I have the below firewall rules. There exist a network on a separate vlan. This network is only to be reached from, and should no be able to reach the Internet or anywhere else. While capturing packets on LAN, I still see packets to and replies from outside ip-addresses. No group policy applied to the network in question. What am I missing here?
I have tried to make a dedicated deny rule for source, and although the hit counter increments I still see outside packets when capturing.