How do you exactly correctly interpret this report?
Interpret1 has only 269 accept logs on internal firewall, which i hardly can believe given the amount of people that work here. Drop and Reject is a lot, which looks normal to me.
Interpret2 same -> low accept logs on internal firewall, although i know there is a lot of internall traffic.
Failover happened on this day, that's the reason why you see also high activity on IFW02. Normally IFW01 is the primary active one.
Interpret3 is report of 5 days, still low accept logs in internal firewall, Drop and Reject is a lot, which again looks normal to me
How is this possible when we log all rules in the policy where traffic has been accepted? Or how do i have to interpret this?