It's quite wierd as one would like to capture the very traffic that is sent to the wire or traffic recieved from the wire unaltered, whatever active ruleset.
What's even weird is that during a www session, most of the packets would originate from my NAT firewall's IP, but one or two (in a sequence) would show a LAN IP.
I'm confused as to why this is happening.
Has anyone encountered something similar?