributed networks from one single screen without the complexity of remote site access.
'Zero touch' - Efficient Deployment
Simply scan the QR Code on each Nebula device or on the outer carton before on-site deployment. After being registered to a network, Nebula devices are automatically discovered when they’re connected and preconfigured settings are automatically applied.
Real-time updating and monitoring with historical data
Network topology is automatically drawn and updated each time a new device is added to the network.
Software updates to the cloud management interface and networking devices are automatically applied.
Access extended Alerts functionality including email & App alerts with selectable alert options & smart Alerting.
Access data history data for easy network activity tracking and troubleshooting.
Superb network performance for the best user experience
Nebula not only provides a stable network environment by incorporating a mechanism that prevents configurations that could potentially cause network disconnection between the device and NCC, but also comes with a comprehensive range of features such as DCS, Load Balancing and Smart Client Steering to ensure faster connections for the best user experience.
Highlights:
- Intuitive, automated network management interface as well as continuous feature updates that eliminate training and labor for network implementation, maintenance and support
- Zero-touch provisioning, built-in multi-tenant, multisite network management tools accelerate deployment of large networks
- Centralized, unified and on-demand control as well as visibility that reduce capital expense for hardware and software
- Free cloud management for the life of the product without the need for ongoing costs
- Access points and switches with NebulaFlex Pro, USG FLEX firewalls (0102 bundled SKUs), ATP firewalls, and Nebula 5G/LTE routers are sold with bundled Professional Pack license for you to experience advanced cloud management features
- A comprehensive networking and security product portfolio from a single vendor ensures better product compatibility
- Per-device licensing model with flexible subscriptions provides rich diversity and high flexibility for customers of all sizes
Solution Architecture:
The Nebula Cloud provides a networking paradigm for building and managing networks over the Internet in the Software as a Service model. Software as a Service (SaaS) is defined as a way of delivering software for users to access via the Internet rather than local installation. In the Nebula architecture, network functions and management services are pushed to the cloud and delivered as a service that provides instant control to the entire network without wireless controllers and overlay network management appliances.
Data Privacy and Out-of-band Control Plane
The Nebula service uses the infrastructure and services built upon the Amazon Web Service (AWS), so all Nebula security details can be referred to AWS Cloud Security. Nebula is committed to data protection, privacy and security as well as compliance with applicable regulatory frameworks in the world. Nebula’s technical architecture along with its internal administrative and procedural safeguards can assist customers with design and deployment of cloud-based networking solutions that comply with EU data privacy regulations.
In Nebula’s out-of-band control plane, network and management traffics are split into two different data paths. Management data (e.g. configuration, statistics, monitoring, etc.) turn towards Nebula’s cloud from devices through an encrypted Internet connection of the NETCONF protocol, while user data (e.g. Web browsing and internal applications, etc.) flows directly to the destination on the LAN or across the WAN without passing through the cloud.
All Nebula devices are built from the ground up for cloud management with the capability to communicate with Nebula’s cloud control center through the Internet. This TLS-secured connectivity between hardware and the cloud provides network-wide visibility and control for network management using the minimal bandwidth.
Over the cloud, thousands of Nebula devices around the world can be configured, controlled, monitored and managed under a single pane of glass. With multi-site network management tools, businesses are allowed to deploy new branches of any size, while administrators are able to make policy changes any time from a central control platform.
Features of the Nebula Architecture:
- End user data does not traverse through the cloud.
- Unlimited throughput, no centralized controller bottlenecks when new devices are added.
- Network functions even if connection to cloud is interrupted.
- Nebula’s cloud management is backed by a 99.99% uptime SLA.
NETCONF Standard
Nebula is an industry-first solution that implements NETCONF protocol for safety of configuration changes in cloud management as all NETCONF messages are protected by TLS and exchanged using secure transports. Prior to NETCONF, CLI scripting and SNMP were two common approaches; but they have several limitations such as lacking of transaction management or useful standard security and commit mechanisms. The NETCONF protocol has been designed to address the shortcomings of the existing practices and protocols.
With the support of TCP and Callhome to overcome the NAT barrier, NETCONF is considered more reliable and elegant. It is also thinner than CWMP (TR-069) SOAP, which saves Internet bandwidth. With these features, the NETCONF protocol is regarded as more suitable for cloud networking.
Nebula Control Center (NCC):
Nebula Control Center offers a powerful insight into distributed networks. Its intuitive and web-based interface illustrates an instant view and analysis of network performance, connectivity and status automatically and continuously. Integrated with organization-wide and sitewide management tools, Nebula provides a quick and remote access for administrators to ensure the network is up and performing efficiently.
