Why are the firewall admin 2FA login codes being rejected by the firewall?

Options
Zyxel_Cooldia
Zyxel_Cooldia Posts: 1,590 image  Zyxel Employee
Zyxel Certified Network Administrator - Security Zyxel Certified Sales Associate 100 Answers 1000 Comments

Question:

Why are the firewall admin 2FA login codes being rejected by the firewall?

Answer:

This issue usually occurs if the mobile phone's clock is off by even a minute or two. The Google Authenticator app relies strictly on precise time-synchronization to generate valid tokens.

How it works:
Both the client device and the firewall independently calculate the authentication code using a shared secret key and the current timestamp. Because of this independent calculation, if the time on either side drifts even slightly out of sync, the generated codes will not match, and the firewall will reject the login attempt.