I am sending my log information to Wallwatcher as a syslog server. I have a problem though that it shows my outbound traffic as inbound, thus having the local ip address in the remote column. I think I have traced this to the monowall. If I look at the raw logs. For instance, I have this line in the raw logs.
14:53:35.219827 xl0 @100:8 p <Local IP Address>,3421 -> <Remote Ip address>,110 PR tcp len 20 48 -S K-S IN
This is clearly traffic coming in on the LAN interface (xl0) going out. Any ideas why it is logged as IN?