Ideally, you can create 2 new VLAN interfaces under the Internal port (Default VLAN for Internal port), one for External and another for management traffic by configuring the sign-in policies accordingly, however it is considered as Internal port VLANs at the end.
I would recommended having separate physical connection for each traffic to get the most out of the VPN server. If it's PSA7000c/f device, then beware about this https://kb.pulsesecure.net/articles/Pulse_Secure_Article/KB44446/?kA13Z000000L3HA.
... View more