Nebula - Collaborative Detection & Response (CDR)

Zyxel Nebula's Collaborative Detection & Response (CDR) is a security feature designed to detect and block malicious client IP traffic within your network. It works by identifying unsafe connections that reach a pre-set threshold. When CDR is enabled, it can block or quarantine traffic from wired and WiFi clients sending malicious traffic, preventing its spread throughout the network.

CDR identifies malicious traffic using a combination of Web Filtering, Anti-Malware, and IPS (IDP) signatures.

To utilize the full functionality of CDR, you need:

  • A Gold/UTM Security Pack license.
  • A Nebula Pro Pack license.

Without these licenses, CDR functionality will be limited or unavailable. For instance, with a Nebula Base/Plus Pack and no Gold/UTM Security Pack, CDR event detection is available and events are logged, but containment actions like alert, block, or quarantine are not.

You can configure CDR settings under Site-wide > Configure > Collaborative detection & response in the Nebula control center.

CDR

 click on “Enable” to activate CDR feature

 “Enable” to activate CDR feature

Here is the policy table where you can configure the criteria and the actions, as the figure below:

 policy table

 

Terms explanations:

Occurrence: How many times of threat hit [HW1] by a client.

 Duration: Within the time duration, CDR detects a threat. 

Containment: The action when both criteria have been triggered. 

Alert: NCC sends an alert email to administrators when triggered. Security service functions will block illegal traffic.

Block: NCC sends an alert email to administrators. Gateway or AP will block the traffic and redirect it to the block page. *Block wireless client is only supported on AP. The client cannot connect to the WiFi during the block duration. 

Quarantine: NCC sends an alert email to administrators. AP will disconnect the client’s WiFi connection and then when the client connects to the WiFi again, it will get the quarantine VLAN IP. *Quarantine function only works on AP.

CDR

4. Block is to prevent the malicious client from accessing the wireless network, while
Quarantine is for AP (that supports CDR), which isolates clients using dynamic VLAN assignment.

using dynamic VLAN assignment

5. Exempt list is a whitelist where you can input the IP or MAC of the device that you don’t want to be blocked by CDR.

 Figure 3. Exempt list

 Figure 3. Exempt list

Example of a client blocked by CDR

When a client had surfed a malicious website and the act triggered the CDR criteria, the client browser will pop-out a warning message as the figure shown below:

CDR warning message

Figure 4. CDR warning message

How can the administrator release the client?

Go to Site-wide > Monitor > Containment list, you may choose “Release” or “Add to Exempt list”.

Containment list

Figure 5. Containment list

Articles in this section

Was this article helpful?
0 out of 0 found this helpful
Share

Comments

0 comments

Please sign in to leave a comment.