Does Traffic Flow report before or after the firewall rules are applied? That is, if I have a rule that blocks all incloming packets with a destination port of 8080, and a packets comes in for 192.168.1.1:8080 will that get reported to traffic flow and dropped, or dropped and not reported.
(Destination NAT is in use, if that matters)