USG Flex 200: Can i set a threshold limit on emails notificatons recieved from a Security Policy?

Options
Lucas_Wilson
Lucas_Wilson Posts: 3  Freshman Member
Zyxel Certified Network Engineer Level 1 - Nebula First Comment

Scenario:
We recently applied a security policy called "Blocked_IPs" on a client's USG Flex 200. The goal was to prevent certain LAN IP addresses from accessing both the local network and the internet if their activity appeared suspicious.

Earlier today, we added a mobile device to the block list after detecting signs of botnet activity. The policy is configured to "Log alert" for all matching traffic, which—based on my understanding—generates an alert for every single connection attempt.

As a result, with the nature of botnet activity, our email inbox was flooded with alerts, most of which were unnecessary and overwhelming.

Suggested Improvement (if not already available):
It would be very helpful if the firewall offered a threshold or rate-limiting feature for alert notifications. For example, a configurable option to send a summary report of matched activity every 5 minutes—rather than individual alerts—would significantly reduce noise while still keeping us informed of potential threats.

All Replies

  • Zyxel_Melen
    Zyxel_Melen Posts: 3,529  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate

    Hi @Lucas_Wilson,

    In the current log settings page, we have the log consolidation funtion that will aggregate multiple logs during a period, in seconds. Please navigate to Menu > Configuration > Log & Report > Log Settings > edit system log > Log Consolidation to change the period from 10 seconds to 300 seconds.

    image.png image.png

    Hope this helps.

    Zyxel Melen