When using the Sniffer Tool to stream data to Wireshark, if the Sniffer Tool is set to get data from Interface ether1, then is the data being captured before or after the firewall (before filtering and NAT or after filtering and NAT)?
I think it can be either or both, depending on what the sniffer filter criteria was set to. The best way to look at it, is the sniffer will capture packets coming from the wire into the interface and or leaving the interface going out on the wire