How to ensure my LAN user must to go through NGAF device before access to LAN and External? i did create a policy to deny user (LAN) RDP to Server (LAN) but due to your technician explained that because user pass through the NGAF so the policy which is created is doesn't work for me. as Usual, the connection in our network like this: WAN -> NGAF -> Switchs -> PC&Server.  please correct me if i did wrong. thank you

Your network topology is correct. I might unable to understand your concern. Policy will work if it is configured correctly when traffic passes through NGAF. Since if it is a local network, so packets will transfer via switch within the same network thus it will not deny LAN RDP to servers. You can create access control policy to stop LAN RDP to LAN servers.
i want to send you an attachment file that show you the policy is created by me but click on insert image button is no respond at all. Let me explain to you, the policy is from source LAN to Dest. LAN, RDP port, action is deny. then you see the remote connection still able to access.  
Please refer to images attached. Compare with your policy and then try. I hope it will work.
May I also know your device firmware version.

i followed as you said. but still not work. i also don't know what is the problem?
Kindly drop an email to for further assistance. They will troubleshoot the problem and will resolve issue. Thank you.
your topology is correct but you need create a trunk between your core switch & NGFW
what is this mean "create a trunk"? this is so weird, only sangfor will facing this topology issue. i did used other product but everything is work fine. maybe i am not smart enough.

