I am wondering why all raw logs show as inbound "IN" even when the traffic
being logged originated on the LAN destined for an external address? I ask
because I am trying to create rules for our syslog/reporting application to
properly recognize IN/OUT traffic. Any help would be greatly appreciated.