thanks for the reply.
- Im not sure.. we have a syslog server on the inside of our firewall and customers firewalls are sending logs to it from untrust to trust.
- hmm so the first address is our inside of our LB and 60.9.185.16 is not anything and that is not lagit traffic.
Thanks.