FortiWiFi v7.4.3(F) build2573 Local-In Policy for ANY Interface Issue
On January 19th, we started to receive SOC alerts for failed logins to a FortiWiFi 60E running 7.4.3 (Feature). Normally we don't push out Feature version firmware so why it is installed is another story unrelated to the current issue. I do not have a date on when this Firmware was loaded so I am unsure if this has been an issue since loading 7.4.3 or recent issue. We did have SSLVPN enabled for 443 up until January 1st at which point it was reassigned to port 4444 and disabled in favor of Remote Access IPSec.
We found that there is a Local In policy for HTTPS listening on ANY interface rather than just the LAN interface where HTTPS is enabled on the interface. We cannot remove this listing. The FortiWiFi is without subscription and stuck on 7.4.3 using Automatic Upgrade. The downside is that Automatic Upgrade is failing to download the image for the next mature image available. I really loathe 7.4 introduction of blocking manual upgrades when there have been a number of critical CVEs by Fortinet.
We will likely reformat this FortiWiFi in an effort to place on a Mature version firmware, or force the client to purchase a license (SMB budgets are tough). I just wanted to get this information out in the wild.

Local-In Policy

