Hello
We have distributed pppoe concentrators in the network and we log client traffic at every station where MT is present. I wanted to optimize some firewall rules and I wonder if the following is correct. I don't understand the login difference between in and out in the forward chain.
/ip firewall filter
add action=log chain=forward in-interface=all-ppp protocol=tcp tcp-flags=syn
add action=log chain=forward in-interface=all-ppp protocol=tcp tcp-flags=fin