What are the different containment actions available in CDR, and how do they behave?

Options
Zyxel_Cooldia
Zyxel_Cooldia Posts: 1,590 image  Zyxel Employee
Zyxel Certified Network Administrator - Security Zyxel Certified Sales Associate 100 Answers 1000 Comments

Question:

What are the different containment actions available in CDR, and how do they behave?

Answer:

Alert: This action simply sends an alert notification email to the configured recipient and does not restrict client traffic.

Block: This blocks the client's traffic on both the Nebula AP and Firewall, and redirects the user to a local or external notification block page.

Quarantine: This action is specifically for wireless clients. After a compromised wireless station disassociates, it is dynamically assigned to a dedicated Quarantine VLAN to isolate it from the rest of the network.

Note on Notifications: Only the "Alert" action will send email notifications. The "Block" action will just block traffic without an email alert, and "Quarantine" only applies to wireless APs.

Tagged: