>No, those are RSTs and FINs coming after the state is closed, expected >behavior. >http://doc.pfsense.org/index.php/Logs_show_%22blocked%22_for_traffic_from_a_legitimate_connection,_why%3F
Ok, but unless I'm misunderstanding, I am not logging packets blocked by the default rule, so why would this be logged? And how do I know which rule was applied to this traffic like in the screenshot above? [cid:image001.png@01CBD738.2C9B5970]
<<inline: image001.png>>