Unusual Admin Login Detection

Options
Zyxel_Lynn
Zyxel_Lynn image  Zyxel Employee
5 Answers First Comment Friend Collector First Anniversary
edited August 17 in Other Topics

Securing Management Access

To enhance security for firewall management, Zyxel has introduced the Unusual Admin Login detection feature. This feature monitors login attempts and alerts administrators to suspicious activity that might indicate compromised credentials.

How Detection Works

The system utilizes a 30-day sliding window to determine "normal" login behavior.

  • External (WAN) Logins: The firewall tracks the source IP and country. If a login originates from a new public IP or a country not seen in the last 30 days, it is flagged as unusual.
  • Internal (LAN) Logins: For local management traffic, the system tracks the source device"s hostname. Logging in from a new laptop or PC will trigger an alert until that device is established in the history.

Alerting and Logs

When an unusual login is detected, notifications are delivered via email or push notification. Secure Reporter logs now include enriched data fields, such as the geographical location (country) for WAN logins and the source hostname for LAN logins. This feature is available for USG Flex H series, ATP, and USG Flex firewalls in both cloud and on-premise modes.