If the web interface or CLI are exposed on the WAN network, brute-force attacks can be deployed repeatedly by malicious actors to gain illegitimate access to the firewall management functions. We recommend the following to mitigate the impact:
Navigate to Device > Settings > Administration > Login/Multiple Administrators.
Go to the Administrator Name & Password section and select TOTP from the drop-down list in the One-time Passwords Method field.
Create a rule that limits HTTPS Management access.
