Currently we are testing using just the syslog, not the emblem format. Yesterday we had reported 1.5GB of outgoing FTP traffic when in fact this was an incoming transfer. Today as well as all last week FA is reporting FTP outgoing traffic, yet these ports are blocked at the firewall as well as the service is shut down. So I have to question then this traffic. I have looked at the logs and see nowhere near that amout of traffic for the entire day. Is anyone else getting such inaccurate reports with a Cisco PIX firewall?