the rule basically looks for inbound connections that is translated by checking if the value of the variable in/out in Firewall devices is equal to
May i know where is parameter set here to filter only the inbound connections?. May i know what is the variable/parameter set i have to go for only to get outbound connections?.
As per my understanding on firewall by checking the ACL group name only we can go for defining inbound/outbound connections and all.
The value of In/Out equals to 1 means inbound connections. Some Firewalls label an inbound connection with the number 1 and the outbound connection with the number 0 but again this depends from a firewall vendor to another. You should check your event logs to see which values they use.
Retrieving data ...