Nebula Control Center is also engineered with a number of security tools that provide optimal protection to networks, devices and users; and they also deliver the needed information to enforce security and enhance control over the entire Nebula network.
Highlights
- Responsive web design and intuitive user interface with light & dark modes
- Multi-lingual management interface (English, Traditional Chinese, Japanese, German, French, Russian and more to come)
- Multi-tenant, multi-site manageability
- Role-based administration privileges
- First time setup wizard
- Powerful organization-wide management tools
- Rich site-wide management tools
- Site-based auto and smart configuration tools
- Misconfigured protection against disconnecting NCC
- Configuration changing alerts
- Login & Configure auditing
- Real-time and historical monitoring/reporting
- Granular device based information and trouble shooting tools
- Flexible firmware management
First Time Setup Wizard
Nebula first time setup wizard helps create your organization/site and setup an integrated network with only a few simple clicks, making your devices up and running in minutes.
Role-based Administration
Supervisors are allowed to appoint different privileges for multiple administrators to manage network and guess access. Specify management authority in the network access control function to maximize security and to avoid accidental misconfiguration.
Organization-wide Management Tools
Powerful organization-wide features such as organizational overview, configuration backup and restore, configuration template and configuration clone are supported to allow MSP and IT admins to manage their org/sites much easier.
Site-wide Management Tools
Integrated with the feature-rich dashboards, maps, floor plans, automatic visual and actionable network topology and site-based auto and smart configuring tools, the Nebula Control Center delivers instant network analysis and automatically performs AP authentication, configuration parity check, switch ports link aggregation and site-to-site VPN.
Misconfiguration Protection
To prevent any connectivity interruption caused by incorrect or inappropriate configuration, the Nebula devices can intelligently identify if the order or setting from NCC is correct to ensure the connection is always up with the Nebula cloud.
Configuration Changing Alerts
Configuration changing alerts help administrators to manage thousands of networking devices more efficiently, especially in larger or distributed sites. These real-time alerts are automatically sent from the Nebula Cloud system when configuration changes are made to keep new policies always up-to-date in the entire IT organization.
Login & Configure Auditing
The Nebula cloud control center automatically records the time and IP address of every logged in administrators. The configure audit log lets administrators track Web-based login actions on their Nebula networks to see what configuration changes were made and who made the changes.
Real-time & Historical Monitoring
Nebula Control center provides 24x7 monitoring over the entire network, giving administrators real-time and historical activity views with unlimited status records that can be backdated to the installation time.
Nebula Mobile App
The Nebula mobile app offers a fast approach to network management, providing an easy method for device registration and an instant view of real-time network status, which is particularly suitable for small business owners with little to no IT skills. With it, you can perform WiFi network configuration, break down usage by device and client, troubleshoot with live tools, check the status of connected Nebula devices and clients at a glance, and scan device QR codes to register large numbers of devices to the Nebula Control Center all at once. The app’s features and functions include:
Highlights
- Sign up Nebula account
- Installation walk through wizard for creating org & site, adding devices (QR code or manually), setting up WiFi networks
- Hardware install guide and LED guide
- Centralize 3-in-1 device status
- Per-device and site-wide usage graph
- Per-device and site-wide PoE consumption
- WiFi login info sharing via mobile phone or QR code
- Switch and gateway ports info
- Check map and photo of device location
- Firmware upgrade schedule
- Enable/disable SSID
- Site-wide client monitoring with action support
- Site-wide application usage analysis with action support
- License overview and inventory
- Live trouble shooting tools: reboot, Locator LED, switch port power cycle, cable diagnostics, connection test
- Tech support and MSP contact info
- Push notifications - Device down/up & license issue related
- Notification center up to 7 days alert history
Nebula Licenses:
Flexible Subscription for Your Needs
Nebula Control Center (NCC) offers multiple subscription options to meet customers’ needs. Whether you are looking for a complimentary option giving you some peace of mind at no extra cost, more control over your network updates and visibility, or even the most advanced management of cloud networking, Nebula is here to help you.
The plan you choose will determine the service level of Nebula Cloud.
Flexible Management License Subscription
Base Pack
License-free feature set/service with a rich set of management features
Plus Pack
An add-on feature set/service that includes all the features from free Nebula Base Pack as well as the most frequently requested advanced features to enable additional control of network updates and visibility.
