Zyxel Nebula Control Center
This guide will show you how to connect your branch in Zyxel Nebula Control Center to the GoodAccess Gateway via a site-to-site connection using the IPSec protocol.
Last updated
Was this helpful?
This guide will show you how to connect your branch in Zyxel Nebula Control Center to the GoodAccess Gateway via a site-to-site connection using the IPSec protocol.
Log in to the GoodAccess Control Panel, and go to Network > Clouds & Branches.
Click + Add new, enter a Name (e.g., Prague Office), select the required Gateway, and define your local Subnets (using CIDR notation).
Choose IPSec Protocol, and click Continue.
Fill out the configuration form (Public IP, Pre-Shared Key, etc.). These parameters must match the configuration you will set on your device in the next steps.
Click Submit to finish, or Continue to define optional Branch Segments for finer access control.
You may return to the configuration via the Edit button of your Branch at any time.
Example of configuration (Default preset):
Shared Secret - Create a new strong password
Public IP - IP of your site
IKE Lifetime (Phase 1) - 8 hours (28800 seconds)
Tunnel Lifetime (Phase 2) - 1 hour (3600 seconds)
Dead Peer Detection Delay - 30 seconds
Encryption (Phase 1) - aes256
Encryption (Phase 2) - aes256
Integrity (Phase 1) - sha256
Integrity (Phase 2) - sha256
Diffie-Hellman Groups (Phase 1) - 16 - modp4096
Diffie-Hellman Groups (Phase 2) - 16 - modp4096
Log in to the Zyxel Nebula Control Center, and switch to the site you want to connect to GoodAccess.
Go to Configure > Firewall > Site-to-Site VPN.

Enable the local network you want to access via GoodAccess.
Under the Non-Nebula VPN peers section click on the + Add button, give it a name, and set the configuration as follows:
Public IP - IP of your GoodAccess Gateway
Private subnet - Subnet of your GoodAccess Gateway
Pre-shared secret - Shared Secret (Step 1)
Click on the Default button, and set the configuration as follows:
IKE version - IKEv2
Phase 1 & 2 - Must match configuration from GoodAccess (Step 1)
Click OK, and then Save.


You have now successfully connected your branch to GoodAccess.
Firewall rules
Make sure that your device allows incoming connections from your GoodAccess Gateway private subnet on the following ports:
UDP 500
UDP 4500
You may check the status of the connection in:
GoodAccess: Go to Control Panel > Network > Clouds & Branches to view the tunnel status. Use the Test Connection button to validate the IPsec tunnel itself, or optionally to test a specific system (target must have ICMP enabled).
Nebula Control Center: Go to Monitor > Firewall > VPN connections.
Last updated
Was this helpful?
Was this helpful?