Unusual Admin Login Detection
Options
Zyxel_Lynn
Zyxel Employee
Zyxel Employee
Securing Management Access
To enhance security for firewall management, Zyxel has introduced the Unusual Admin Login detection feature. This feature monitors login attempts and alerts administrators to suspicious activity that might indicate compromised credentials.
How Detection Works
The system utilizes a 30-day sliding window to determine "normal" login behavior.
- External (WAN) Logins: The firewall tracks the source IP and country. If a login originates from a new public IP or a country not seen in the last 30 days, it is flagged as unusual.
- Internal (LAN) Logins: For local management traffic, the system tracks the source device"s hostname. Logging in from a new laptop or PC will trigger an alert until that device is established in the history.

Alerting and Logs
When an unusual login is detected, notifications are delivered via email or push notification. Secure Reporter logs now include enriched data fields, such as the geographical location (country) for WAN logins and the source hostname for LAN logins. This feature is available for USG Flex H series, ATP, and USG Flex firewalls in both cloud and on-premise modes.
0
Categories
- All Categories
- 442 Beta Program
- 3.1K Nebula
- 237 Nebula Ideas
- 6.8K Security
- 740 USG FLEX H Series
- 376 Security Ideas
- 1.8K Switch
- 87 Switch Ideas
- 1.5K Wireless
- 58 Wireless Ideas
- 7.2K Consumer Product
- 319 Service & License
- 512 News and Release
- 99 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 5.3K FAQ
- 34 Documents
- 91 About Community
- 119 Security Highlight