Pro Pack
A full feature set/service that includes all the features from Nebula Plus Pack as well as additional advanced functionality and management features to enable maximum manageability of NCC for devices, sites, and organizations.
MSP Pack
Per-admin user account license that includes cross-org. management features and can be used in conjunction with existing Packs (Base/Plus/Pro).
M = Management Feature (NCC)
R = LTE/5G Mobile Router Feature
F = Firewall Feature
S = Switch Feature
W = Wireless Feature
M |
R |
F |
S |
W |
Feature Name |
Base Pack |
Plus Pack |
Pro Pack |
|
|
|
|
|
Unlimited Registration & Central Management (Configuration, Monitoring, Dashboard, Location Map & Floor Plan Visual) of Nebula Devices |
|
|
|
|
|
|
|
|
Zero Touch Auto-Deployment of Hardware/Configuration from Cloud |
|
|
|
|
|
|
|
|
Over-the-air Firmware Management |
|
|
|
|
|
|
|
|
IOS and Android APP (Deployment, Management and Push Notifications) |
|
|
|
|
|
|
|
Central Device and Client Monitoring (Log and Stat Information) and Reporting |
24HR (Rolling) |
7D (Rolling) |
1YR (Rolling) |
|
|
|
|
|
Admin Accounts per Organisation (Full Access for Administration Rights) |
5 |
8 |
NO LIMIT |
|
|
|
|
|
User Authentication Entries (via built-in Nebula Cloud Authentication Server) |
50 |
100 |
NO LIMIT |
|
|
|
|
|
Network Function Scheduling (SSID/PoE/Firewall Rules) |
|
|
|
|
|
|
|
|
MAC-Based and 802.1X Authentication |
|
|
|
|
|
|
|
|
Captive Portal Authentication |
|
|
|
|
|
|
|
|
Exempt from Cloud Saving Mode |
|
|
|
|
|
|
|
|
Advanced Firmware Scheduling (Org/Site/Device) |
|
|
|
|
|
|
|
|
Advanced Reporting Features (including Export/Email Reports/Scheduled Reports – Custom Logo) |
|
|
|
|
|
|
|
|
Automatic Network Topology (Visual and Actionable) |
|
|
|
|
|
|
|
|
Email users and alert Notifications |
|
|
|
|
|
|
|
|
WiFi Vouchers (Auto-Gen Vouchers for Access/Authentication with user defined time limits) |
|
|
|
|
|
|
|
|
Advanced Switch Control (Vendor Based VLAN, Auto PD Recovery) |
|
|
|
|
|
|
|
|
Organizational User Audit/Change Logs |
|
|
|
|
|
|
|
|
Organisational-wide Configuration Sync, Clone and Template |
|
|
|
|
|
|
|
|
Configuration Backup/Restore |
|
|
|
|
|
|
|
|
Remote CLI Access/Configurator |
|
|
|
|
|
|
|
|
Priority Nebula Support Request (Direct NCC incl. Web Chat) |
|
|
|
|
|
|
|
|
Open API for Ecosystem Partner Application Integration |
|
|
|
|
|
|
|
|
Advanced WiFi AAA Security (Dynamic Personal PSK, Dynamic VLAN Assignment via NCAS, 3rd Party AAA Integration incl. Captive Portal MAC Auth. Fallback) |
|
|
|
|
|
|
|
|
Advanced WiFi Control & Management (RSSI Threshold Setting per AP, Export NAT AP Traffic Log, Programmable SSID & PSK) |
|
|
|
|
|
|
|
|
Advanced Client Connection Monitoring & Trouble Shooting (WiFi Aid, Connection log) |
|
|
|
|
|
|
|
|
WiFi Health Monitoring and Report (AI/Machine Learning for Wireless) |
|
|
|
|
|
|
|
|
Switch IP Interfacing & Static Routing |
|
|
|
|
|
|
|
|
Switch Stacking (physical stacking) |
|
|
|
|
|
|
|
|
Switch Surveillance Monitoring |
|
|
|
|
|
|
|
|
Switch IPTV Feature Set (Advanced IGMP, IPTV Report w. AI/ML Alert) |
|
|
|
|
|
|
|
|
Zyxel CNM SecuReporter Traffic Log Archiving |
|
|
|
|
|
|
|
|
Firewall Advanced VPN Feature Set (VPN Topology, VPN Traffic Usage, Smart VPN, L2TP VPN Client Script Provisioning) |
|
|
|
|
|
|
|
|
Collaborative Detection & Response (CDR) with automatically respond action (USG FLEX & ATP Series only) |
|
|
|