when firewall rule is added /extra 17:41:01 Connection using NAT TCP 10.242.1.2 : 5525 ? 121.x.x.x : 22 [SYN] len=48 ttl=128 tos=0x00 srcmac=00:00:00:00:00:00 dstmac=00:00:00:00:00:00 17:41:02 Packet filter rule #9 TCP 10.242.1.2 : 5525 ? 192.168.2.250 : 22 [SYN] len=48 ttl=127 tos=0x00 srcmac=00:1c:c0:aa:21:8c dstmac=00:00:00:00:00:00 17:41:05 DNS request UDP 192.168.2.250 : 32772 ? 192.168.2.100 : 53 len=69 ttl=64 tos=0x00 srcmac=00:00:00:00:00:00 dstmac=00:1c:c0:aa:21:8c when firewall rule is disable 17:43:35 Connection using NAT TCP 10.242.1.2 : 5531 ? 121.x.x.x : 22 [SYN] len=48 ttl=128 tos=0x00 srcmac=00:00:00:00:00:00 dstmac=00:00:00:00:00:00 17:43:36 Default DROP TCP 10.242.1.2 : 5531 ? 192.168.2.250 : 22 [SYN] len=48 ttl=127 tos=0x00 srcmac=00:1c:c0:aa:21:8c dstmac=00:00:00:00:00:00 17:43:38 WebAdmin connection TCP 192.168.2.200 : 5532 ? 192.168.2.100 : 4444 [SYN] len=48 ttl=128 tos=0x00 srcmac=00:00:00:00:00:00 dstmac=00:1c:c0:aa:21:8c 17:43:38 Connection using NAT TCP 10.242.1.2 : 5531 ? 121.x.x.x : 22 [SYN] len=48 ttl=128 tos=0x00 srcmac=00:00:00:00:00:00 dstmac=00:00:00:00:00:00 17:43:39 Default DROP TCP 10.242.1.2 : 5531 ? 192.168.2.250 : 22 [SYN] len=48 ttl=127 tos=0x00 srcmac=00:1c:c0:aa:21:8c dstmac=00:00:00:00:00:00 17:43:44 Connection using NAT TCP 10.242.1.2 : 5531 ? 121.x.x.x : 22 [SYN] len=48 ttl=128 tos=0x00 srcmac=00:00:00:00:00:00 dstmac=00:00:00:00:00:00 17:43:45 Default DROP TCP 10.242.1.2 : 5531 ? 192.168.2.250 : 22 [SYN] len=48 ttl=127 tos=0x00 srcmac=00:1c:c0:aa:21:8c dstmac=00:00:00:00:00:00