> Source: [sk180091](https://support.checkpoint.com/results/sk/sk180091)

# sk180091 - Interface Direction in FW log is different from Threat Prevention ( IPS)  log

| Property | Value |
|----------|-------|
| Solution ID | sk180091 |
| Date Created | 2022-11-04 |
| Last Modified | 2022-11-22 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R81.20, R81.10 (EOS), R81 (EOS) |

## Symptoms

- The Firewall blade and the Threat Prevention (IPS) blade show different interface directions for the same packet.  
Firewall Blade?inbound eth1  
IPS Blade?outbound eth1  
![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk180091/0202210051112301.topology.jpg)  

![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk180091/1202210051112482.log_summary.png)  

![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk180091//2202210051113173.fw_log.png)  

![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk180091/3202210051113404.TP_ips_log.png)

## Solution

No fix is required. This behavior is by design.  

In the "Threat Prevention (IPS)" logs, the "direction" field has a different meaning than in the Firewall logs.  

In the Threat Prevention (IPS) logs:
"Outbound" means a Client to Server (C2S) packet.  
"Inbound" means Server to Client (S2C) packet.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
