How can I configure my Zyxel firewall to effectively block Helldown ransomware attacks?

Timseat1959
Timseat1959 Posts: 2 image  Freshman Member

I have deployed Zywall firewalls across multiple client sites, and two have recently been compromised by Helldown ransomware. Despite having updated to firmware V5.39, the attacks persisted. I've implemented the following security measures:

  • Changed all administrator passwords
  • Disabled web GUI access from WAN
  • Enabled Geo-IP defense and SSL VPN
  • Activated two-factor authentication for all users

However, the ransomware still infiltrated the network. Could there be additional configurations or best practices to further harden the firewall against such threats? Any insights or recommendations would be greatly appreciated.