Does anyone know why a Firewall Accounting report always returns a "0" in the inbound/outbound column? When I view the raw Checkpoint logs in the Event Viewer, I can clearly see which traffic is outbound and which traffic is inbound. However, there doesn't seem to be a way to run a report to filter out inbound vs outbound, unless I start parsing through the source/destination IPs for known internal addresses.
If the information is being capture in the raw logs, I imagine it must be saved somewhere to use in reporting. Has anyone ever found this location?
Thanks in advance.