Zyxel Nebula captive portal: built in and external
Nebula access points get their captive portal from the Nebula Control Center, with several sign in methods and a switch to use a login page you host. Here is what each does, from Zyxel’s own guide.
Not supported by VoqadoWiFi. Written from Zyxel documentation read on 7 October 2026.
What Nebula is and who runs it
Zyxel Nebula is a cloud managed range: access points and security gateways are configured from the Nebula Control Center (NCC). Captive portal settings sit with each SSID under the access point settings, so the portal is a cloud setting rather than something on the device.
Using a login page from an external web portal
Under Captive portal customization in the NCC you can switch to a custom login page from an external web portal instead of the one built into the NCC, and specify the page’s URL. Zyxel provides a ZIP of example captive portal HTML files to download, edit and host on a web server.
Zyxel’s guide does not list the parameters the access point sends. A Zyxel staff answer on the Zyxel community shows them in an example link: gw_addr, apmac, usermac, apip, userip, auth_path and apurl, where apurl points at the access point’s Clicktocontinue.cgi. For a click to continue page, the button has to call the script that notifies the access point through that address, and the thread says the control code in the sample page cannot be changed.
In plain terms, the guest browser tells the access point the guest accepted, and the access point opens the network. The exact fields that post carries are not in the guide, which is why this flow needs testing on hardware before anyone relies on it.
Guest WiFi you can run on Zyxel Nebula today
| Option | What it does | Source |
|---|---|---|
| Click-to-continue | Traffic is blocked until the guest agrees to the user agreement; the device uses an internal account to authenticate them. | Vendor docs |
| Voucher | Guests log in with a unique printable code for time limited access; the expiry counts down after the first login. | Vendor docs |
| Sign-on with Nebula cloud authentication | Guests authenticate against the NCC user database. | Vendor docs |
| Sign-on with My RADIUS server | Guests authenticate against your RADIUS server, with optional MAC authentication fallback. | Vendor docs |
| Sign-on with Facebook | Guests authenticate with Facebook Login. | Vendor docs |
| Walled garden | Wildcard domains or IP addresses reachable without logging in. | Vendor docs |
Vouchers suit venues that sell or ration access, such as a hotel lobby or a coworking day pass. Click-to-continue covers a plain terms page with nothing else to run.
Reauthentication and the walled garden
Captive portal reauthentication is set per type of user, including click-to-continue users and RADIUS users, so you decide how often each kind of guest sees the portal again.
If you host your own login page, add its domain to the walled garden, or the phone cannot load it before the guest is let through.
VoqadoWiFi and Zyxel Nebula: the honest status
VoqadoWiFi does not support Zyxel Nebula today. VoqadoWiFi works with two controller platforms: TP-Link Omada and Ubiquiti UniFi. On those, the controller sends each new guest to the VoqadoWiFi login page as an external captive portal, and VoqadoWiFi asks the controller to open the network once the guest signs in.
This page describes what Zyxel documents, so you can decide what to do with the hardware you have. It is not a setup guide for VoqadoWiFi, and nothing on it means VoqadoWiFi works with Zyxel Nebula.
| Question | Answer |
|---|---|
| VoqadoWiFi status | Not supported by VoqadoWiFi yet |
| What the vendor calls the external portal | Captive portal customization, external web portal |
| How access is granted, as documented | Form post from the guest browser. After the guest signs in, the guest browser posts a small form back to the access point or router, which then opens the network. |
Click to continue on Nebula is plausible for an external portal, but the post to the access point is only shown in a community thread, not the guide, so it would need proving on Nebula hardware. VoqadoWiFi has not built it, and there is no date.
If you are choosing hardware now, the TP-Link Omada setup guide and the Ubiquiti UniFi setup guide show exactly what VoqadoWiFi needs. If you are keeping your current hardware, its own options above work today without us.
Zyxel Nebula questions
Can Zyxel Nebula use an external captive portal?
What sign in methods does Nebula offer?
How do Nebula vouchers work?
Does VoqadoWiFi work with Zyxel Nebula?
Sources
Every Zyxel fact on this page comes from these official pages, read on 7 October 2026. Menus and features change between releases, so check them against your own version.
Keep reading
Zyxel and Nebula are trademarks of Zyxel Communications. VoqadoWiFi is not affiliated with, endorsed by, or sponsored by Zyxel.