From firmware v5.00 onwards you can use a different port for the SSL VPN, so only the SecuExtender can log in on this port, no admin nor any other user.
To set this up, you have to log into your USG and change the SSL-VPN port under
Configuration > VPN > SSL VPN > Global Setting
Next you need to create a firewall rule that allows this port from WAN to ZyWall. In general you can simply add a service under
Configuration > Object > Service
and add this new Service to the Default_WAN_to_Zywall group.
If you don't want to log in as an admin or user to the Web GUI of the device, you now can simply remove the HTTPS access from WAN to ZyWall. In general this can be done by removing the HTTPS service from the default_WAN_to_ZyWall group.