Zyxel Nebula's Collaborative Detection & Response (CDR) is a security feature designed to detect and block malicious client IP traffic within your network. It works by identifying unsafe connections that reach a pre-set threshold. When CDR is enabled, it can block or quarantine traffic from wired and WiFi clients sending malicious traffic, preventing its spread throughout the network.
CDR identifies malicious traffic using a combination of Web Filtering, Anti-Malware, and IPS (IDP) signatures.
To utilize the full functionality of CDR, you need:
- A Gold/UTM Security Pack license.
- A Nebula Pro Pack license.
Without these licenses, CDR functionality will be limited or unavailable. For instance, with a Nebula Base/Plus Pack and no Gold/UTM Security Pack, CDR event detection is available and events are logged, but containment actions like alert, block, or quarantine are not.
You can configure CDR settings under Site-wide > Configure > Collaborative detection & response in the Nebula control center.
click on “Enable” to activate CDR feature
Here is the policy table where you can configure the criteria and the actions, as the figure below:

Terms explanations:
Occurrence: How many times of threat hit [HW1] by a client.
Duration: Within the time duration, CDR detects a threat.
Containment: The action when both criteria have been triggered.
Alert: NCC sends an alert email to administrators when triggered. Security service functions will block illegal traffic.
Block: NCC sends an alert email to administrators. Gateway or AP will block the traffic and redirect it to the block page. *Block wireless client is only supported on AP. The client cannot connect to the WiFi during the block duration.
Quarantine: NCC sends an alert email to administrators. AP will disconnect the client’s WiFi connection and then when the client connects to the WiFi again, it will get the quarantine VLAN IP. *Quarantine function only works on AP.

4. Block is to prevent the malicious client from accessing the wireless network, while
Quarantine is for AP (that supports CDR), which isolates clients using dynamic VLAN assignment.

5. Exempt list is a whitelist where you can input the IP or MAC of the device that you don’t want to be blocked by CDR.
Figure 3. Exempt list
Example of a client blocked by CDR
When a client had surfed a malicious website and the act triggered the CDR criteria, the client browser will pop-out a warning message as the figure shown below:
Figure 4. CDR warning message
How can the administrator release the client?
Go to Site-wide > Monitor > Containment list, you may choose “Release” or “Add to Exempt list”.
Figure 5. Containment list




Comments
0 commentsPlease sign in to leave a comment.