Oh my! The VLAN police are going to lock you up for mixing tagged and untagged on the same physical link! That aside...
I assume that the IP addresses noted in your packet capture description are those associated with the MAC addresses, and not the actual addresses from the IP headers in the captured packets?
Without seeing your firewall rules, it's hard to say... but it does sound like there is one that is allowing the traffic. What rules do you have on your VLAN 10 interface?
So I assume that your management network is supposed to be covered by your PrivateNetworks alias? Double-check that?
I'd maybe try adding an explicit block rule at the top of the list for INTERNAL and see if that gets applied, then try to figure out why some other rule is allowing more than you want. You could turn on logging for your (suspect) rules and try to use that to find out which one is doing it too.....