CDR Testing

Dpj
Dpj Posts: 55  Ally Member
First Comment First Anniversary

Hello, my first post in this section… We want to setup CDR for customers, but first want to get familiar with it, and find out how we configure it, it does what we want.

Is there a method to test it?

Like download some (innocent) files but files what triggers CDR?

I know Microsoft has some test files, but do they trigger CDR?

Home - Microsoft Defender Testground (i hope this isn't triggered as spam….) just an example from them

Yours dennis

Accepted Solution

All Replies

  • Zyxel_Kay
    Zyxel_Kay Posts: 1,279  Zyxel Employee
    Zyxel Certified Network Engineer Level 2 - Nebula Zyxel Certified Network Engineer Level 2 - WLAN Zyxel Certified Network Engineer Level 2 - Switch Zyxel Certified Network Engineer Level 2 - Security
    Answer ✓

    Hi @Dpj

    Could you please share the model of your device? This will help us provide more tailored assistance.

    If you're looking to configure CDR on your Nebula Firewall, we recommend checking out this article, which offers a detailed introduction to the feature and guidance on configuration:

    Kay

  • Dpj
    Dpj Posts: 55  Ally Member
    First Comment First Anniversary

    Hello Kay,

    we use currently the USG Flex 200 with UTM License. We are testing if this license is usefull for our customers. Beside how to configure it, we also want to investigate if it does what we want it has to do.

  • Zyxel_Kay
    Zyxel_Kay Posts: 1,279  Zyxel Employee
    Zyxel Certified Network Engineer Level 2 - Nebula Zyxel Certified Network Engineer Level 2 - WLAN Zyxel Certified Network Engineer Level 2 - Switch Zyxel Certified Network Engineer Level 2 - Security

    Hi @Dpj

    You can refer to the article mentioned earlier and try configuring CDR on your USG FLEX 200 to see if it meets your requirements.

    Kay

  • Julien44
    Julien44 Posts: 7  Freshman Member
    First Comment Friend Collector

    Hi,
    What is the port used to display the message on client browsers in case of CDR blocking?
    I have already had blocks with CDR but users do not have a message, only a loss of network resources.
    (It must be blocked by a policy rule…)
    Thanks

  • Zyxel_Kay
    Zyxel_Kay Posts: 1,279  Zyxel Employee
    Zyxel Certified Network Engineer Level 2 - Nebula Zyxel Certified Network Engineer Level 2 - WLAN Zyxel Certified Network Engineer Level 2 - Switch Zyxel Certified Network Engineer Level 2 - Security

    Hi @Julien44

    Could you please share which firewall model you are using?

    Kay

  • Julien44
    Julien44 Posts: 7  Freshman Member
    First Comment Friend Collector

    Hi,
    I have a Zyxel ATP700 Firewall.

    Thanks

  • Zyxel_Kay
    Zyxel_Kay Posts: 1,279  Zyxel Employee
    Zyxel Certified Network Engineer Level 2 - Nebula Zyxel Certified Network Engineer Level 2 - WLAN Zyxel Certified Network Engineer Level 2 - Switch Zyxel Certified Network Engineer Level 2 - Security

    Hi @Julien44

    Could you please check if the CDR feature is set up correctly? The following article provides guidance on configuring CDR for both on-premises and Nebula mode firewalls. Kindly refer to the instructions and ensure your CDR configuration is complete.
    [2024 June Spotlight] The solution you must know: Collaborative Detection & Response (CDR) — Zyxel Community

    If you have confirmed that everything is set up properly, please share the destination you are accessing, your firewall management mode (on-premises/Nebula), and a screenshot of the relevant event logs.

    If you're using Nebula cloud mode, please enable Zyxel support access and provide your Nebula organization and site name.

    Kay

  • Dpj
    Dpj Posts: 55  Ally Member
    First Comment First Anniversary

    Hello Kay, sorry, was busy with other things. Yes i think it will fullfill our needs. But i would like the possibility to test it. The same as under Security Service:

    I downloaded i file (an fake mallware file). My computer directly tells me: Hey you cannot download this file. But in the zyxel device (usg Flex 200 with gold license) i don't see anything. I would like to know, how to see if it does what i want it to do.

    yours dennis

  • Zyxel_Kay
    Zyxel_Kay Posts: 1,279  Zyxel Employee
    Zyxel Certified Network Engineer Level 2 - Nebula Zyxel Certified Network Engineer Level 2 - WLAN Zyxel Certified Network Engineer Level 2 - Switch Zyxel Certified Network Engineer Level 2 - Security
    edited 3:09AM

    Hi @Dpj

    Could you please confirm if clicking the download button allows the fake malicious files to be downloaded directly, or if the firewall successfully blocks them? Additionally, could you share the link to the fake malicious file with us? We would like to conduct further analysis.

    Please also enable Zyxel support access and provide your Nebula organization and site name to facilitate our investigation.

    Kay