Hm, OK after some testing in lab I came to the following conclusion and questions:
- CP admin guides must provide more specific intention of the managment interface and its usage
-meaning GW uses allowed hosts table only when initial policy is loaded, after you install security policy, packet flow to GW is process via policy rules (that was my understaning of the usage of the specific table )
Regardnign impled rules- is there an implied rule to process the "allowed hosts" table first? If so could you point me in the right direction.
Check if you want to redefine internet facing IF as MANAGEMENT - to my understanding this sould be the case on all WAN only accesible GWs. OR is there any security limitations? After policy is installed and GW object is defined as destination in security policy, GW is accesible via all interfaces.
So I guess this solve my problem when connecting a new GW, after that if policy is in order access should work.
Br