I did a little more research on the port-80 traffic that's sneakin' by the proxy. I just checked the PF logs for yesterday and today, and there are 70 "rogue" packets.
Seven are from our SBS 2003 server to one Google IP.
Six are from (non-existent, I think) 10.x.x.67 to Google and two to Viet Nam.
The other 57 are from my desktop to Viet Nam, Google, Berlin, etc. I leave my unit running, so the packets continued while I was out of the office until 2009:10:15-04:01:24 this morning.
Cheers - Bob
This thread was automatically locked due to age.