SCR50AXE [Secure Cloud-managed Router] - Configure in Nebula and Getting Started

This article addresses the introduction SCR50AXE, benefits, and limitations, along with step-by-step instructions on registering your device, configuring NAT (Port Forwarding), and setting up Site-to-site VPN, with subsections covering configuration for another Nebula Router/Gateway and a non-Nebula Router/Gateway, and concluding with guidance on configuring static IP on LAN devices

Disclaimer!  This article offers a general overview of the series and may not apply uniformly to every model, software/firmware version. Before purchasing or using the device, please consult the model/version-specific documentation or reach out to technical support for accurate information

Why you need SCR50AXE

How SCR50AXE add in Nebula

The router comes with these Subscription Free features:

  • 5 users are recommended
  • Support WiFi 6E AXE5400 
  • Support Guest WiFi 
  • Support VLAN
  • Support 4 SSID 
  • Max 3 VPN tunnels simultaneously (site-to-site, spoke only)
  • Currently no support for Remote VPN (client-to-site)
  • No support for Smart Mesh

Note! If you're having issues getting the SCR device online, please reset the device by holding the RESET button for 15 seconds. Then wait for the device to start up again and then it should come online.

Register your Device

First, connect to your device via cable or via WiFi using the SSID (WiFi Name), and WiFi password found on the back-side of the device to enable the configuration of the device

Download and install the Nebula Mobile App

You can get it from App store or Google Play 

  • Open the application, create an account, and proceed to create your initial organization and site

  • Add (register) the device by scanning the QR code on the back of the device

Choose your Trial licenses If you want to install your product right now and start using it, you can activate your licenses immediately by checking both the Elite Pack Trial And Nebula Pro Pack Trial, which will give you 30 days trial.

  • Please wait up to 3 minutes for the device to get ready (the device will show solid green) and be successfully implemented into Nebula, then click next.


  • Configure your WAN settings If you have DHCP, Static IP, or PPPoE on your WAN, please configure this here now. Then the device will connect to the internet

Note! If you're having issues getting the SCR device online, please reset the device by holding the RESET button for 15 seconds. Then wait for the device to start up again and then it should come online.

Firmware Upgrade

It's recommended to use the latest firmware available, which the device will upgrade to if you choose "Yes". Otherwise, choose "No" - which is not recommended

Create WiFi Network

Create your WiFi network (SSID) by entering your WiFi Name and WiFi Password and click next.

Сonfigure NAT

If you have a local server that you want Web GUI access to on port 443, you may configure this under 

"Site-wide -> Configure -> Security Router -> Firewall -> NAT - Virtual Server"
  • Protocol - if it's TCP or UDP (you may select "both" if you're unsure)
  • Public Port - the port which the remote user is trying to connect to
  • LAN IP - The IP of the internal server
  • Local Port - the port that the internal server should respond to
  • Allow Remote IP - You may restrict the remote users to only be able to connect from certain public IPs. 

The firewall rule will automatically be created in the background to allow this NAT.

For more information, look here: 

Port Forwarding (NAT) - Configure Virtual Server / [Many] 1:1 NAT / Virtual Server Load Balancer

Configure Site-to-site VPN

Configure Site-to-site VPN for another Nebula Router/Gateway
If you have another Nebula Router/Gateway in the same Organization that you want to connect to via VPN, you may use the VPN area found on:

Site-wide -> Configure -> Security Router -> Firewall

Select "Nebula VPN enable" and choose "Nebula VPN topology - disable"

Note! If you have a double-NAT (a modem/router in front of the SCR50AXE that is not in bridge mode), you need to select "Custom" NAT traversal and enter the public IP of your SCR50AXE device.

You may also try to choose "wan" and "auto" to automatically make Nebula detect the public IP of your device.

Configure Site-to-site VPN for a non-Nebula Router/Gateway
If you haven't got a Nebula router/gateway on the other side of the VPN tunnel, or if the Nebula router is in another organization, you can go ahead and configure this manually under

  • Site-wide -> Configure -> Security Router -> Site-to-site VPN -> Non-Nebula VPN Peers
  • Name - Name of the VPN
  • Public IP - The WAN IP of the other side's Gateway
  • Private Subnet - The other side's LAN subnet, which you want to reach from your side (use subnet, not gateway address - e.g. 192.168.10.0/24, not 192.168.10.1/24)
  • IPsec Policy - Advanced settings for your VPN, which has to match on both sides
  • Pre-shared Secret - The pre-shared key/password that needs to match on both sides

  • Make sure that you set the IKE version, Encryption, Authentication DH Group, lifetime the exact same as the other side's VPN settings. Same goes for the Phase 2 settings

Note! Be sure to check the "Advanced tab" under the "IPSec Policy" menu in Nebula to make sure that the Local ID and Peer ID is set to any on both sides

Then click OK and save the settings afterward

Configure Static IP on LAN devices
How to set up a Static IP on an SCR device?

Go to Site-wide > Clients
  • Select the Client list
  • Choose the category "Security router clients"
  • Click on "Add client"

  • Fill in the Name, MAC address, and IP address fields, then select "Reserve IP
    “policy for the device

  • Finally, click "OK" to set up a static IP

Articles in this section

Was this article helpful?
0 out of 2 found this helpful
Share