Getting started
Defined Networking's Managed Nebula makes it easy to set up a secure, high performance Nebula network in a few steps. This guide will walk you through the process of creating your Managed Nebula account, configuring your network, and getting your devices (hosts) communicating with each other.
1. Create an account
To create your free account with support for up to 100 hosts, visit admin.defined.net/signup and provide an email address. This email address will be the primary login for the account. You can add additional admins by their email addresses or set up SSO to grant access through your company's identity provider.
When you submit the signup form you'll receive an email with a "magic link" which will take you to the next step of registration: registering a two-factor authentication device. If your device does not support passkeys, you will need an authenticator app which supports time-based OTP such as Duo Mobile, Authy, or Google Authenticator.
After clicking the magic link in the email, register a passkey by following the browser prompts or scan the QR code with your authenticator app and enter the 6-digit code from the app to verify your registration. Note that you can register additional authenticators as backups in your account settings after logging in.
2. Choose a network range
Before you can add hosts to your Managed Nebula account, you'll need to set up the private network that they will communicate on. Every Managed Nebula network is automatically assigned a unique IPv6 prefix. You may optionally add an IPv4 network range for the network. Hosts will be assigned IP addresses within your IPv4 and IPv6 network ranges.
After an IPv4 network range has been configured, it cannot be changed, and there are some important factors to consider when deciding which range to use. If you're not ready to choose an IPv4 range just yet, that's OK—start with the auto-assigned IPv6 prefix now and configure the IPv4 network range later.
See Choosing a CIDR for more details and guidance.
3. Create and enroll hosts
You're ready to add hosts to your network. To add a host, navigate to the Hosts tab in the admin panel and click Add host. Enter the host details and click Save. After the host is created, follow the on-screen instructions to install and enroll the appropriate version of DNClient on the target machine.
4. Configure access between hosts (optional)
Host-to-host access is controlled by roles and tags. By default, roles allow hosts to ping each other but block all other traffic. If your hosts need to communicate beyond ping:
- Edit the role assigned to the host
- Add firewall rules to allow traffic from all hosts or specific roles
For more advanced access control, see Creating firewalls using roles and tags.
5. Add a self-hosted lighthouse (optional)
A lighthouse is a special type of host that allows hosts in your Managed Nebula network to discover each other. Every network needs at least one, so a managed lighthouse is provisioned for you automatically when creating a network. You don't have to do a thing.
If you wish to enroll your own lighthouse instead of (or alongside) the managed one, see Enrolling a Lighthouse for step-by-step instructions.
Further steps
Your Managed Nebula network is now up and running. Going forward, to ensure your network runs at peak performance and to gain access to new features as we release them, be sure to keep your DNClient updated and keep an eye on our blog for announcements.
Managed Nebula includes a powerful API that can be used to automate host creation, manage roles, access audit logs, and more. See the full API reference for more information.
Lastly, we would love to hear from you! What problems is Managed Nebula solving for you? Are there features that you would like us to build? Do you need any help? Use our contact form to get in touch!