Why can an external device access the login page of my Fortigate?
Hello everybody, I'm working on a Fortigate 60F (v7.2.10) and I manage my Fortigate at the address:
or
https://79.x.x.x:40443 (for externals)
https://10.1.0.1:40443 (for internals)
because 79.x.x.x is the wan1 interface, I defined two local-in-policy:
 

login_group is an address group:


 
 
![]()
 
HTTPS-40443 is:

 
 
The policy n.1 works fine, if I try to access (10.1.0.1:40443 or vpn.xxx.com:40443) I correctly see the login page.
From the same network (10.1.10.0/24), another device, can't (correctly).
If I use an external device (for example my phone), connected to a different external network, it can access vpn.xxx.com:40443 and also 79.x.x.x:40443. The policy n.2 doesn't generate any log. What am I missing?
 
 
