🛡️ ToastFort

local-in policy vs firewall policy

traffic TO the FortiGate is governed by local-in policies; traffic THROUGH it by firewall policies — two separate engines

A classic trap. **Firewall policies only ever control traffic passing through the device.** Traffic destined to the FortiGate itself — admin GUI/SSH, IPsec IKE, SSL-VPN, BGP, ping to an interface — is handled by local-in policies (config firewall local-in-policy), which are largely implicit and permissive by default. If an admin can still log in despite a deny-all policy, this is why.

In the corpus (2)

Deployment & system configuration

Firewall policies & authentication