ZyXEL NSG50 Nebula Cloud Security Gateway

ZyXEL NSG50 Nebula Cloud Security Gateway
Key Features
  • 4 x Gigabit Ethernet LAN Ports
  • 2 x WAN Ports (1 x SFP, 1 x GbE)
  • 1 x USB Port
  • 1 x RJ45 Console Port
Show More
With a variety of security features, including an ICSA-certified firewall, IPsec VPN connectivity, Intrusion Detection and Prevention (IDP), and Application Patrol, the NSG50 Nebula Cloud Security Gateway from Zyxel offers enhanced security while providing intuitive remote management functionality.
Special Order
Expected availability: 7-14 business days
$50/mo. suggested payments.*
with 6 Mos. Promo Financing
Akiva M., B&H Computer Expert

True Know-How

Ask Our Experts


ZyXEL NSG50 Overview

  • 1Description
  • 2Out-of-the-Box Cloud-Managed Gateway
  • 3Easy Setup, Simple Management
  • 4Zero-Touch VPN Connections
  • 5Streamlined Policy Management
  • 6Effective Network Protection
  • 7Power Application Security
  • 8Firewall
  • 9IPSec VPN
  • 10Intrusion Detection and Prevention (IDP)
  • 11Application Protocol
  • 12Networking
  • 13Authentication
  • 14Captive Portal
  • 15System Management
  • 16Logging and Monitoring

With a variety of security features, including an ICSA-certified firewall, IPsec VPN connectivity, Intrusion Detection and Prevention (IDP), and Application Patrol, the NSG50 Nebula Cloud Security Gateway from Zyxel offers enhanced security while providing intuitive remote management functionality.

With the Nebula Cloud, network admins can manage multiple Nebula gateways from a single point with the ability to manage event logs, monitor traffic statistics, and more. Once configured, the Nebula Cloud Security Gateway offers enhanced firewall functionality with a variety of features, including stateful packet inspection, VLAN support, PPPoE, static route support, and much more. Additionally, this gateway offers streamlined policy management including a unified policy management interface, IDP, application protocol, and firewall (ACL) features, along with source and destination IP addressing and destination port and time policy criteria.

The NSG50 Nebula Cloud Security Gateway comes equipped with four Gigabit LAN ports, a single SFP WAN port, and a single GbE WAN port. Alongside the network ports is a single USB port and a single RJ45 console port. Installation is simple, as the gateway comes wall mountable and features a fanless design for quiet operation.

Out-of-the-Box Cloud-Managed Gateway

The Zyxel NSG50 can be easily deployed at a remote location through nearly zero-touch cloud provisioning. It automatically pulls policies and configuration settings, and receives seamless firmware upgrades and security signature updates from the cloud without the need for on-site networking expertise.

Easy Setup, Simple Management

Traditional gateways require administrators to perform configuration and to manage security policies on each device one by one which costs considerable time and effort. The Zyxel Nebula provides a single point of management to all the Nebula gateways for administrators to synchronize security settings across thousands of sites to every device all at once. The cloud interface provides site-wide visibility and control that enable administrators to manage event logs, traffic statistics, bandwidth consumption, networked clients, and application usage without access to the individual devices.

Zero-Touch VPN Connections

Establish a VPN to keep branch locations securely connected. With the Zyxel Nebula Security Gateway, either site-to-site or hub-and-spoke VPN connections can be configured with complete simplicity through few clicks in the Nebula Control Center, without complex VPN configuration steps. The intuitive cloud management interface gives administrators a real-time view to monitor VPN connectivity between multiple locations.

Streamlined Policy Management

The Zyxel Nebula Security Gateway streamlines configuration of your firewall and security features for faster, easier, and more consistent policy settings by supporting object-based management and a unified configuration. Moreover, any configuration made in the Nebula Control Center can automatically propagate to all the connected Nebula gateways.

Effective Network Protection

Nebula's IDP (Intrusion Detection and Prevention) system scans multiple layers and protocols to inspect vulnerabilities invisible to simple port- and protocol-based firewalls by utilizing Deep Packet Inspection (DPI) technology that eliminates false positives with a database of malware signatures and provides effective protection against intrusion from unknown back doors.

Power Application Security

The Zyxel Nebula Security Gateway supports Application Patrol, which can identify, categorize, and control social, gaming, productivity, and other Web applications and behaviors. Users can block undesirable applications to boost productivity and prevent bandwidth abuse.


• Stateful packet inspection
• User-aware policy enforcement
• Static route
• Firewall
• Intrusion Detection and Prevention (IDP)
• Application Patrol


• Topology: Site-to-site, hubs-and-spoke
• Encryption: AES (256-bit), 3DES and DES
• Authentication: SHA-2 (512-bit), SHA-1 and MD5
• Perfect forward secrecy (DH groups) support 1, 2, 5, 14
• IPSec NAT traversal
• Dead peer detection and relay detection
• VPN auto-reconnection
• L2TP over IPSec

Intrusion Detection and Prevention (IDP)

• Signature-based
• Behavior-based scanning
• Automatic signature updates

Application Protocol

• Granular control over the most important applications
• Identifies and controls applications and behaviors
• Top application usage record


• Routing mode
• Ethernet and PPPoE
• VLAN tagging (802.1Q)
• DHCP client/server/relay
• Dynamic DNS support
• Maximum bandwidth
• Bandwidth limit per client IP


• Microsoft Windows Active Directory integration
• External RADIUS user database
• Nebula Cloud (Nebula Control Center) authentication

Captive Portal

• Web-based authentication
• Forced user authentication (transparent authentication)
• Sign-on or click-to-continue authentication
• Multiple instances of captive portal
• Customizable portal templates
• Internal or external captive portal redirect
• Walled garden support

System Management

• Cloud managed
• Role-based administration
• SNMP v2c (MIB-II)
• System configuration rollback
• Cloud firmware upgrade

Logging and Monitoring

• Comprehensive local logging
• Syslog (to up to 2 servers)
• Real-time traffic monitoring

ZyXEL NSG50 Specs

Hardware Specifications10/100/1000 Mb/s RJ45 Ports
4 x LAN (GbE)
2 x WAN (1 x SFP, 1 x GbE)
USB Ports
Console Port
Yes (RJ45)
System Capacity & PerformanceSPI Firewall Throughput
300 Mb/s
VPN Throughput
70 Mb/s
IDP Throughput
120 Mb/s
Unlimited User
Max. TCP Concurrent Sessions
Max. TCP Session Rate
Max. Concurrent IPsec VPN Tunnels
Customizable Zones
VLAN Interface
Virtual Private Network (VPN)
Yes (IPSec, L2TP over IPSec)
Application Patrol
Intrusion Detection and Prevention (IDP)
Bandwidth Management
PowerPower Input
12 VDC, 2.0 A max.
Max. Power Consumption
12.0 W
Heat Dissipation
40.95 BTU/hr
Temperature & HumidityOperating Temperature
32 to 104°F / 0 to 40°C
Storage Temperature
-22 to 158°F / -30 to 70°C
Operating Humidity
10 to 90% non-condensing
Storage Humidity
10 to 90% non-condensing
MTBF44,000 hours
FCC Part 15 (Class B), IC, CE
EMC (Class B), RCM, BSMI
Dimensions8.50 x 5.63 x 1.30" / 216 x 143 x 33 mm
Weight2.29 lb / 1.04 kg
See any errors on this page? Let us know


Browsing History